The ASCPC On-Demand course blends offensive and defensive techniques across a variety of CI/CD platforms, focusing on practical, hands-on skills. Students will explore vulnerabilities, exploit misconfigurations, and learn how to defend against real-world CI/CD threats.
Key focus areas include:
- GitHub Actions Security: Explore context injection, pull request abuse, artifact poisoning, and misconfigured OIDC workflows.
- CircleCI Misconfigurations: Hijack pipeline configurations and exploit insecure runner setups.
- AWS CodeBuild Exploitation: Abuse IAM roles, environment variables, and pipeline triggers to escalate privileges and exfiltrate secrets.
- Docker Registry Attacks: Inject malicious images and perform credential harvesting through poorly secured registries.
- Kubernetes Integration Risks: Compromise clusters via CI/CD, enumerate resources, and escalate access across pods and containers.
- Azure DevOps Abuse: Leak credentials, escalate privileges, and abuse service connections in insecure Azure DevOps pipelines.
- Each module is supported by guided labs that simulate real CI/CD environments and include both offensive attack paths and defensive remediation strategies.
