{"product_id":"defending-kubernetes-cloud-native-infrastructure-in-the-age-of-ai","title":"Defending Kubernetes \u0026 Cloud-Native Infrastructure in the Age of AI","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e Defending Kubernetes \u0026amp; Cloud-Native Infrastructure in the Age of AI\u003cbr\u003e\u003cstrong\u003eTrainer:\u003c\/strong\u003e Madhu Akula\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-09, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 am - 5:00 pm\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 1000 BHD\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eDefending containerized workloads and cloud-native infrastructure is more critical than ever. Recent security reports indicate that 42% of respondents cite security as a top concern with container and Kubernetes strategies, while attackers start probing new clusters in as little as 18 minutes.\u003c\/p\u003e\n\u003ch2\u003e2. Course Description\u003c\/h2\u003e\n\u003cp\u003eThis hands-on, real-world training is designed to equip Blue Teamers, Cloud Security Engineers, Security Architects, and DevSecOps professionals with the skills needed to understand and defend Kubernetes clusters across the supply chain, infrastructure, and runtime layers.\u003c\/p\u003e\n\u003cp\u003eThe course addresses current threat landscapes including AI\/ML workload security, supply chain attacks, and emerging attack vectors identified in recent days.\u003c\/p\u003e\n\u003cp\u003eThrough simulated attack scenarios, practical labs, and real-world case studies, participants will learn to detect modern TTPs, implement effective security controls, and improve observability and incident response capabilities.\u003c\/p\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003eDay 1\u003c\/h3\u003e\n\u003ch3\u003eSection 1: Foundation \u0026amp; Threat Landscape\u003c\/h3\u003e\n\u003ch4\u003e3.1 Fast-Track Kubernetes 101 for Defenders\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.1.1\u003c\/strong\u003e Architecture deep-dive from a security perspective\u003cbr\u003e\u003cstrong\u003e3.1.2\u003c\/strong\u003e Attack surface analysis and entry points\u003cbr\u003e\u003cstrong\u003e3.1.3\u003c\/strong\u003e Understanding AI\/ML workload orchestration patterns\u003c\/p\u003e\n\u003ch4\u003e3.2 Threat Modeling \u0026amp; Intelligence\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.1\u003c\/strong\u003e MITRE ATT\u0026amp;CK for Containers framework (latest tactics)\u003cbr\u003e\u003cstrong\u003e3.2.2\u003c\/strong\u003e Analysis of latest recent Kubernetes incident trends\u003cbr\u003e\u003cstrong\u003e3.2.3\u003c\/strong\u003e Anonymous authentication exploitation patterns\u003cbr\u003e\u003cstrong\u003e3.2.4\u003c\/strong\u003e STRIDE methodology adapted for cloud-native environments\u003cbr\u003e\u003cstrong\u003e3.2.5\u003c\/strong\u003e Behavioral threat detection using IOCs\u003c\/p\u003e\n\u003ch4\u003e3.3 Defensive kubectl Kung-Fu: Advanced API Auditing\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.1\u003c\/strong\u003e API server security hardening beyond basics\u003cbr\u003e\u003cstrong\u003e3.3.2\u003c\/strong\u003e Detecting lateral movement through API abuse\u003cbr\u003e\u003cstrong\u003e3.3.3\u003c\/strong\u003e Advanced RBAC audit techniques\u003cbr\u003e\u003cstrong\u003e3.3.4\u003c\/strong\u003e API server attack path analysis\u003c\/p\u003e\n\u003ch4\u003e3.4 Supply Chain Security Revolution\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.4.1\u003c\/strong\u003e Container image signing with Sigstore\/Cosign\u003cbr\u003e\u003cstrong\u003e3.4.2\u003c\/strong\u003e Software Bill of Materials (SBOM) enforcement\u003cbr\u003e\u003cstrong\u003e3.4.3\u003c\/strong\u003e Provenance verification and attestation\u003cbr\u003e\u003cstrong\u003e3.4.4\u003c\/strong\u003e Private registry threat modeling\u003cbr\u003e\u003cstrong\u003e3.4.5\u003c\/strong\u003e Third-party dependency risk assessment\u003c\/p\u003e\n\u003ch3\u003eSection 2: Advanced Hardening \u0026amp; Attack Path Mitigation\u003c\/h3\u003e\n\u003ch4\u003e3.5 Next-Gen Container Isolation\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.1\u003c\/strong\u003e Container escape prevention with gVisor\/Kata\/etc.\u003cbr\u003e\u003cstrong\u003e3.5.2\u003c\/strong\u003e Advanced security profiles like KuberArmor or AppArmor \u0026amp; seccomp-bpf\u003cbr\u003e\u003cstrong\u003e3.5.3\u003c\/strong\u003e User namespace security considerations\u003cbr\u003e\u003cstrong\u003e3.5.4\u003c\/strong\u003e Privileged container detection strategies\u003c\/p\u003e\n\u003ch4\u003e3.6 Zero-Trust Network Security\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.1\u003c\/strong\u003e Service mesh security (Istio\/Linkerd security policies)\u003cbr\u003e\u003cstrong\u003e3.6.2\u003c\/strong\u003e eBPF-based network monitoring and enforcement\u003cbr\u003e\u003cstrong\u003e3.6.3\u003c\/strong\u003e East-west traffic encryption patterns\u003cbr\u003e\u003cstrong\u003e3.6.4\u003c\/strong\u003e Network policy testing and validation\u003c\/p\u003e\n\u003ch4\u003e3.7 Identity \u0026amp; Access Management Revolution\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.7.1\u003c\/strong\u003e RBAC security assessment methodology\u003cbr\u003e\u003cstrong\u003e3.7.2\u003c\/strong\u003e ServiceAccount token security\u003cbr\u003e\u003cstrong\u003e3.7.3\u003c\/strong\u003e Workload identity \u0026amp; federation\u003cbr\u003e\u003cstrong\u003e3.7.4\u003c\/strong\u003e Pod Security Standards (PSS) enforcement\u003c\/p\u003e\n\u003ch4\u003e3.8 Modern Application Delivery Security\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.8.1\u003c\/strong\u003e GitOps security patterns and threat modeling\u003cbr\u003e\u003cstrong\u003e3.8.2\u003c\/strong\u003e Helm security beyond basics (OCI registries)\u003cbr\u003e\u003cstrong\u003e3.8.3\u003c\/strong\u003e Kustomize security considerations\u003cbr\u003e\u003cstrong\u003e3.8.4\u003c\/strong\u003e ArgoCD\/Flux security hardening\u003c\/p\u003e\n\u003ch4\u003e3.9 Secrets \u0026amp; Data Protection\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.9.1\u003c\/strong\u003e External Secrets Operator patterns\u003cbr\u003e\u003cstrong\u003e3.9.2\u003c\/strong\u003e HashiCorp Vault integration security\u003cbr\u003e\u003cstrong\u003e3.9.3\u003c\/strong\u003e CSI driver security considerations\u003cbr\u003e\u003cstrong\u003e3.9.4\u003c\/strong\u003e Encryption at rest with cloud KMS integration\u003c\/p\u003e\n\u003ch4\u003e3.10 Cloud-Native Defense Integration\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.10.1\u003c\/strong\u003e Cloud provider security service integration\u003cbr\u003e\u003cstrong\u003e3.10.2\u003c\/strong\u003e Workload identity and IRSA security patterns\u003cbr\u003e\u003cstrong\u003e3.10.3\u003c\/strong\u003e Cloud metadata API protection strategies\u003cbr\u003e\u003cstrong\u003e3.10.4\u003c\/strong\u003e Multi-cloud security considerations\u003c\/p\u003e\n\u003ch3\u003eDay 2\u003c\/h3\u003e\n\u003ch3\u003eSection 3: Detection, Monitoring \u0026amp; AI-Enhanced Response\u003c\/h3\u003e\n\u003ch4\u003e3.11 Runtime Security Revolution\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.11.1\u003c\/strong\u003e Falco rule customization and tuning\u003cbr\u003e\u003cstrong\u003e3.11.2\u003c\/strong\u003e eBPF-based monitoring with Tetragon\/Tracee\u003cbr\u003e\u003cstrong\u003e3.11.3\u003c\/strong\u003e Cilium Hubble for network observability\u003cbr\u003e\u003cstrong\u003e3.11.4\u003c\/strong\u003e Container runtime security (containerd\/CRI-O)\u003c\/p\u003e\n\u003ch4\u003e3.12 AI\/ML Workload Security Specialization\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.12.1\u003c\/strong\u003e GPU resource abuse detection\u003cbr\u003e\u003cstrong\u003e3.12.2\u003c\/strong\u003e Model poisoning prevention strategies\u003cbr\u003e\u003cstrong\u003e3.12.3\u003c\/strong\u003e ML pipeline security monitoring\u003cbr\u003e\u003cstrong\u003e3.12.4\u003c\/strong\u003e Jupyter\/MLflow security considerations\u003c\/p\u003e\n\u003ch4\u003e3.13 Advanced Threat Detection\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.13.1\u003c\/strong\u003e Behavioral anomaly detection with ML\u003cbr\u003e\u003cstrong\u003e3.13.2\u003c\/strong\u003e Cryptomining detection patterns\u003cbr\u003e\u003cstrong\u003e3.13.3\u003c\/strong\u003e Advanced persistent threat (APT) indicators\u003cbr\u003e\u003cstrong\u003e3.13.4\u003c\/strong\u003e Secrets scanning in runtime environments\u003c\/p\u003e\n\u003ch4\u003e3.14 Policy-as-Code \u0026amp; Governance\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.14.1\u003c\/strong\u003e Kyverno policy \u0026amp; OPA Gatekeeper engine comparison\u003cbr\u003e\u003cstrong\u003e3.14.2\u003c\/strong\u003e Spotter universal security policy engine\u003cbr\u003e\u003cstrong\u003e3.14.3\u003c\/strong\u003e Policy testing and CI\/CD integration\u003c\/p\u003e\n\u003ch4\u003e3.15 Persistence \u0026amp; Evasion Hunting\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.15.1\u003c\/strong\u003e Sidecar injection attack detection\u003cbr\u003e\u003cstrong\u003e3.15.2\u003c\/strong\u003e Init container abuse patterns\u003cbr\u003e\u003cstrong\u003e3.15.3\u003c\/strong\u003e DaemonSet privilege escalation hunting\u003cbr\u003e\u003cstrong\u003e3.15.4\u003c\/strong\u003e Node-level persistence techniques\u003c\/p\u003e\n\u003ch4\u003e3.16 Incident Response Playbooks\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.16.1\u003c\/strong\u003e Automated response orchestration\u003cbr\u003e\u003cstrong\u003e3.16.2\u003c\/strong\u003e Container forensics techniques\u003cbr\u003e\u003cstrong\u003e3.16.3\u003c\/strong\u003e Kubernetes-native incident response tools\u003c\/p\u003e\n\u003ch3\u003eSection 4: Auditing, Automation \u0026amp; Future-Ready Defense\u003c\/h3\u003e\n\u003ch4\u003e3.17 Comprehensive Security Posture Assessment\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.17.1\u003c\/strong\u003e Multi-tool audit orchestration\u003cbr\u003e\u003cstrong\u003e3.17.2\u003c\/strong\u003e KubeAudit, Trivy, Kubescape, Kube-score, Spotter comparison\u003cbr\u003e\u003cstrong\u003e3.17.3\u003c\/strong\u003e Popeye resource optimization auditing\u003cbr\u003e\u003cstrong\u003e3.17.4\u003c\/strong\u003e Custom policy development\u003c\/p\u003e\n\u003ch4\u003e3.18 Compliance \u0026amp; Benchmarking Excellence\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.18.1\u003c\/strong\u003e CIS Kubernetes Benchmark implementation\u003cbr\u003e\u003cstrong\u003e3.18.2\u003c\/strong\u003e NIST Cybersecurity Framework mapping\u003cbr\u003e\u003cstrong\u003e3.18.3\u003c\/strong\u003e SOC 2 compliance for Kubernetes\u003cbr\u003e\u003cstrong\u003e3.18.4\u003c\/strong\u003e PCI-DSS container security requirements\u003c\/p\u003e\n\u003ch4\u003e3.19 DevSecOps Integration Mastery\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.19.1\u003c\/strong\u003e Security scanning in GitOps workflows\u003cbr\u003e\u003cstrong\u003e3.19.2\u003c\/strong\u003e Admission controller testing in CI\/CD\u003cbr\u003e\u003cstrong\u003e3.19.3\u003c\/strong\u003e Infrastructure as Code security scanning\u003cbr\u003e\u003cstrong\u003e3.19.4\u003c\/strong\u003e Progressive delivery security gates\u003c\/p\u003e\n\u003ch4\u003e3.20 Real-World Case Study Deep Dives\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.20.1\u003c\/strong\u003e Kubernetes cryptojacking incident analysis\u003cbr\u003e\u003cstrong\u003e3.20.2\u003c\/strong\u003e Misconfigured API server exploitation case studies\u003cbr\u003e\u003cstrong\u003e3.20.3\u003c\/strong\u003e Supply chain attack post-mortems\u003cbr\u003e\u003cstrong\u003e3.20.4\u003c\/strong\u003e AI\/ML infrastructure compromise scenarios\u003c\/p\u003e\n\u003ch4\u003e3.21 Security Maturity \u0026amp; Future Direction\u003c\/h4\u003e\n\u003cp\u003e\u003cstrong\u003e3.21.1\u003c\/strong\u003e Kubernetes Security Maturity Model (KSMM)\u003cbr\u003e\u003cstrong\u003e3.21.2\u003c\/strong\u003e Emerging security tools landscape\u003cbr\u003e\u003cstrong\u003e3.21.3\u003c\/strong\u003e Cloud-native security platform integration\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eIntermediate\u003c\/strong\u003e - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eAdvanced\u003c\/strong\u003e - The student is expected to have significant practical experience with the tools and technologies that the training will focus on.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBasic Kubernetes knowledge (kubectl, YAML manifests)\u003c\/li\u003e\n\u003cli\u003eContainer security fundamentals\u003c\/li\u003e\n\u003cli\u003eLinux system administration experience\u003c\/li\u003e\n\u003cli\u003eFamiliarity with cloud provider security services\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e6. What Students Should Bring\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003eStudents should bring a laptop with a browser and we will provide you with access to the browser-based labs.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cul\u003e\n\u003cli\u003e00+ page digital workbook with step-by-step labs and references\u003c\/li\u003e\n\u003cli\u003eCustom lab environment for continued practice\u003c\/li\u003e\n\u003cli\u003eSecurity policy templates and implementation guides\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e8. Trainer Bio\u003c\/h2\u003e\n\u003ch3\u003eMadhu Akula\u003c\/h3\u003e\n\u003cp\u003eMadhu Akula is a pragmatic security leader and creator of Kubernetes Goat, an intentionally vulnerable by-design Kubernetes Cluster to learn and practice Kubernetes Security. Also published author and cloud-native security architect with extensive experience.\u003c\/p\u003e\n\u003cp\u003eAlso, he is an active member of the international security, DevOps, and cloud-native communities (null, DevSecOps, AllDayDevOps, AWS, CNCF, USENIX, OWASP, etc). Holds industry certifications like OSCP (Offensive Security Certified Professional), CKA (Certified Kubernetes Administrator), CKS (Certified Kubernetes Security Specialist), etc.\u003c\/p\u003e\n\u003cp\u003eMadhu frequently speaks and runs training sessions at security events and conferences around the world including DEFCON (24, 26, 27, 28, 29, 30, 31, 32, 33 \u0026amp; 34), BlackHat USA, EU, ASIA (2018, 19, 21, 22, 23, 24, 25 \u0026amp; 26), USENIX LISA (2018, 19 \u0026amp; 21), SANS Cloud Security Summit 2021 \u0026amp; 2022, O'Reilly Velocity EU, GitHub Satellite, Appsec EU (2018, 19 \u0026amp; 22), All Day DevOps (2016, 17, 18, 19, 20, 21, 22, 23 \u0026amp; 24), DevSecCon (London, Singapore, Boston), DevOpsDays India, c0c0n (2017, 18 \u0026amp; 20), Nullcon (2018, 19, 21 \u0026amp; 22), SACON, WeAreDevelopers, null and multiple others.\u003c\/p\u003e\n\u003cp\u003eHis research has identified vulnerabilities in over 200+ companies and organisations including; Google, Microsoft, LinkedIn, eBay, AT\u0026amp;T, WordPress, NTOP Adobe, etc, and is credited with multiple CVEs, Acknowledgements, and rewards.\u003c\/p\u003e\n\u003cp\u003eHe is co-author of Security Automation with Ansible2 (ISBN-13: 978-1788394512), which is listed as a technical resource by Red Hat Ansible. He is the technical reviewer for Learn Kubernetes Security, and Practical Ansible2 books by Packt Pub.\u003c\/p\u003e\n\u003cp\u003eAlso won 1st prize for building an Infrastructure Security Monitoring solution at InMobi flagship hackathon among 100+ engineering teams. In addition to his technical expertise, Madhu advises startups on building exceptional products and communities, helping them add significant value along the way.\u003c\/p\u003e\n\u003ch2\u003e9. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e9.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.8\u003c\/strong\u003e By purchasing this ticket you agree to abide by the \u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003eDEF CON Training Code of Conduct\u003c\/a\u003e and the registration terms and conditions listed above.\u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49942336504051,"sku":null,"price":1000.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/MadhuAkula.avif?v=1786559982","url":"https:\/\/me.shop.defcon.org\/products\/defending-kubernetes-cloud-native-infrastructure-in-the-age-of-ai","provider":"DEF CON MIDDLE EAST","version":"1.0","type":"link"}