SANS Community Night – SANS Oslo April 2024

Join us on Tuesday 23rd April 2024 for the SANS Oslo April Community Night 2024.

SANS Community Nights are a great way to stay in touch with your local InfoSec community and to hear the latest in technical wizardry, industry intelligence, and thought leadership from our amazing instructors.

Join us at the Radisson Blu Scandinavia Hotel, Holbergsgate 30, Oslo, 0166, Norway.

View the agenda below:

Tuesday 23rd April 2024

Registration
17:30 – 18:00

Networking
18:00 – 19:00

Breaking the Kubernetes Kill Chain: Host Path Mount
With Eric Johnson and Ryan Nicholson
19:00 - 20:00

Abstract:

Breaking the Kubernetes Kill Chain: Host Path Mount with Eric Johnson and Ryan Nicholson.
Microsoft's Threat Matrix for Kubernetes helps organizations understand the attack surface a Kubernetes deployment introduces to their environments. This ensures that adequate detections and mitigations are in place. By covering over 40 different attacker techniques, defenders can learn about Kubernetes-specific mitigations and controls to deploy to their environments. In this session, we will explore the MS-TA9013 Host Path Mount technique, which is commonly used by attackers to perform privilege escalation in a Kubernetes cluster. Attendees will learn how attackers and defenders can:

  • Escape the container's host volume mount to gain persistence on an underlying node
  • Move laterally from the underlying node into the customer's cloud environment
  • Analyze Kubernetes audit logs to detect pods deployed with a hostPath mount
  • Deploy an admission controller that prevents new pods from using a hostPath mount

Secure your Seat

Thank you for your interest in our community nights. Please send an email to salessupport_UKINI@sans.org to secure a seat.