Post

DevSecOps Labs: Index & Practical Roadmap

Practical hands-on lab index mapping real-world cloud security and DevSecOps exercises to each week of the 4-week study plan. Includes lab objectives, tools, success criteria, and direct links to full walkthroughs.

DevSecOps Labs: Index & Practical Roadmap

Overview

When I started my DevSecOps journey, I realized quickly that reading theory and passing multiple-choice quizzes is only 20% of the game. Real confidence comes from building the architecture, breaking it intentionally, and fixing it in code.

This page serves as the master index for all the hands-on security labs I built throughout the 4-week Cloud Security & DevSecOps Study Plan.

Every lab below is structured around a clear workflow:

  1. Objective: What specific security problem we are solving.
  2. Tools & Stack: The exact services and open-source utilities used.
  3. Success Criteria: The verifiable proof that the fix or control works.
  4. Walkthrough Link: Direct link to the complete step-by-step documentation.

Week 1: AWS Security Services & Identity

Lab 1.1: IAM Least Privilege Role & Policy Simulator


Lab 1.2: Trigger and Investigate a GuardDuty Finding


Lab 1.3: AWS Config Rule & Auto-Remediation for S3


Lab 1.4: CloudTrail Forensics with Athena


Lab 1.5: WAF Setup with OWASP Core Rules on an ALB

  • Objective: Attach AWS WAF Web ACL to an Application Load Balancer and block SQL injection and cross-site scripting attempts.
  • Tools: AWS WAF v2, ALB, curl
  • Success Criteria: Clean HTTP GET requests return 200 OK, payloads containing ' OR 1=1 -- trigger immediate 403 Forbidden responses.
  • Walkthrough: Day 6: AWS WAF & Shield - Protecting Web Apps from Layer 7 Attacks

Week 2: Secrets Management & Container Security

Lab 2.1: Secrets Manager Automatic Rotation


Lab 2.2: HashiCorp Vault Dynamic AWS Credentials

  • Objective: Configure Vault to generate short-lived, leased IAM credentials on demand.
  • Tools: HashiCorp Vault, AWS IAM
  • Success Criteria: vault read aws/creds/s3-reader issues temporary keys that automatically expire and self-destruct upon lease expiry.
  • Walkthrough: Day 9: HashiCorp Vault Basics

Lab 2.3: Dockerfile Hardening Before and After

  • Objective: Refactor an insecure root-based Dockerfile into a minimal, non-root, read-only container image.
  • Tools: Docker, Docker Bench for Security
  • Success Criteria: Container runs as unprivileged UID 10001, root filesystem mounted read-only, image size reduced by over 80%.
  • Walkthrough: Day 10: Docker Security Hardening

Lab 2.4: Container Image Scanning with Trivy

  • Objective: Scan container images in CI to filter out Critical and High CVEs before deployment.
  • Tools: Trivy, Docker, GitHub Actions
  • Success Criteria: Scans return structured tables of CVEs, pipeline exits with error code 1 when Critical vulnerabilities are detected.
  • Walkthrough: Day 11: Container Image Scanning with Trivy

Lab 2.5: Kubernetes RBAC & Network Isolation

  • Objective: Implement dedicated ServiceAccounts and restrictive NetworkPolicies to stop lateral movement.
  • Tools: kubectl, Kubernetes (K3s/Minikube), NetworkPolicy manifests
  • Success Criteria: Pods cannot access unauthorized namespaces; default cluster-admin service account tokens are disabled.
  • Walkthrough: Day 12: Kubernetes RBAC & Pod Security

Lab 2.6: Runtime Threat Detection with Falco

  • Objective: Monitor Linux kernel syscalls inside containers and trigger alerts on shell execution or sensitive file reads.
  • Tools: Falco, Helm, Kubernetes
  • Success Criteria: Spawning /bin/bash inside a running pod immediately generates a Notice alert in Falco logs.
  • Walkthrough: Day 13: Runtime Security with Falco

Week 3: Pipeline Security & Automated Testing

Lab 3.1: SAST Scanning with Semgrep

  • Objective: Audit source code on pull requests using open-source Semgrep rules and custom regex patterns.
  • Tools: Semgrep CLI, GitHub Actions
  • Success Criteria: Vulnerable code patterns (like unparameterized SQL queries) fail automated CI checks with actionable guidance.
  • Walkthrough: Day 15: SAST with Semgrep

Lab 3.2: Dependency Vulnerability Scanning with Snyk

  • Objective: Detect outdated and vulnerable third-party packages in package.json and requirements.txt.
  • Tools: Snyk CLI, Dependabot
  • Success Criteria: High-severity dependency CVEs flagged, automated PRs generated for patched minor versions.
  • Walkthrough: Day 16: SCA with Snyk & Dependabot

Lab 3.3: Infrastructure as Code (IaC) Scanning with Checkov

  • Objective: Scan Terraform plans and HCL code for misconfigurations before infrastructure is provisioned.
  • Tools: Checkov, tfsec, Terraform
  • Success Criteria: Flagged violations (like open ingress 0.0.0.0/0 on port 22 or unencrypted EBS volumes) block the merge.
  • Walkthrough: Day 17: IaC Scanning with Checkov & tfsec

Lab 3.4: DAST Scanning with OWASP ZAP

  • Objective: Perform automated dynamic application security testing against running web application staging endpoints.
  • Tools: OWASP ZAP (Docker), curl
  • Success Criteria: Identifies missing security headers (CSP, HSTS), weak cookie flags, and exposed administrative endpoints.
  • Walkthrough: Day 18: DAST with OWASP ZAP

Lab 3.5: Full Secure CI/CD Pipeline

  • Objective: Integrate SAST, SCA, IaC scanning, image linting, and branch protection into a unified GitHub Actions workflow.
  • Tools: GitHub Actions, Semgrep, Snyk, Checkov, Trivy
  • Success Criteria: All automated checks run concurrently on PRs; non-compliant builds fail before reaching the main branch.
  • Walkthrough: Day 19: Building a Full Secure CI/CD Pipeline

Week 4: Cloud Incident Response, Threat Modeling & Posture

Lab 4.1: Simulated Incident Response on Compromised IAM Keys

  • Objective: Walk through the complete 4-phase incident response cycle when an AWS access key is leaked.
  • Tools: AWS CLI, CloudTrail, Athena, IAM
  • Success Criteria: Deactivate compromised key, revoke active STS sessions, isolate affected resources, and extract blast radius logs.
  • Walkthrough: Day 22: Cloud Incident Response

Lab 4.2: Threat Modeling with STRIDE

  • Objective: Deconstruct an application architecture, draw data flow diagrams, and map threats against STRIDE categories.
  • Tools: STRIDE Framework, Data Flow Diagrams
  • Success Criteria: Detailed threat breakdown covering Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.
  • Walkthrough: Day 23: Threat Modeling with STRIDE

Lab 4.3: CIS Benchmark Remediation Sprint

  • Objective: Audit an AWS account against the CIS AWS Foundations Benchmark v1.4 and remediate failed controls.
  • Tools: AWS Security Hub, AWS CLI, Terraform
  • Success Criteria: Remediate account baseline controls (enforce MFA on root, rotate stale keys, enable CloudTrail multi-region).
  • Walkthrough: Day 24: CIS Benchmarks & Compliance Basics

Lab 4.4: Zero Trust Network Micro-Segmentation

  • Objective: Replace flat subnet security group rules with explicit security group-to-security group references.
  • Tools: AWS VPC, Security Groups, EC2
  • Success Criteria: Web tier can only reach the app tier on designated ports; lateral movement from web directly to database is strictly blocked.
  • Walkthrough: Day 21: Zero Trust Architecture

Lab 4.5: Multi-Account Guardrails with SCPs

  • Objective: Write and attach Service Control Policies across an AWS Organization to prevent disabling security services.
  • Tools: AWS Organizations, Service Control Policies (SCPs)
  • Success Criteria: Local account administrators cannot disable CloudTrail or delete security log buckets, even with full AdministratorAccess.
  • Walkthrough: Day 2: SCPs & Permission Boundaries

Progress & Completion Matrix

Lab #Topic / ExerciseDomainStatusFull Walkthrough
1.1IAM Least Privilege & Policy SimulatorIdentityCompletedView Guide
1.2GuardDuty Threat Finding & EventBridgeDetectionCompletedView Guide
1.3AWS Config Rule & Auto-RemediationComplianceCompletedView Guide
1.4CloudTrail Forensic Analysis with AthenaForensicsCompletedView Guide
1.5AWS WAF & OWASP Managed Rules on ALBPerimeterCompletedView Guide
2.1Secrets Manager & Lambda RotationSecretsCompletedView Guide
2.2HashiCorp Vault Dynamic AWS IAM CredentialsSecretsCompletedView Guide
2.3Dockerfile Hardening & Docker BenchContainersCompletedView Guide
2.4Trivy Container CVE Scanning in CIContainersCompletedView Guide
2.5Kubernetes RBAC & Pod Security IsolationKubernetesCompletedView Guide
2.6Falco Kernel Syscall Threat DetectionRuntimeCompletedView Guide
3.1Semgrep SAST Static Code AnalysisPipelineCompletedView Guide
3.2Snyk & Dependabot SCA Dependency ScansPipelineCompletedView Guide
3.3Checkov & tfsec IaC Static Security AuditsPipelineCompletedView Guide
3.4OWASP ZAP Dynamic Application SecurityPipelineCompletedView Guide
3.5Full Secure GitHub Actions CI/CD PipelinePipelineCompletedView Guide
4.1Compromised IAM Key Containment & IRIncident ResponseCompletedView Guide
4.2STRIDE Threat Model DecompositionModelingCompletedView Guide
4.3CIS AWS Foundations Benchmark RemediationComplianceCompletedView Guide
4.4Zero Trust Network Micro-SegmentationArchitectureCompletedView Guide
4.5Service Control Policies (SCPs) GuardrailsGovernanceCompletedView Guide

You can find me online at:

My signature image

This post is licensed under CC BY 4.0 by the author.