tryhackme 18
- Cloud-based IaC - Terraform, AWS CloudFormation, and Secure IaC Practices
- On-Premises IaC - Vagrant Provisioning, Ansible Automation, and Pipeline Exploitation
- Intro to IaC - Declarative vs Imperative, Lifecycle, and Virtualisation Primitives
- Container Hardening - Daemon Protection, Cgroups Limits, Seccomp, AppArmor, and Grype Image Auditing
- Container Vulnerabilities - Breakouts via Privileged Capabilities, Docker Sockets, Exposed TCP, and Host Namespaces
- Intro to Kubernetes - Cluster Architecture, Declarative YAML, Kubectl Operations, and RBAC Hardening
- Intro to Docker - Image Lifecycle, Dockerfiles, Compose Orchestration, and Socket Architecture
- Intro to Containerisation - Docker Architecture, Linux Namespaces, and Process Isolation
- Mother's Secret - Code Review, Route State Machine Exploitation, and Path Traversal in Node.js
- DAST - Dynamic Application Security Testing, OWASP ZAP, Authenticated Scans, and CI/CD Automation
- SAST - Static Application Security Testing, AST Modeling, Taint Analysis, and Semgrep Rules
- Dependency Management - Supply Chain Attacks, S3 Skimmers, and Python Dependency Confusion
- CI/CD and Build Security - Pipeline Exploitation, Build Runner Poisoning, and Environment Segregation
- Source Code Security - Git Internals, Credential Hygiene, and Secrets Management in CI/CD
- Intro to Pipeline Automation - CI/CD Architecture, Build Agent Security, and Environment Segmentation
- Secure Software Development Lifecycle (SSDLC) - Methodologies, Threat Modelling, and Testing Automation
- Software Development Lifecycle (SDLC) - Phases, CALMS Framework, and Core Delivery Metrics
- Introduction to DevSecOps - Cultural Evolution, Shift-Left Security, and Pipeline Shared Responsibility