Command and KubeCTL: Real-World Kubernetes Security for Pentesters - Mark Manning (Shmoocon 2020)
Kubernetes is a security challenge that many organizations need to take on, and we as pentesters, developers, security practitioners, and the technically curious need to adapt to these challenges. In this talk we will look at tactics, techniques, and tools to assess and exploit Kubernetes clusters. We will demonstrate how to intercept service mesh traffic, evade runtime syscall filters, exploit custom sidecars, and chain attacks that go from compromising a build environment, to exploiting production applications. We’ll cover real world attack paths, provide practical advice, and guidance using the experience of conducting hundreds of reviews of containerized environments while running NCC Group’s container research group. Mark Manning (@antitree) is a Technical Director with NCC Group and heads the container research practice there. He has been focused on containerization and orchestration technologies like Kubernetes and performs many of NCC Group’s containerization related assessments and research. This includes running container breakouts and attack simulations on orchestration environments, performing architecture reviews of devops pipelines, and working with developers to assist with applications that leverage containerization technologies like namespace isolation, Linux kernel controls, syscall filtering, and integration with products like Docker and Kubernetes. This video is mirrored from the original upload to Internet Archive: https://archive.org/details/ShmooCon_...

Reverse Engineering Apple’s BLE Continuity Protocol - Sam Teplov (Shmoocon 2020)

Anti-Forensics for Fun and Privacy - Alissa Gilbert (Shmoocon 2020)

Attacking AI - Jason Haddix - NDC Security 2026

Kubernetes Hacking: From Weak Applications to Cluster Control

Chip Decapping on a Budget - Zach Pahle (Shmoocon 2020)

Kubernetes Zero to Hero: The Complete Beginner’s Guide (2025 Edition)

A Wireless Journeyman’s Experience in Practical SIGINT - Russell Handorf

Extracting an ELF From an ESP32 - Chris Lyne and Nick Miles (Shmoocon 2020)

Billionaire's WARNING: I'm SELLING. The Crash Is Already Here!

Adventures in Hardware Hacking or Building Expensive Tools on a Budget - Zac Franken (Shmoocon 2020)
![You’ll stop using ChatGPT after listening to this | Jonathan Pageau [ARC 2026]](https://i.ytimg.com/vi/yZUuKzDQSsI/hqdefault.jpg?sqp=-oaymwEjCNACELwBSFryq4qpAxUIARUAAAAAGAElAADIQj0AgKJDeAE=&rs=AOn4CLAXTozuIcoGA_3ys1pkvHYXgL8C4Q)
You’ll stop using ChatGPT after listening to this | Jonathan Pageau [ARC 2026]

The Path Less Traveled: Abusing Kubernetes Defaults

"Hack ANY Cell Phone" - Hacker Shows How Easy It Is To Hack Your Cell Phone

Adversary Detection Pipelines: Finally Making Your Threat Intel Useful - Xena Olsen (Shmoocon 2020)

Conan O’Brien Mocks Trump At Harvard Commencement | Crowd Erupts During Viral Speech

Hack the Stars - Yacko, Wacko, and Dot (Shmoocon 2020)

LISA19 - Deep Dive into Kubernetes Internals for Builders and Operators

Whitelisting LD PRELOAD for Fun and No Profit - Tony Lambert (Shmoocon 2020)

Kubernetes Security: Attacking and Defending K8s Clusters

