Event Hack Red Con 2024 starts on Oct 25, 2024, 10:00:00 AM (America/Kentucky/Louisville)
Abusing DevOps to Pivot Between Cloud and On-Prem
2Hr Workshop
Location: Workshop 2 - 10/26/24, 2:00 PM - 10/26/24, 4:00 PM (America/Kentucky/Louisville) (2 hours)
Tom Porter
Red Team Operator, FusionX | Accenture Security
Tom Porter
Red Team Operator, FusionX | Accenture Security

Tom Porter

Tom is a Senior Red Team Operator at FusionX / Accenture and has spent the last decade consulting with Fortune 100 organizations as an offensive security practitioner. He has spoken or led trainings at several industry conferences, focusing on advanced tradecraft, building high-performing red teams, mentoring in InfoSec, and attacking cloud platforms. He began his career building DevOps pipelines and crafting detections for a Department of Defense blue team, eventually transitioning to PCI-based penetration testing. Prior to his career in cybersecurity, Tom was a professional baseball player, and he now spends most of his free time throwing baseballs in the backyard with his three young children.

 https://www.twitter.com/porterhau5

Colbert Zhu

Colbert Zhu is an offensive security consultant with experience in penetration testing, purple teams, and objective-based adversary simulations. Colbert is also an avid Yankees fan and fond of making Excel spreadsheets for fantasy baseball. 

 https://www.linkedin.com/in/colbert-zhu/


Workshop Description:


As more scrutiny is placed on the endpoint, threat actors are turning to DevOps and CI/CD platforms for initial access, escalation, and lateral movement. This workshop will showcase how these platforms can be used to pivot from on-prem to cloud, from cloud to on-prem, and how to push malicious code through pipelines to obtain additional access or establish persistence.

Attendees will get hands-on and perform field-tested, OPSEC-conscious techniques against full CI/CD pipelines. Come add TTPs to your toolkit and see why DevOps is the target-rich environment modern adversaries are looking to exploit.