ON-DEMAND

Pwned Labs Kubernetes Attack & Defense Bootcamp - Professional Edition


Launches 20 October. Early bird pricing: $349 until launch, then $399.


Hands-on Kubernetes attack and defense training focused on real-world attack paths, from minikube to EKS, GKE and AKS.


Ideal for: penetration testers, red and purple teamers, cloud and platform security engineers, DevOps engineers, and detection engineers. No prior Kubernetes experience required.


Four sessions, each under four hours, taking operators from zero Kubernetes knowledge to root on a node and on into the cloud account behind it

 

Pwned Labs Kubernetes Attack & Defense Bootcamp - Professional Edition Overview

KRTP-certificate

The cloud is built on Kubernetes!

This on-demand bootcamp and structured learning path teaches practical techniques for attacking and defending Kubernetes. Session one builds the fundamentals on neutral ground in minikube, since most Kubernetes attack tradecraft is identical across EKS, GKE and AKS. Sessions two and three then show that managed Kubernetes relocates the prize to the node identity, and that turning a service account token into a cloud credential is the same core primitive on every provider. Session four is the purple capstone.

After completing the bootcamp and associated learning path, you will validate your skills in a fully hands-on, unproctored exam that requires completing an end-to-end exploitation chain.

The exam environment is dynamic, with scenarios changing regularly to reflect real-world Kubernetes and cloud attacks and ensure certification credibility.

kubernetes

Prerequisites and key learning outcomes

You should be comfortable with the Linux command line and with reading YAML and JSON. Familiarity with containers helps but is not required. No prior Kubernetes experience is required: session one takes a student who has never touched Kubernetes through to root on a node.

After completing the bootcamp and passing the exam, you will demonstrate proficiency in:

  • Explaining Kubernetes as a set of attackable trust boundaries, and distinguishing the control plane from the data plane
  • Enumerating a cluster from an unauthenticated external position and from a low-privilege pod foothold
  • Analyzing service account tokens and RBAC to determine permissions and recognize verbs equivalent to cluster-admin
  • Escalating to cluster-admin via RBAC misconfigurations, escaping the container to the host node, and dumping every secret in the cluster
  • Reaching the Instance Metadata Service from a pod and abusing IRSA, EKS Pod Identity and Fargate task credentials
  • Turning a projected or federated service account token into a cloud credential on EKS, GKE and AKS
  • Establishing in-cluster and cloud-side persistence, weaponizing admission webhooks, and evading runtime and audit controls
  • Analyzing Kubernetes audit logs, applying cloud-native detections, hunting your own persistence, and producing a purple team report
waypath

What you get

You get ongoing access to the full Kubernetes security curriculum, organized into four pillars that align to the four sessions: core Kubernetes attack, the EKS deep dive, GKE and AKS, and the purple capstone. Each pillar includes its own learning path so you can hit the ground running before the session starts.

  • Lifetime access to the latest session recordings, updated slides and command guides, bootcamp labs, and all future course updates
  • 45 days of Academy lab access for the learning paths tied to each session, starting from when you redeem your voucher rather than from purchase, with no deadline to claim and extendable with subscription
  • Direct preparation for the KRTP certification exam
  • More information on the bootcamp, learning paths, and the KRTP exam is available here
TeamTNT

Focus on trending techniques and tradecraft

The Pwned Labs Kubernetes Attack & Defense Bootcamp - Professional Edition covers attacker tradecraft drawn from real Kubernetes and cloud security assessments, generalized into vendor-neutral, teachable patterns. This includes tradecraft seen in campaigns such as TeamTNT, which worms across exposed Kubernetes clusters and steals cloud credentials from compromised nodes, and the RBAC Buster campaign, which abuses an exposed Kubernetes API to plant a hidden ClusterRoleBinding for persistent cluster control. Labs run against realistic clusters, starting in minikube and moving into managed Kubernetes on all three major providers.

You will learn how to:

  • Reproduce tradecraft from real Kubernetes and cloud findings
  • Execute attacks using current red team tooling and manual tradecraft
  • Design controls and detections that reduce blast radius

Meet the team

Our instructors are on hand in Discord to help whenever you need it.

ayush-2

Ayush Singh is a co-instructor on this bootcamp and part of the Pwned Labs offensive security team.

He has built a wide range of Kubernetes, GCP, and Google Workspace tools and projects for the security community, and has authored many of the Kubernetes labs on the Pwned Labs platform.

His offensive enumeration and analysis work across cloud and Kubernetes environments directly informs the course content.

Ian_Austin

Ian Austin is a security researcher and educator with a career spanning over 20 years in technical, security and leadership roles for global enterprises.

Ian was Head of Content at Hack The Box, a leading online platform for cybersecurity training and assessment. He also participated in the Green Team of Locked Shields, a NATO cyber defense exercise, contributing to the design and execution of realistic scenarios.

He is the founder of Pwned Labs, providing gamified and immersive cloud security labs for red and blue teams.

kubernetes_cloud

How it works

This on-demand bootcamp launches 20 October. Enroll now to lock in early bird pricing, then work through the learning path and labs at your own pace once it goes live. Your purchase includes 45 days of lab access and two KRTP exam attempts. The 45 days begins when you redeem your voucher rather than at purchase, and there is no deadline to claim it. Lab access is extendable with subscription. Support is available via Discord.

 


Purchase options


Each bootcamp purchase includes two attempts at the KRTP exam. Additional re-attempts can be purchased separately.

Bootcamp registration is required to attempt the exam.

Bulk and team purchases are available.

aisrtp_pricing
exam_reattempt-2

Ask your employer to fund KRTP


Need employer funding approval? Use our ready-made employer funding request to outline the value of the Pwned Labs Kubernetes Attack & Defense Bootcamp - Professional Edition and the KRTP certification.

Prefer to self-fund? You can enroll now.

 

Got any Questions? Get in touch