Focus Areas:
π Application Security
, βοΈ Cloud Security
, βοΈ DevSecOps
, πͺͺ Identity & Access Management
, π Vulnerability Management
This Tool Demo covers following tools where the speaker has contributed or authored
GCPGOAT
GCPGOAT
Abstract
GCPGoat is a vulnerable by design infrastructure on GCP featuring the latest released OWASP Top 10 web application security risks (2021) and other misconfiguration based on services such as IAM, Storage Bucket, Cloud Functions and Compute Engine. GCPGoat mimics real-world infrastructure but with added vulnerabilities. It features multiple escalation paths and is focused on a black-box approach.