Session
Building a digital beehive: The cluster that wasn't real, but the attacks were
Kubernetes is everywhere now—and so are attacks against it. Misconfigurations, exposed APIs, and overly permissive RBAC have made clusters a prime target, while most security tools stop at scanning images and YAML instead of showing what attackers do after they get in.
This talk introduces KubeDecoy – a lightweight, open-source Kubernetes honeypot built from familiar components: vcluster, Falco, Falcosidekick, and NGINX. The goal is simple: stand up a convincing fake cluster, expose realistic attack surfaces, and quietly observe how real adversaries interact with them.
We’ll walk through the architecture, a live-style deployment on Minikube, and practical workarounds for vcluster’s limitations using only open-source components. Along the way, we’ll map KubeDecoy’s detections to the Kubernetes Threat Matrix, highlight where it shines (and where it doesn’t), and show how you can apply these ideas in your own clusters—whether you’re blue team, red team, or somewhere in between.
Arnav Tripathy
Security Operations at Kaseya. Breaking things in Dev, Sec, and Ops — usually all three at once
Dublin, Ireland
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top