Session
Gone in 60 Minutes: Effectively Close the Exploitable Window with Detection as Code
Platform teams have shift-left covered: scanners on every PR, admission control on every deploy, SBOM+VEXs on every image. Then a high-severity CVE drops with "patch coming soon," and all of it goes quiet for days while a known-exploitable workload sits in production. This is the most uncomfortable corner of day-2 on Kubernetes, and most teams have no declarative answer for it.
We'll show how Kubescape, the CNCF incubating project for Kubernetes security, makes runtime detection a Kubernetes resource: a Rule CRD you review in a PR, version in Git, deploy via Argo or Flux, and roll back like any other manifest. Using the TeamPCP Trivy compromise as an example, we'll cover what the eBPF sensor sees, how to turn an advisory/IoC into a Rule CRD live on stage, how SBOB profiles keep the signal trustworthy, and a CI/CD workflow that gets from "CVE published" to "rule deployed" in under an hour. For platform engineers, SREs, app developers, and security teams alike.
Dr. Constanze Roedig
Independent OpenSource Maintainer and Cybersecurity Researcher
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top