Session

Detecting Compromised CI with eBPF and Cilium Tetragon

CI/CD pipelines are a prime target for attackers. Recent incidents, such as the Trivy workflow compromise, show how CI can be abused to execute untrusted code and exfiltrate sensitive data.

Tetragon, the eBPF-based runtime security component of the Cilium project, is widely used to protect Kubernetes workloads. This talk shows how it can also be applied to CI environments such as GitHub Actions to detect compromised jobs and prevent data exfiltration.

After a brief introduction to how Tetragon leverages eBPF, this talk demonstrates its use in GitHub Actions, providing runtime signals that reveal malicious behavior. You’ll see concrete examples of policies that observe process and network activity to detect unexpected outbound connections and identify compromised jobs in real time.

Attendees will learn practical techniques to use Tetragon to detect and prevent malicious behavior in ephemeral CI environments.

Liz Rice

Chief Open Source Officer, Isovalent @ Cisco

London, United Kingdom

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top