Session

Hardening GitHub: From Default to Defended

GitHub ships with sensible defaults. The problem is that sensible defaults aren't security controls - and the gap between them is where real attacks land.

In this demo-heavy session, we go hands-on with the security decisions that most organizations either skip, misconfigure, or misunderstand. Through live demonstrations, we'll trace how attackers exploit workflow triggers, overly permissive tokens, unpinned Actions, and bypassed secret protection - then close each gap in real time.

We'll also connect GitHub security to the broader Microsoft security stack - how Defender for Cloud surfaces DevOps posture findings, how Entra workload identity federation replaces long-lived secrets in pipelines, and how to get GitHub audit signals into your existing detection and response workflows.

This isn't a product overview. Every demo is rooted in attack patterns being used right now, with fixes you can apply the same week.

Pierre Thoor

Microsoft Security MVP · Senior Cloud Security Architect @ Onevinn · Author

Helsingborg, Sweden

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top