talk
Linux Investigations & Hacking the CI/CD pipeline
DC416’s February meetup, with two technical talks and an open floor. Julian Pileggi, a principal incident response consultant at Mandiant, gave an introduction to Linux investigations, covering which artifacts to check when responding to an incident on a single Linux system and how to set an environment up so it’s easier to investigate. Geoff Heymann of Security Compass presented “Your CI/CD Pipeline is my CI/CD Pipeline”, on how an attacker can use a pipeline to compromise an application or the infrastructure around it.
The open floor was for any DC416 tribe that wanted to share a hacker project it had been working on. Mandiant, a FireEye Company, sponsored the night.
Sources & references