Skip to main content
00:00/00:00
Lecture 43 of 85

Restrict Kernel Modules 0231

Download Course (Free)

Course Content

0 / 85 completed
Section 1: Introduction2 videos

Exam Information 0147

2m

Course Introduction 0855

11m
Section 2: Understanding the Kubernetes Attack Surface2 videos

The 4C’s of Cloud Native security 0313

6m

The Attack 0806

23m
Section 3: Cluster Setup and Hardening31 videos

Section Introduction 0115

3m

What are CIS Benchmarks 0552

9m

CIS benchmark for Kubernetes 0241

6m

Kubebench 0115

3m

Kubernetes Security Primitives 0318

3m

TLS Introduction 0128

1m

Authentication 0534

8m

Service Accounts 1434

19m

TLS in Kubernetes 0748

11m

TLS Basics 2003

27m

TLS in Kubernetes – Certificate Creation 1055

22m

View Certificate Details 0431

8m

Certificates API 0607

7m

API Groups 0552

9m

KubeConfig 0832

15m

RBAC 0428

7m

Authorization 0730

9m

Cluster Roles and Role Bindings 0433

8m

Kubelet Security 1448

24m

Kubectl Proxy Port Forward 0648

10m

Kubernetes Dashboard 0613

12m

Securing Kubernetes Dashboard 0138

3m

Kubernetes Software Versions 0254

4m

Verify platform binaries before deploying 0211

3m

Cluster Upgrade Process 1111

13m

Network Policy 0751

16m

Developing Network Policies 1136

15m

Docker Service Configuration 0657

11m

Docker – Securing the Daemon 0725

11m

Demo – Cluster Upgrade 1137

1h 5m

Ingress 2234

37m
Section 4: System Hardening20 videos

Section Introduction 0130

3m

Minimize host OS footprint Intro 0051

1m

Least Privilege Principle 0516

5m

Limit Node Access 0548

6m

SSH Hardening 0549

6m

Privilege Escalation in Linux 0305

4m

Remove Obsolete Packages and Services 0256

5m

Restrict Kernel Modules 0231

2mNow Playing

Identify and Disable Open Ports 0221

3m

Minimize IAM roles 0546

5m

Minimize external access to the network 0212

3m

UFW Firewall Basics 0555

5m

Linux Syscalls 0420

4m

AquaSec Tracee 0320

3m

Restrict syscalls using seccomp 0837

9m

AppArmor 0409

5m

Implement Seccomp in Kubernetes 0751

10m

Linux Capabilities 0405

4m

AppArmor in Kubernetes 0244

3m

Creating AppArmor Profiles 0511

6m
Section 5: Minimize Microservice Vulnerabilities16 videos

Section Introduction 0054

2m

Security Contexts 0152

2m

Admission Controllers 0807

14m

Validating and Mutating Admission Controllers 1026

17m

Open Policy Agent OPA 0948

14m

Pod Security Policies Optional 0739

12m

OPA in Kubernetes 0945

22m

Container Sandboxing 0653

8m

Manage Kubernetes secrets 0820

13m

gVisor 0455

4m

Runtime Classes 0317

4m

kata Containers 0225

3m

Using Runtimes in Kubernetes 0223

2m

Demo Encrypting Secret Data at Rest 1847

58m

One way SSL vs Mutual SSL 0437

6m

Implement pod to pod encryption by use of mTLS 0635

10m
Section 6: Supply Chain Security6 videos

Section Introduction 0030

1m

Image Security 0443

5m

Minimize base image footprint 0724

12m

Use static analysis of user workloads egKubernetes resources Docker files 0246

4m

Whitelist Allowed Registries – Image Policy Webhook 0516

9m

Scan images for known vulnerabilities Trivy 0834

16m
Section 7: Monitoring Logging and Runtime Security8 videos

Section Introduction 0050

1m

Perform behavioral analytics of syscall process 0447

4m

Falco Overview and Installation 0253

3m

Use Falco to Detect Threats 0839

9m

Falco Configuration Files 0654

7m

Ensure Immutability of Containers at Runtime 0518

6m

Mutable vs Immutable Infrastructure 0450

4m

Use Audit Logs to monitor access 1018

12m