Seasides
trainingtechnical

EKS Goat: AWS EKS Security Masterclass

Day 3February 21, 2026
09:00 AM
Goa, India

About This Session

The EKS Goat Security masterclass includes real-world security misconfigurations like IRSA, RBAC, ECR, IMDS, network paths and attacks on AWS EKS, followed by guided defensive remediations.

The EKS Goat Security masterclass includes real-world security misconfigurations like IRSA, RBAC, ECR, IMDS, network paths and attacks on AWS EKS, followed by guided defensive remediations. It is an immersive, hands-on workshop using the OWASP EKS Goat lab to walk practitioners through end-to-end attack-and-defend workflows on Amazon EKS: exploit paths, lateral movement, credential abuse, privilege escalation, and post-exploitation, then implement mitigations with AWS IAM, admission controls, and runtime observability (Tetragon). Each red-team step is paired with a measurable blue-team defense, plus supply-chain verification and practical detection strategies.

Meet the Trainers

Anjali Shukla

Anjali Shukla

Cloud Security Engineer

Anjali Shukla is a seasoned cloud security engineer with over six years of experience in DevSecOps, Kubernetes security (EKS/GKE) as welll as AWS, Azure, GCP security. She is the founder of Kubernetes Village, a community dedicated to enhancing Kubernetes security along with leading the OWASP EKS Goat project, focusing on AWS EKS security, and actively shares her research on cloud security via her YouTube channel, @peachycloudsecurity. She has contributed to the community by volunteering at events like Cloud Village at DEF CON and BSides and is recognized AWS Community Builder. Her speaking engagements include Black Hat Spring USA, Black Hat Europe, Nullcon, Seasides Goa, BSides Bangalore, CSA Bangalore, C0c0n, and Nullcon.

View Profile →
Divyanshu Shukla

Divyanshu Shukla

Senior Security Engineer

Divyanshu Shukla is a Senior security engineer with more than seven years of experience in Cloud Security, Kubernetes Security, DevSecops, Web Application Pentesting, and Threat Modelling. Reported multiple vulnerabilities to companies like Airbnb, Google, Microsoft, AWS, Apple, Amazon, Samsung, Zomato, Xiaomi, Alibaba, Opera, Protonmail, Mobikwik, etc, and received CVE-2019-8727 CVE-2019-16918, CVE-2019-12278, CVE-2019-14962 for reporting issues. Currently co-lead of OWASP EKS Goat, Author of Burp-o-mation and a very-vulnerable-serverless application. Also part of AWS Community Builder for security and Defcon Cloud Village crew member 2020/2021/2022. Delivered talks at events like Blackhat Europe, Seasides, C0c0n, Nullcon, Brucon, Bsides Bangalore and Bsides Ahmedabad. Also winner of ""Cybersecurity samurai 2023"" at Bsides Bangalore 2023 & ""Cloud Security Champion'' at CSA Bangalore 2023.

View Profile →

Quick Info

Date

February 21, 2026

Time

09:00 AM

Location

Goa, India

EKS Goat: AWS EKS Security Masterclass | Seasides 2026