Join our colleague Constanze Roedig, key researcher at SBA Research, at KubeCon & CloudNativeCon, in Salt Lake City, USA, where she will present Gone in 60 Minutes: Effectively Close the Exploitable Window with Detection as Code with Ben Hirschberg.
© Constanze Roedig
Abstract
Platform teams have shift-left covered: scanners on every PR, admission control on every deploy, SBOM+VEXs on every image. Then a high-severity CVE drops with “patch coming soon,” and all of it goes quiet for days while a known-exploitable workload sits in production. This is the most uncomfortable corner of day-2 on Kubernetes, and most teams have no declarative answer for it.
We’ll show how Kubescape, the CNCF incubating project for Kubernetes security, makes runtime detection a Kubernetes resource: a Rule CRD you review in a PR, version in Git, deploy via Argo or Flux, and roll back like any other manifest. Using the TeamPCP Trivy compromise as an example, we’ll cover what the eBPF sensor sees, how to turn an advisory/IoC into a Rule CRD live on stage, how SBOB profiles keep the signal trustworthy, and a CI/CD workflow that gets from “CVE published” to “rule deployed” in under an hour. For platform engineers, SREs, app developers, and security teams alike.
About the conference
KubeCon + CloudNativeCon is one of the leading global gatherings for the cloud-native community, bringing together developers, engineers, architects, and open-source contributors from around the world. The event showcases the latest developments in Kubernetes, cloud-native technologies, platform engineering, security, observability, and AI, while providing opportunities to learn, share experiences, and connect with the community.
