Companies Home Search Profile

Container Infrastructure Analysis with Trivy

Focused View

Zach Roof

49:32

93 View
  • container-infrastructure-analysis-trivy.zip
  • 1. Course Overview.mp4
    01:14
  • 1. What Is Trivy_.mp4
    07:34
  • 2. Installation.mp4
    02:42
  • 3. Demo 1_ Reactive Integration Overview.mp4
    02:39
  • 4. Demo 1_ Trivy Scan.mp4
    03:54
  • 5. Demo 2_ Proactive Approach (Consumer View).mp4
    07:53
  • 6. Demo 2_ Proactive Approach (Technical View).mp4
    04:20
  • 7. Demo 3_ Docker Image Tampering Github Workflow.mp4
    04:29
  • 8. Demo 3_ Docker Image Tampering Script.mp4
    05:18
  • 9. Demo 3_ Docker Image Tampering Check.mp4
    06:26
  • 1. Next Steps.mp4
    03:03
  • Description


    Want to learn how to find vulnerabilities in docker images? How about preventing these vulnerabilities in the first place? If so, you're in the right place! In this course you will learn Container Infrastructure Analysis with Trivy.

    What You'll Learn?


      In this course, we will focus on automating docker image security scans:

      1. use Trivy (and a Github Action) to scan Dockerfiles within Github
      2. use Trivy to uncover a malicious image within a Docker registry
      3. perform an analysis on the malicious image to uncover the source of compromise
      When you’re finished with this course, you’ll have the skills and knowledge to detect these techniques: Supply Chain Compromise (T1195), Implant Container Image (T1525).

    More details


    User Reviews
    Rating
    0
    0
    0
    0
    0
    average 0
    Total votes0
    Focused display
    Category
    Zach describes himself as “an ordinary guy who’s extraordinarily curious about technology.” This curiosity has led to roles in Software Development, Application Security, DevOps, and Security Engineering. Currently, Zach is the Lead Security Engineer at Credible where he helps lead the security vision of a highly sensitive Fintech product. Outside of his day job, Zach has spoken at SyntaxCon, created cybersecurity tutorials through Securing The Stack, led an AWS Meetup group, and has provided cybersecurity consulting services. When not hitting the keyboard, Zach is hitting the trails! He is an avid hiker and enjoys the simplicity of nature. In fact, Zach’s favorite quote is “Simplicity is the ultimate sophistication” by Leonardo Da Vinci. Zach’s fondness of simplicity has manifested in his tutorials, where he aims to simplify complex topics in the areas of Software Development, DevOps, and Security.
    Pluralsight, LLC is an American privately held online education company that offers a variety of video training courses for software developers, IT administrators, and creative professionals through its website. Founded in 2004 by Aaron Skonnard, Keith Brown, Fritz Onion, and Bill Williams, the company has its headquarters in Farmington, Utah. As of July 2018, it uses more than 1,400 subject-matter experts as authors, and offers more than 7,000 courses in its catalog. Since first moving its courses online in 2007, the company has expanded, developing a full enterprise platform, and adding skills assessment modules.
    • language english
    • Training sessions 11
    • duration 49:32
    • level average
    • English subtitles has
    • Release Date 2023/02/27