Reducing ECS cost with resource over-provisioning
AWS Fargate can be expensive for multi-container workloads, but over-provisioning with EC2 backed ECS isn’t as simple as you’d expect
Simon is one of the Punk Security Directors and has over 17 years experience working within IT, primarily focused on automation and InfoSec.
Simon has a wealth of experience and approaches DevOps from an infrastructure background, but is a keen Python and .NET CORE developer. He has authored two of our opensource projects, pwnSpoof and SMBeagle.
Simon worked in the UK military, before working across industry delivering automation and information security.
AWS Fargate can be expensive for multi-container workloads, but over-provisioning with EC2 backed ECS isn’t as simple as you’d expect
Our funky PCB Art badges made it back to BSIDES Cheltenham!
DevSecOps tooling can be bypassed and ignored if proper development processes are not enforced, and this is where peer approvals come in
AWS Athena is the easiest way to search organisation-wide cloudtrails implemented by AWS Control Tower. In this blog, we walk you through it.
We’re diving deep into a lesser-discussed variant of HTML injection that isn’t very well known at all, Base Tag Injection.
Developers typically use the unittest.mock module to patch the requests library directly, replacing real HTTP calls with mock objects. vcrpy makes it much easier.
We take a look at the Zed Attack Proxy as it moves away from OWASP and towards the Software Security Project
dnsReaper is designed to check your own domains, but now we’ve added Project Discovery and SecurityTrails support too!
We ran a stall, gave 2 talks and provided 400 Delorean PCB conference branches to make BSIDES Cheltenham that little bit more awesome.
We put a lot of effort into testing our CTF platform, but a simple oversight nearly meant we had to call it off.
We use Cloudflare to protect our CTF from spam bots, VPNs and hackers.
AWS IAM permission boundaries allow you to safely delegate user and role creation permissions
Our DevSecOps CTF is May 4th this year, but what makes it tick?
AWS managed Kubernetes (EKS) allows your pods to assume AWS iam roles automatically so you don’t have to handle pesky credentials.
SecretMagpie is our opensource secret detection tool, and in this article we walk you through using it against an organisation’s public repositories.
Kubernetes network policies can be difficult to write but the free cilium editor makes it really simple
Kubernetes pods can be abused to take over the entire Kubernetes cluster. rbac-police shows you which.
The Cyber Essentials scheme provides simple and clear guidance but how does it apply to cicd?
Attackers typically use stolen AWS Access keys to deploy expensive cryptomining ec2 instances, but this can be be blocked with SCPs.
Simon delivered his subdomain hijacking talk with a new twist. Why is DevOps making us more vulnerable?
With so many of our talks taking us to Manchester and London, Simon jumped at the chance for a local talk in Newcastle!
We exhibited for the first time, choosing Manchester DTX as our first ever trade event.
Daniel also spoke on the DevOps stage, giving a fantastic talk on DevSecOps
We are proud to be one of the first members of the UK Cyber Security Council, an NCSC initiative and self-regulatory body for the Cyber profession.
We evaluated the leading vendors in this space and found uSecure to be the best fit for our customers. In fact, we liked it so much that we’ve decided to include it in all of our vCISO packages for small businesses.
Hugo allows us to build a super fast website, hosted out of an AWS S3 bucket, but with all the features you need from a modern CMS.
We loved presenting our two opensource tools, pwnSpoof and SMBeagle, live at @hack.
ArgoCD allows us to deploy our apps onto Kubernetes directly from our source control, GitHub.
We kept SMBeagle shrouded in mystery until Blackhat, but now its public on Github under the apache license.
pwnSpoof had some major updates in preparation for Blackhat EU and we loved engaging with the community on its future.
Daniel was invited to present a 30 minute talk on DevSecOps at DTX in London.
It was a fantastic experience and you can stream the presentation here.