In cloud-native reality, pentest makes its way as a security assessment where we audit Kubernetes users, API limits, authentication, and other Kubernetes policies making sure your team could deploy and run code securely.
A. Kubernetes Configuration Audit
We deliver a technical audit of Kubernetes \ OpenShift cluster configuration, particularly in the following ten areas:
Authentication
Authorisation
Secrets Management
Cryptography
Multi-tenancy & Pod security
Protection for privileged accounts
Protection for cluster networking
Vulnerability management
Monitoring and logging
Management and integration
B. Pipeline Analysis
As a second step, we complement Kubertenes security assessment by analysing neighbouring areas:
Image Security (dockerfile)
Application Security checks (pipeline)
Leaked Secrets and Tokens (including Kubernetes configmap)
C. Kubernetes Security Framework
There we design a cybersecurity framework for a Kubernetes cluster that works, making controls on three core layers that delivers results:
Built-in security controls of Docker, Docker Swarm, Kubernetes or OpenShift.
Using your existing security controls (SIEM, Identity Providers, Vaults and Privileged Access Management) or any Kubernetes security tools.
Drafting RFPs to support tendering and procurement of specialized OpenShift and Kubernetes security suites.
Our Cases on K8S Penetration Testing
Kubernetes Security Assessment for US Retail Chain
Key Findings:
- weak authentication;
- secrets were stored in plain text;
- direct deployment from dev network.
OpenShift Security Assessment for Digital Bank in Europe
Key Findings:
- public access to etcd;
- all containers ran under root;
- all users were admins.
PCI DSS Penetration Testing for FinTech Amaiz Ltd.
We maintain a laser focus on API Penetration Testing and related disciplines
Digital Experience
We provide Customer Portal access with all findings and recommendation for each customer - the portal could be connected to customers' systems like Jira
Professionalism
We employ experts with 5+ years of experience delivered security assessments for UK, EU, US, Hong Kong and Israeli companies