WS1 - CI/CD Weaponization: Build It, Deploy It, Own It
Description
Instructed by: Ricardo Sanchez
Level of Difficulty: Beginner, Intermediate
Abstract:
GitHub Actions has become the de facto automation layer for modern software, and the de facto attack surface. In 2025, a single compromised Action leaked secrets across 23,000 repositories. One year later, the TeamPCP group ran the same playbook at scale by compromising Trivy's actions. Different victims, same root cause: a CI/CD pipeline that trusted what it shouldn't.
In this hands-on workshop, participants will build a complete end-to-end attack chain in a controlled lab environment, emulating adversary TTPs observed in recent GitHub Actions breaches. From initial access through malicious workflow manipulation to secret exfiltration, each phase is paired with detection and analysis techniques to bridge offensive and defensive perspectives.
Whether you're on a red or purple team looking to simulate attacker behavior, or part of a blue team (AppSec or DevSecOps) aiming to harden CI/CD pipelines, this workshop delivers practical, real-world skills grounded in today’s evolving threat landscape.
Pre-Requisites:
· Basic knowledge in GitHub and bash
· Ability to read JavaScript and Python code
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity


