OWASP EKS Goat is a hands-on AWS EKS security lab that teaches real-world attack and defense techniques for AWS managed Kubernetes clusters.
The lab simulates realistic attack paths and defense mechanisms including misconfigured IAM roles, IRSA abuse, ECR image backdooring, RBAC privilege escalation, and pod-to-node breakout. Participants walk through both the offensive and defensive scenarios.
Attack Scenarios (includes CVE-2024-23897):
Exploit Jenkins CVE to leak IAM credentials via IMDSv2.
Backdoor ECR images using leaked credentials.
Deploy compromised image into the EKS cluster.
Escalate privileges and breakout from pod to EC2 node.
Abuse IAM roles to exfiltrate data from S3.
Defense Scenarios:
Audit cluster state using Kubescape, Kubebench, and Hadolint.
Implement Pod Security Context and enforce policies with Kyverno (CEL).
Detect runtime behavior with eBPF-based Tetragon.
Scan and lock down ECR repositories.
Integrate AWS GuardDuty for monitoring.

Project lead
Senior security engineer experienced in Cloud Security, Kubernetes Security, DevSecops, Web Application Pentesting, and Threat Modelling. Reported multiple vulnerabilities to companies like Airbnb, Google, Microsoft, AWS, Apple, Amazon, Samsung, Zomato, Xiaomi, Alibaba, Opera, Protonmail, Mobikwik, etc, and received CVE-2019-8727 CVE-2019-16918, CVE-2019-12278, CVE-2019-14962 for reporting issues. Currently co-lead of OWASP EKS Goat, OWASP GKE Goat, Author of Burp-o-mation and a very-vulnerable-serverless application. Also part of AWS Community Builder for security and Defcon Cloud Village crew member 2020/2021/2022. Delivered talks at events like Blackhat Europe, Seasides, C0c0n, Nullcon, Brucon, Bsides Bangalore and Bsides Ahmedabad. Also winner of "Cybersecurity samurai 2023" at Bsides Bangalore 2023 & "Cloud Security Champion'' at CSA Bangalore 2023. Reach out at peachycloudsecurity[dot]com

Project lead
Anjali is a seasoned cloud security engineer experienced in DevSecOps and Kubernetes security (EKS/GKE) as well as AWS, Azure, and GCP security. She is the founder of Container Security Village and Kubernetes Village, communities dedicated to enhancing cloud-native security. As the project lead for OWASP EKS Goat, she focuses on AWS EKS security research and hands-on exploitation paths. Anjali is a recognized AWS Community Builder and actively shares her research through her YouTube channel, @peachycloudsecurity. Her extensive speaking history includes Black Hat Spring USA, Black Hat Europe, Nullcon, Seasides Goa, BSides Bangalore, CSA Bangalore, and C0c0n. She has also contributed to the community by volunteering at Cloud Village at DEF CON and various BSides events globally.Reach out at peachycloudsecurity[dot]com