Skip to Main Content

InfoSec World 2-Day Workshop - Supply-Chain to Runtime: Attacking & Defending the Modern DevOps Stack

Registration is now open for our InfoSec World training on October 11-12, 2026.

October 11, 2026
Threat Hunting Red Team Adversarial Attack Simulation

Join us for this two-day, in-person workshop at InfoSec World!

It’s 2026 and developers have become the new focus for attackers seeking to elevate privileges quickly and quietly while operating in enterprise environments. Building upon processes and technologies commonly found in real-world environments, this course will walk students through a comprehensive attack path centered on enterprise DevOps technologies, processes, misconfigurations, and attacks.

During this course students can expect to:

  • Gain familiarity with a standard enterprise development workflow
  • Enumerate and triage source code repositories
  • Exploit build pipelines to compromise secrets and achieve remote code execution
  • Exploit common devops integrations such as: chat bots, secret servers, and AI assistants to elevate operational privileges
  • Understand potential supply chain exposures within your enterprise
  • Read and write detective alerts for each attack

Taught by Senior Security Engineer Mike Spitzer, Managing Director of Offensive Security Jason Lang, and Principal Security Consultant Sam Link.

* Please note: Starred sessions (⭐️) are included for All-Access Passholders only; Main Conference registrants may attend for an additional fee.