Continuous Security Testing with OWASP secureCodeBox in Kubernetes - Jannik Hollenbach

35:41 · 03 Sep 2024 – 04 Sep 2024 · YouTube

About this talk

This talk introduces OWASP secureCodeBox, an open-source Kubernetes operator designed to schedule and orchestrate the execution of various security scanning tools such as ZAP, Nuclei, Trivy, and Nmap. The speaker discusses how secureCodeBox streamlines the execution of scans via a Scan custom resource, enabling easy integration of scan results with finding management systems like OWASP DefectDojo for effective tracking and analysis of security findings. Additionally, the optional AutoDiscovery component is highlighted, which automates the detection of applications within Kubernetes clusters and facilitates the scheduling of scans, including Trivy scans for container dependencies and dynamic scans against HTTP services. Jannik Hollenbach, a Software Security Engineer at iteratec GmbH and a contributor to the OWASP secureCodeBox and Juice Shop projects, shares insights from his extensive experience with open-source security testing tools.

From event

ContainerDays Conference 2024

03 Sep 2024 – 04 Sep 2024

All event videos
Back to Watch