Continuous Security Testing with OWASP secureCodeBox in Kubernetes - Jannik Hollenbach
About this talk
This talk introduces OWASP secureCodeBox, an open-source Kubernetes operator designed to schedule and orchestrate the execution of various security scanning tools such as ZAP, Nuclei, Trivy, and Nmap. The speaker discusses how secureCodeBox streamlines the execution of scans via a Scan custom resource, enabling easy integration of scan results with finding management systems like OWASP DefectDojo for effective tracking and analysis of security findings. Additionally, the optional AutoDiscovery component is highlighted, which automates the detection of applications within Kubernetes clusters and facilitates the scheduling of scans, including Trivy scans for container dependencies and dynamic scans against HTTP services. Jannik Hollenbach, a Software Security Engineer at iteratec GmbH and a contributor to the OWASP secureCodeBox and Juice Shop projects, shares insights from his extensive experience with open-source security testing tools.
More from this event
See all 77 talks →
Fireside Chat with Kelsey Hightower & Sebastian Scheele
44:16
Coping with Zero Days with Cilium Tetragon - Liz Rice
42:15
Building Trust in Fintech: DevSecOps Strategies at Saxo Bank - Jinhong Brejnholt
35:35
Seven years and counting – The DevOps journey at Hermes Germany - Stephan Stapel
34:16