Official Website link
Date: June 15–17, 2026 | 3 Day Training
Time: 9:00 AM – 5:30 PM IST
Location: Bengaluru (Physical)
Level: Intermediate
Format: 3 Day Hands-on Training
Instructors: Anant Shrivastava (Founder, Cyfinoid Research), Sunil Yadav (Founder / Head of Security, x-biz Techventures)
Course Overview
Comprehensive training covering offensive and defensive strategies for software supply chain security. Attendees learn to identify and exploit vulnerabilities across the delivery lifecycle, then implement industry-standard frameworks (SLSA, NIST SSDF) through hands-on labs.
In 2026, supply chain attacks remain some of the hardest threats to understand and some of the easiest for attackers to exploit — targeting developers, automation, and the software delivery lifecycle itself, from poisoned packages and malicious IDE plugins to build hijacks.
Topics Covered
- Software Supply Chain Architecture & Threat Landscape
- Developer Environment & IDE Security
- Git & GitHub Misconfigurations
- Dependency & Package Management Security
- CI/CD Pipeline Exploitation & Defense
- Container Image Security
- Kubernetes & Cloud Attack Paths
- IAM & Cloud Configuration Security
- Supply Chain Provenance & Verification
- SLSA Framework Implementation
- NIST SSDF Standards
- Software Bill of Materials (SBOM)
- Runtime Security & Threat Detection
- Incident Response & Recovery
Training Curriculum
Part 1 — From the Attacker’s Perspective
- Introduction to software supply chain (beyond code dependencies)
- Exploiting VS Code workspaces; trojanizing IDE & browser extensions
- Git & GitHub misconfigurations; attacking CI pipelines & custom runners
- Creating malicious dependencies; attacking package ecosystems (npm, gradle, etc.)
- Exploiting deployment systems (GitHub & ArgoCD) and container image misconfigurations
- Cloud & Kubernetes attack paths (IAM, data, configurations, insecure defaults)
Part 2 — From Vulnerability to Fortification
- Defense strategies with SLSA and NIST SSDF; top-down governance
- Effective inventory management & SBOMs; establishing, storing & verifying provenance
- Protecting assets & establishing baseline security; cloud audits
- Runtime security, threat detection, response & recovery
- Mapping roles and responsibilities; securing against the attacks covered in Part 1