Official Website link
Date: October 6-8, 2026 | 3 Day Pre-Conference Training (9:00 AM - 5:30 PM)
Location: Grand Hyatt, Bolgatty, Kochi, Kerala
Track: Pre-Conference Trainings (T8)
Format: 3 Day Training
Instructor: Anant Shrivastava | Founder, Cyfinoid Research
Course Overview
GitHub is where code, identity, automation, and release trust meet. If your org ships software, your GitHub org is part of your production environment.
This training shows how attackers abuse GitHub Actions, runners, tokens, and integrations to compromise builds and releases, then switches to defense with a practical hardening playbook and an organization level security review. The format is hands-on and scenario driven, with guided labs for every module plus a capstone where participants attack a vulnerable GitHub org end to end, document the chain as an incident narrative, apply defenses that break the chain, and re-test to confirm the fixes.
Topics Covered
- Module 1: GitHub Actions and runner fundamentals
- Module 2: Threat modeling GitHub CI/CD
- Module 3: Recon and initial access paths
- Module 4: Workflow exploitation techniques
- Module 5: Pull request trust boundaries
- Module 6: Self-hosted runner compromise and lateral movement
- Module 7: Release and distribution compromise
- Module 8: Hardening workflows and dependencies
- Module 9: Secure deployments from GitHub
- Module 10: Organization level security review and hardening workshop
Key Takeaways
- Map real GitHub CI/CD attack paths, from initial access to release compromise
- Identify insecure workflow patterns and fix them using safer defaults
- Understand GitHub token and secret exposure paths, and reduce blast radius
- Secure GitHub Actions usage across the org with policies and guardrails
- Harden self-hosted runners and design safer runner topologies
- Build an org level security review checklist that can be repeated every quarter