Need help finding something? We're here for you

Contact Us

Need help finding something? We're here for you

Contact Us

Software Supply Chain Security for Red Teamers

Recent high-profile breaches have shown how far a single compromise can spread. This course teaches red teamers to analyze the software supply chain, emulate the attacks that exploit it, and understand the defenses against them.

rate limit

Code not recognized.

About this course

Modern software is built and delivered through complex ecosystems of source control platforms, build pipelines, dependency registries, cloud services, artifact stores, and deployment mechanisms. This course teaches red team professionals how to understand that ecosystem as a software supply chain and to analyze it as a meaningful security target. Beginning with foundational concepts, it defines the software supply chain as the full set of systems and processes involved in building, packaging, distributing, and deploying software, then shows how each stage creates distinct trust boundaries that attackers can abuse. Students will examine major real-world incidents, including compromises at SolarWinds, Codecov, event-stream, and CircleCI, along with dependency confusion research, to understand how supply chain attacks occur in practice and why their impact can extend far beyond a single application or host.

The course then shifts into hands-on and operational content, covering CI/CD pipeline fundamentals, software supply chain attack paths, defensive frameworks such as SLSA, SBOMs, and VEX, and the security controls organizations apply at each stage. It concludes by introducing the fundamentals of building an SSC red teaming practice, including scope setting, authorization considerations, tool selection, lab design, continuous self-improvement, and knowledge-sharing.

By the end of the course, students will have completed a comprehensive introduction to how modern supply chain environments can be assessed and possess a practical path forward for improving specialized red team tradecraft in a fast-growing discipline of security. 

Learning objectives

By the end of this course, students will have achieved the following learning objectives:

  • Understand what the SSC is and how it relates to the software development lifecycle (SDLC)
  • Identify the various stages in the SSC, as well as the systems and services commonly associated with each of them
  • Recognize continuous integration and continuous delivery/deployment (CI/CD) pipelines as both the vehicle that moves software artifacts between SSC trust boundaries and a valuable attack surface
  • Understand SSC defensive strategies and the mechanisms to test them effectively
  • Analyze previous incidents of SSC compromise to determine the general details of the events, their impact, what went wrong, and what the incident teaches observers about SSC security
  • Understand the concept of SSC red teaming, including its unique challenges in an offensive security consulting context, general methodologies, operational processes, and next steps to become a technically proficient practitioner

Student requirements

  • Hardware - A machine capable of running containers, e.g. Docker Desktop or Podman. There are no local virtual machines or further special software requirements to participate in this course or labs.
  • Knowledge - Some experience with network security, application security, and containerization concepts is desired, but not required.

Who this course is for

This course is directed toward cybersecurity and red team professionals with no prior knowledge of SSC fundamentals.

 

About this course

Modern software is built and delivered through complex ecosystems of source control platforms, build pipelines, dependency registries, cloud services, artifact stores, and deployment mechanisms. This course teaches red team professionals how to understand that ecosystem as a software supply chain and to analyze it as a meaningful security target. Beginning with foundational concepts, it defines the software supply chain as the full set of systems and processes involved in building, packaging, distributing, and deploying software, then shows how each stage creates distinct trust boundaries that attackers can abuse. Students will examine major real-world incidents, including compromises at SolarWinds, Codecov, event-stream, and CircleCI, along with dependency confusion research, to understand how supply chain attacks occur in practice and why their impact can extend far beyond a single application or host.

The course then shifts into hands-on and operational content, covering CI/CD pipeline fundamentals, software supply chain attack paths, defensive frameworks such as SLSA, SBOMs, and VEX, and the security controls organizations apply at each stage. It concludes by introducing the fundamentals of building an SSC red teaming practice, including scope setting, authorization considerations, tool selection, lab design, continuous self-improvement, and knowledge-sharing.

By the end of the course, students will have completed a comprehensive introduction to how modern supply chain environments can be assessed and possess a practical path forward for improving specialized red team tradecraft in a fast-growing discipline of security. 

Learning objectives

By the end of this course, students will have achieved the following learning objectives:

  • Understand what the SSC is and how it relates to the software development lifecycle (SDLC)
  • Identify the various stages in the SSC, as well as the systems and services commonly associated with each of them
  • Recognize continuous integration and continuous delivery/deployment (CI/CD) pipelines as both the vehicle that moves software artifacts between SSC trust boundaries and a valuable attack surface
  • Understand SSC defensive strategies and the mechanisms to test them effectively
  • Analyze previous incidents of SSC compromise to determine the general details of the events, their impact, what went wrong, and what the incident teaches observers about SSC security
  • Understand the concept of SSC red teaming, including its unique challenges in an offensive security consulting context, general methodologies, operational processes, and next steps to become a technically proficient practitioner

Student requirements

  • Hardware - A machine capable of running containers, e.g. Docker Desktop or Podman. There are no local virtual machines or further special software requirements to participate in this course or labs.
  • Knowledge - Some experience with network security, application security, and containerization concepts is desired, but not required.

Who this course is for

This course is directed toward cybersecurity and red team professionals with no prior knowledge of SSC fundamentals.