Skip to contentSkip to content
Verified credentials. On-chain. Forever.Learn more
Ewance
Sign in
Cover image for Harden a Linux Container Runtime Against Privilege Escalation
Code

Harden a Linux Container Runtime Against Privilege Escalation

FreeVerified credential3 weeksAdvanced

Overview

What this challenge is about.

Harden EKS worker nodes with AppArmor and Falco, then replay the attack chain to prove it fails. Get a verifiable certificate.

The scenario

The SaaS (regulated under SOC 2 + ISO 27001, EU customers under GDPR) cannot wait for the next vendor-image release — a 90-day fix window is in the contract.

CredentialBlockchain-anchored
ShareableLinkedIn-ready
LanguageEnglish
PaceSelf-paced

The Brief

What you'll do, and what you'll demonstrate.

Re-baseline and harden a Kubernetes worker-node OS posture, deploy runtime detection, and prove the documented attack chain is now blocked.

Earning criteria — what you'll demonstrate

  • Baseline OS posture with kube-bench, Trivy, and OSCAP
  • Write workload-class AppArmor profiles that don't break the app
  • Deploy runtime detection (Falco) with high-signal rules
  • Validate hardening against a known attack chain end-to-end

Program Fit

Where this fits in your program.

Sharpens the same skills your degree expects you to demonstrate.

Aligned coursework coming soon.

One more thing

You can put a credential on your CV by Friday.