daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (2960B)


      1 ---
      2 title: "CI/CD Attacks"
      3 section: "DevOps"
      4 sectionSlug: "devops"
      5 sourcePath: "docs/devops/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/devops/README.md"
      7 sha: "203bb0c0b290"
      8 isIndex: true
      9 ---
     10 
     11 # CI/CD Attacks
     12 
     13 > CI/CD pipelines are often triggered by untrusted actions such a forked pull requests and new issue submissions for public git repositories. These systems often contain sensitive secrets or run in privileged environments. Attackers may gain an RCE into such systems by submitting crafted payloads that trigger the pipelines. Such vulnerabilities are also known as Poisoned Pipeline Execution (PPE).
     14 
     15 ## Summary
     16 
     17 - [Tools](#tools)
     18 - [CI/CD Products](#summary)
     19     - [GitHub Actions](/internal/devops/cicd-github-actions)
     20     - [Gitlab CI](/internal/devops/cicd-gitlab-ci)
     21     - [Azure Pipelines (Azure DevOps)](/internal/devops/cicd-azure-devops)
     22     - [Circle CI](/internal/devops/cicd-circle-ci)
     23     - [Drone CI](/internal/devops/cicd-drone-ci)
     24     - [BuildKite](/internal/devops/cicd-buildkite)
     25 - [Hardcoded Secrets Enumeration](/internal/devops/secrets-enumeration)
     26 - [Package Managers and Build Files](/internal/devops/package-managers)
     27 - [References](#references)
     28 
     29 ## Tools
     30 
     31 - [praetorian-inc/gato](https://github.com/praetorian-inc/gato) - GitHub Self-Hosted Runner Enumeration and Attack Tool
     32 - [AdnaneKhan/Gato-X](https://github.com/AdnaneKhan/Gato-X) - Fork of Gato - Gato (Github Attack TOolkit) - Extreme Edition
     33 - [messypoutine/gravy-overflow](https://github.com/messypoutine/gravy-overflow) - A GitHub Actions Supply Chain CTF / Goat
     34 - [xforcered/SCMKit](https://github.com/xforcered/SCMKit) - Source Code Management Attack Toolkit
     35 - [synacktiv/octoscan](https://github.com/synacktiv/octoscan) - Octoscan is a static vulnerability scanner for GitHub action workflows.
     36 - [synacktiv/gh-hijack-runner](https://github.com/synacktiv/gh-hijack-runner) - A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.
     37 - [synacktiv/nord-stream](https://github.com/synacktiv/nord-stream) - List the secrets stored inside CI/CD environments and extract them by deploying malicious pipelines
     38 - [praetorian-inc/glato](https://github.com/praetorian-inc/glato) - GitLab Attack TOolkit
     39 
     40 ## References
     41 
     42 - [Poisoned Pipeline Execution](https://web.archive.org/web/20240226215436/https://www.cidersecurity.io/top-10-cicd-security-risks/poisoned-pipeline-execution-ppe/)
     43 - [DEF CON 25 - Exploiting Continuous Integration (CI) and Automated Build systems - spaceB0x - 2 nov. 2017](https://youtu.be/mpUDqo7tIk8)
     44 - [Controlling the Source: Abusing Source Code Management Systems - Brett Hawkins - August 9, 2022](https://securityintelligence.com/posts/abusing-source-code-management-systems/)
     45 - [Fixing Typos and Breaching Microsoft’s Perimeter - John Stawinski IV - April 15, 2024](https://johnstawinski.com/2024/04/15/fixing-typos-and-breaching-microsofts-perimeter/)