K8SEC.IO / Offensive Research & Training

KAOS

K8sec Agentic Offensive Security

Attack the architecture, not only the prompt.

KAOS is a hands-on learning and certification program for security practitioners assessing agentic systems. It covers the full path from untrusted input and model decisions to MCP tools, APIs, workload identities, memory systems, containers and Kubernetes.

01 / Why KAOS exists

One system. Multiple security domains.

Agentic applications combine probabilistic decisions with conventional software, identities and infrastructure. A credible assessment follows the complete execution path instead of isolating the model.

01

AI security

02

Application and API security

03

Identity and authorization

04

MCP and tool security

05

RAG and memory integrity

06

Container security

07

Kubernetes and cloud security

08

Observability and digital forensics

02 / Execution architecture

Trace every boundary.

The model proposes. Policy and software authorize. An identity executes. Telemetry and persisted state prove what happened.

INPUT / 01

External Input

User, document, message, event or retrieved content enters the system.

DECIDE / 02

Agent / Planner

Models and reasoning loops propose steps, calls and delegations.

AUTHORIZE / 03

Policy Gate

Code, policy and human controls decide whether a proposal may proceed.

DISPATCH / 04

MCP / Tools

Tool registries and MCP clients translate intent into callable capabilities.

EXECUTE / 05

APIs / Workloads

REST, JSON-RPC, services and executors perform concrete operations.

IDENTIFY / 06

Kubernetes Identity

ServiceAccounts, tokens and RBAC determine infrastructure authority.

PERSIST / 07

Memory / RAG

Memory, retrieval stores and vector databases influence future decisions.

Identity Authorization Trust Telemetry Evidence

Example attack surfaces across the path

Direct and indirect prompt injection

Tool-description poisoning

Excessive tool permissions

Confused deputy

Memory poisoning

Retrieval poisoning

Cross-agent trust abuse

Token or workload-identity misuse

Unsafe executor behavior

Kubernetes RBAC escalation

Textual path: External Input → Agent / Planner → Policy Gate → MCP / Tools → APIs / Workloads → Kubernetes Identity → Memory / RAG. Identity, authorization, trust, telemetry and evidence apply across every boundary.

03 / Methodology

From map to containment.

KAOS assessments require architecture analysis, manual validation and reproducible evidence—not an attacking agent asked to find vulnerabilities.

01

Map

Identify agents, tools, data stores, identities and trust boundaries.

02

Trace

Follow a task from input through planning, authorization, execution and persistence.

03

Test

Validate instruction, tool, memory, API and infrastructure attack surfaces.

04

Prove

Capture code, traces, identities, authorization decisions and reproducible evidence.

05

Contain

Recommend controls that break the demonstrated attack path.

04 / Learning path

Build operator capability.

The curriculum is sequenced around observable capability gates. Module durations and public materials will be published when they are validated.

05 / Practical labs

More than prompting.

Candidates work across source, configuration, protocol, identity, runtime and infrastructure evidence. Every result must be manually validated and reproducible.

  • Inspect source code and configuration
  • Enumerate MCP capabilities
  • Map tool permissions
  • Trace model output separately from executor action
  • Analyze memory provenance
  • Manipulate controlled lab inputs
  • Validate identity and authorization decisions
  • Write scripts or custom checks
  • Correlate behavior with container and Kubernetes evidence
  • Produce a defensible attack-path report
  • Recommend and validate remediation
06 / K8SEC + KAOS

Infrastructure intelligence, operator judgment.

K8SEC maps Kubernetes resources, identities, exposures and attack paths. KAOS trains practitioners to test the wider agentic architecture across APIs, MCP, containers, cloud infrastructure and Kubernetes.

K8SEC Agent supplies read-only Kubernetes graph intelligence. It maps services, pods, ServiceAccounts, RBAC relationships, network exposure and attack paths. The human operator must correlate that evidence with the agentic control and data planes.

ServiceEXPOSESPod PodUSES_SAServiceAccount ServiceAccountBINDS_ROLERole PodRUNS_ONNode WorkloadREACHABLE_FROMWorkload
07 / Planned certification

KAOS Practical Operator Assessment

A planned 24-hour, performance-based assessment in an isolated agentic and Kubernetes environment. The assessment emphasizes architecture analysis, manual validation and professional reporting.

24-hour performance-based assessment Isolated environment Multiple attack surfaces Evidence-driven scoring Architecture analysis Manual validation Limited custom tooling Attack-path reconstruction Remediation recommendations Professional report
08 / Current availability

Clear release status.

No course handbook, lab package or registration workflow is public yet. Download actions stay hidden until reviewed assets exist.

    K8SEC.IO / KAOS

    Agentic security is systems security.

    KAOS develops operators who can reconstruct the entire path from instruction to infrastructure action.