+
Skip to content
View some-natalie's full-sized avatar
💖
I may be slow to respond. Slack/text if urgent.
💖
I may be slow to respond. Slack/text if urgent.

Block or report some-natalie

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
some-natalie/README.md

Hi there 👋🏻

I'm Natalie, a DevSecOps engineer and consultant experienced in developer experience and consolidation within a wide array of security-focused environments. I work at the intersection of technology, people, and highly-regulated industries as a Principal Solutions Engineer for Public Sector at Chainguard!

📝 I write about tech, what I'm working on, and what I'm playing with on my blog. Here's what I've been up to lately:

  1. Three years of writing on the internet: Lessons learned about habit after three whole years of writing blog posts!
  2. Container host shenanigans: Let's pull apart the key security risks at each layer of the container ecosystem ... starting at the bottom, risks to our container's host.
  3. Container Escapes 101 - In the wild: So far, we've been SSH'd directly into our host node. This isn't how we normally have access to escape so ... how does these tactics still work? We're going to use the same storage-based escapes as before, but through a web UI and talk through some common difficulties defensive countermeasures.

💼 Day to day, I work with

You can find me in our work Slack sharing all sorts of neat things you can do with all that fun stuff and probably find out how I've broken and maybe fixed something too. 😀

👾 I play with

  • All sorts of handy Raspberry Pi projects, including
  • I'm getting into the Flipper Zero lately - it's so handy and mischievous! (some fun uses)
  • Video games in a Windows VM on my Fedora desktop with libvirt, KVM, and a custom Linux kernel to pass hardware to it. It's got about 5% or so performance drop (just looking at frame rates) over a native install. You should check it out - code and write-up on how it works.

I have an awesome life outside of tech, so while I have a few projects that I enjoy, nothing above is close to where I spend most of my time / energy. If you need anything of mine above fixed, please feel free to fork it and send me a pull request! ❤️

🌸 Heads up!

  • 🌱 I’m currently studying to sit for my OSCP certification and learning the ropes at a container security startup.
  • 🎤 Public speaking is fun! Check out what I've been up to here.
  • 😄 Pronouns: she/her
  • ❓ Looking for my résumé? It's here, but you can also find some of what I've been up to in my profile. If you want to know about where else I've worked and went to school, you should go to LinkedIn.
  • 💬 Want to chat? I'm on Mastodon.

Pinned Loading

  1. kubernoodles kubernoodles Public

    k8s runners for GitHub Actions in the enterprise, made for humans

    Dockerfile 86 19

  2. fedora-acs-override fedora-acs-override Public

    Using the ACS override patch for Fedora to split identical hardware in the kernel

    Shell 54 18

  3. gitlog-to-csv gitlog-to-csv Public

    Creates a CSV file of `git log` data, useful for audit reports and other "chain of custody" type reports

    Shell 7

  4. advanced-security/ghas-to-csv advanced-security/ghas-to-csv Public

    Play with GHAS API to provide posture data over time

    Python 39 16

  5. jekyll-in-a-can jekyll-in-a-can Public

    🧪🥫 - it's Jekyll in a container

    Dockerfile 5 1

  6. advanced-security/enterprise-security-team advanced-security/enterprise-security-team Public

    Manage a uniform team of security managers for every organization in your enterprise

    Python 25 5

点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载