NoLimitSecu #526 - OSAKA

NoLimitSecu #526 - OSAKA

🎙 NoLimitSecu 👥 2K 📅 January 12, 2026 ⏱ 27 min 👁 253 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

KubernetesOSAKAattack pathssecurity auditANSSI

Summary

In this episode of NoLimitSecu, Warren Postdam from ANSSI presents OSAKA, an open-source tool designed to identify attack paths in Kubernetes clusters. The discussion covers common misconfigurations such as privileged containers and excessive capabilities, the challenges of Kubernetes complexity, and the tool’s architecture, which operates offline by analyzing exported cluster configurations. OSAKA uses Neo4j to map attack paths, similar to BloodHound for Active Directory. The tool is used in ANSSI audits and is available on GitHub. The conversation also touches on Kubernetes security features like Pod Security Admission, the limitations of the tool (e.g., no support for third-party products or microVMs), and the potential for community contributions. The episode provides practical insights for security professionals auditing Kubernetes environments.

118 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into Kubernetes security from an expert perspective. The discussion is grounded in practical experience, with concrete examples of misconfigurations and attack paths. The argumentation is solid, as the tool’s design choices are explained logically, such as the offline analysis approach to avoid impacting the cluster. The value is enhanced by the presentation of real-world use cases and the tool’s integration into ANSSI audits. However, the argumentation is primarily anecdotal, relying on the speaker’s authority rather than empirical data or comparative analysis.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the content is based on expert opinion and practical experience rather than formal research. The sources cited are the ANSSI website and the GitHub repository for OSAKA, which are appropriate and verifiable. The title accurately reflects the content, as the episode focuses on the OSAKA tool. The discussion is technically accurate, but it lacks citations to academic literature or external studies. The speaker acknowledges limitations and areas for improvement, which adds to the credibility.

180 words

Title / Content Match

The title accurately reflects the content, which is a detailed discussion of the OSAKA tool for Kubernetes security.

Quality & Reliability

8/10

The video features an expert from ANSSI discussing a tool developed by the agency. The information is technical and based on practical experience, but it is primarily an interview and presentation, not a peer-reviewed study. The tool is open-source and available on GitHub, which adds credibility.

Key Moments

Cited Sources

Concurring Sources

Contribution & Novelties

The video presents OSAKA, an open-source tool from ANSSI that addresses a gap in Kubernetes security auditing by automating the discovery of attack paths. It offers a practical approach for auditors and security teams to assess cluster configurations without direct interaction, reducing risk and overhead. The tool’s integration with Neo4j provides a visual representation of attack paths, facilitating remediation.

Pour aller plus loin :

109 words

Radar Profile

The radar profile shows high scores in quantity and quality of information, with a moderate technical level. The tool's practical focus and expert presentation contribute to high reliability. The overall balance indicates a valuable resource for security professionals.

Reliability 8/10