GitLab / Threat Management Department

Add meeting Rate page Subscribe

GitLab / Threat Management Department

These are all the meetings we have in "Threat Management De…" (part of the organization "GitLab"). Click into individual meeting pages to watch the recording and search or read the transcript.

24 Mar 2021

  • 3 participants
  • 26 minutes
updates
refactor
interim
rethink
capabilities
filtering
issue
process
tuning
sensible
youtube image

23 Mar 2021

No description provided.
  • 2 participants
  • 9 minutes
policies
scan
profile
message
deleted
ui
security
dashboard
discussion
ongoing
youtube image

16 Mar 2021

  • 5 participants
  • 16 minutes
commenting
comments
discussion
flagging
statuses
verbalize
issue
proposed
recorded
notable
youtube image

9 Mar 2021

No description provided.
  • 3 participants
  • 22 minutes
scanning
capabilities
registry
vulnerabilities
refinement
containers
matching
feature
issue
security
youtube image

9 Mar 2021

Topics discussed included community contributions, promotion, hiring, referrals, team building, and a recent outage
  • 5 participants
  • 18 minutes
alert
congratulations
boss
promoted
initiative
added
contributor
recently
overall
git
youtube image

4 Mar 2021

No description provided.
  • 5 participants
  • 52 minutes
vulnerability
vulnerable
vulnerabilities
remediations
security
concern
ensuring
hack
access
undismissed
youtube image

2 Mar 2021

No description provided.
  • 1 participant
  • 2 minutes
policy
editing
yaml
input
complicating
notice
updates
users
binding
handle
youtube image

2 Mar 2021

No description provided.
  • 5 participants
  • 25 minutes
issue
tweaks
monitoring
hubble
security
planning
review
worrying
maintainers
validation
youtube image

2 Mar 2021

  • 12 participants
  • 31 minutes
discussion
haircut
upvoting
posts
commenting
planning
having
questioned
head
debate
youtube image

24 Feb 2021

No description provided.
  • 3 participants
  • 5 minutes
approvals
merge
license
dependencies
software
approvers
approved
project
approval
licensed
youtube image

23 Feb 2021

No description provided.
  • 5 participants
  • 30 minutes
dashboard
concerns
maintainers
updates
monitoring
kubernetes
finally
capabilities
alert
disclaimer
youtube image

23 Feb 2021

Weekly meeting for the Secure:Threat Insights group
  • 6 participants
  • 17 minutes
concerns
dashboards
vulnerabilities
planning
security
insights
threat
vulnerability
discussion
ready
youtube image

16 Feb 2021

No description provided.
  • 6 participants
  • 47 minutes
alert
security
alerts
backend
milestones
automation
approvals
alerted
important
dashboard
youtube image

9 Feb 2021

No description provided.
  • 5 participants
  • 29 minutes
staging
testing
milestones
containers
dashboard
alert
deployment
planning
finalized
capabilities
youtube image

9 Feb 2021

Accomplishments, pairing, OKRs, team day, etc
  • 7 participants
  • 22 minutes
discussion
finished
session
stuff
participants
security
shared
staging
chats
fair
youtube image

2 Feb 2021

No description provided.
  • 6 participants
  • 29 minutes
permissions
policies
approver
gitlab
security
maintainers
das
scan
permission
repository
youtube image

2 Feb 2021

No description provided.
  • 4 participants
  • 10 minutes
discussion
alert
kubernetes
das
demo
security
agent
provides
interface
container
youtube image

27 Jan 2021

In this video we are explaining the idea of having Security Orchestration Policies as Repository with YAML files instead of other idea to store them in database.

You can read more about that idea here: https://gitlab.com/groups/gitlab-org/-/epics/4598 and the code that was presented during this video is available here: https://gitlab.com/gitlab-org/gitlab/-/merge_requests/52661
  • 1 participant
  • 13 minutes
repository
policies
implementation
git
plan
backend
yaml
process
kubernetes
configure
youtube image

26 Jan 2021

No description provided.
  • 4 participants
  • 22 minutes
policies
repository
reviewing
dast
workflow
concerns
security
configuration
auditing
monitoring
youtube image

19 Jan 2021

No description provided.
  • 2 participants
  • 16 minutes
policies
safeguard
discussion
configuration
welcoming
notice
security
approval
monitoring
users
youtube image

12 Jan 2021

DAST Project-level Scan Execution Policies (https://gitlab.com/groups/gitlab-org/-/epics/4598)

Spike: How to add a job that doesn't exist in .gitlab-ci.yml to a pipeline (https://gitlab.com/gitlab-org/gitlab/-/issues/280315)
Spike: How to run a scheduled pipeline with one security job (https://gitlab.com/gitlab-org/gitlab/-/issues/280314)
Spike: How can we fail a pipeline depending on conditions set in Scan Result Policy (https://gitlab.com/gitlab-org/gitlab/-/issues/280313)
Spike: How Gitlab configuration inheritance works (https://gitlab.com/gitlab-org/gitlab/-/issues/282420)
  • 2 participants
  • 25 minutes
scan
scanned
overview
configuration
policies
tweaking
monitoring
execution
concern
dust
youtube image

12 Jan 2021

No description provided.
  • 4 participants
  • 30 minutes
gitlab
container
installed
alert
cads
policies
concerning
v2
app
repository
youtube image

12 Jan 2021

Weekly meeting for the Secure:Threat Insights group
  • 5 participants
  • 12 minutes
discussion
subashi
concerns
feature
savash
issue
noticed
documentation
asking
felipe
youtube image

12 Jan 2021

No description provided.
  • 8 participants
  • 15 minutes
security
threat
reports
listen
having
2021
come
improvements
comment
streaming
youtube image

12 Jan 2021

Open office hours for topics related to Threat Management groups - Secure:Threat Insights & Protect:Container Security
  • 7 participants
  • 50 minutes
threat
concern
discussion
dashboards
realizing
updated
reevaluate
planning
expecting
exploits
youtube image

22 Dec 2020

No description provided.
  • 3 participants
  • 29 minutes
staging
alert
securing
container
discussed
precautions
updates
deployed
dismiss
dashboard
youtube image

17 Dec 2020

Open office hours for topics related to Threat Management groups - Secure:Threat Insights & Protect:Container Security
  • 6 participants
  • 51 minutes
security
threat
alerting
concern
comments
editing
updated
watching
functionality
proceeding
youtube image

15 Dec 2020

No description provided.
  • 5 participants
  • 14 minutes
alert
policies
updates
discussion
security
capabilities
monitoring
notice
panel
configuration
youtube image

15 Dec 2020

Open office hours for topics related to Threat Management groups - Secure:Threat Insights & Protect:Container Security
  • 5 participants
  • 14 minutes
security
alerts
vulnerability
policies
criticals
automatically
threat
patch
concerns
prevent
youtube image

15 Dec 2020

No description provided.
  • 7 participants
  • 15 minutes
security
vulnerability
maturity
threat
improvements
git
viable
finally
note
manage
youtube image

8 Dec 2020

No description provided.
  • 6 participants
  • 29 minutes
milestones
updates
concerns
merged
dashboard
review
milestone
alert
status
early
youtube image

2 Dec 2020

No description provided.
  • 4 participants
  • 18 minutes
overseeing
concern
threat
having
overall
trends
onboarding
updates
staff
okrs
youtube image

1 Dec 2020

No description provided.
  • 6 participants
  • 26 minutes
bot
ops
discussion
feature
frontend
demo
alert
rollout
flag
chat
youtube image

19 Nov 2020

Synchronous discussion to breakdown the work required to implement Generic Security Report Schemas per design issue https://gitlab.com/gitlab-org/gitlab/-/issues/267193
  • 5 participants
  • 49 minutes
discussion
plan
report
refinements
summarize
initiatives
taking
structure
reviewing
frontend
youtube image

17 Nov 2020

No description provided.
  • 7 participants
  • 24 minutes
threats
security
concerned
2021
important
management
tasks
onboarding
weekly
finalize
youtube image

17 Nov 2020

Open office hours for topics related to Threat Management groups - Secure:Threat Insights & Protect:Container Security
  • 5 participants
  • 25 minutes
security
threat
oversight
monitoring
policies
process
approvals
configured
workflows
gitlab
youtube image

10 Nov 2020

No description provided.
  • 5 participants
  • 12 minutes
discussion
backend
finalized
documentation
proposal
issue
navigation
progressing
planning
nick
youtube image

10 Nov 2020

Weekly meeting for the Secure:Threat Insights group
  • 6 participants
  • 26 minutes
initiatives
threat
troubleshooting
insights
updates
concern
vulnerability
edge
advance
manage
youtube image

8 Nov 2020

This is the first and initial idea to start creating issues in Jira for Vulnerabilities. This is the demo of the functionality currently available only in the code in MR: https://gitlab.com/gitlab-org/gitlab/-/merge_requests/46771
  • 1 participant
  • 2 minutes
vulnerabilities
jira
issue
gitlab
error
bug
configured
creating
refresh
juror
youtube image

7 Nov 2020

Open office hours for topics related to Threat Management groups - Secure:Threat Insights & Protect:Container Security
  • 5 participants
  • 55 minutes
vulnerability
vulnerabilities
security
threat
worry
dashboard
warning
managed
spearheading
analyzers
youtube image

4 Nov 2020

Weekly meeting for the Secure:Threat Insights group
  • 4 participants
  • 26 minutes
security
gitlab
vulnerability
discussion
insights
crowdsource
updates
threat
gotcha
management
youtube image

4 Nov 2020

No description provided.
  • 5 participants
  • 14 minutes
lately
having
viewers
ultimately
team
discussion
wayne
anticipate
overachieved
managers
youtube image

27 Oct 2020

No description provided.
  • 6 participants
  • 29 minutes
concerns
fip
security
monitoring
packages
supposed
discussed
centos
threat
policies
youtube image

20 Oct 2020

Weekly meeting for the Secure:Threat Insights group
  • 7 participants
  • 31 minutes
gitlab
issue
monitoring
discussion
threat
thiago
prioritization
pushback
insights
helpers
youtube image

20 Oct 2020

No description provided.
  • 9 participants
  • 26 minutes
performance
assessments
threat
staff
managers
milestones
discussions
expecting
announcements
development
youtube image

13 Oct 2020

No description provided.
  • 7 participants
  • 25 minutes
announced
gitlab
security
discussions
ics
container
important
confidential
patching
ready
youtube image

13 Oct 2020

Last few minutes of discussion was removed since we discussed orange matters (https://about.gitlab.com/handbook/engineering/security/data-classification-standard.html#orange)
  • 5 participants
  • 25 minutes
consider
concerned
improving
planning
existing
challenges
users
security
process
mre
youtube image

29 Sep 2020

No description provided.
  • 6 participants
  • 26 minutes
discussion
concerns
policies
okay
clarifying
important
ahead
approval
arthur
expecting
youtube image

24 Sep 2020

Demo prepared as a part of the proposed solution for https://gitlab.com/gitlab-org/gitlab/-/issues/216983.

In this video we are presenting how to achieve Active Response engine with simple Go application and Falco, that can run scripts that are using ie. kubectl, curl, or any other bash commands.
  • 1 participant
  • 6 minutes
falco
server
terminal
host
execute
alerts
application
configured
console
access
youtube image

22 Sep 2020

No description provided.
  • 5 participants
  • 30 minutes
deployments
gma
v1
decisions
configure
container
dashboard
packages
managed
security
youtube image

15 Sep 2020

No description provided.
  • 4 participants
  • 15 minutes
finalize
github
issue
going
eventually
policies
release
finishing
ready
status
youtube image

15 Sep 2020

Thank you for watching this preview of the upcoming Secure & Defend Section Public Livestream on 2020-09-17!
  • 3 participants
  • 14 minutes
security
fuzzing
alerts
processing
buzzing
vulnerability
updates
happening
safeguards
deployment
youtube image

15 Sep 2020

No description provided.
  • 7 participants
  • 25 minutes
contributions
dashboard
discussion
great
functionality
updates
hassle
insights
vetting
hackathon
youtube image

1 Sep 2020

No description provided.
  • 5 participants
  • 29 minutes
usability
defend
policies
features
deployment
concern
discussion
security
prioritization
restructure
youtube image

28 Aug 2020

2020-08-28 https://gitlab.com/gitlab-org/threat-management/general/-/issues/734


Topics:
1. How to find threat insights and container security issues to work on.
2. What do the Category labels mean.
3. Getting started with Category:Vulnerability Management
  • 5 participants
  • 32 minutes
threat
machia
workflow
ray
community
manager
hackathons
entry
faq
users
youtube image

25 Aug 2020

No description provided.
  • 9 participants
  • 11 minutes
contributors
announcement
nominations
bonus
discussion
note
collaboration
discretionary
volunteer
thanks
youtube image

18 Aug 2020

No description provided.
  • 5 participants
  • 24 minutes
pings
threat
updates
performance
session
management
message
monthly
insights
triage
youtube image

12 Aug 2020

No description provided.
  • 3 participants
  • 16 minutes
zendesk
retrospectives
contributors
concerns
community
accountability
aware
approvals
maintainer
attending
youtube image

4 Aug 2020

No description provided.
  • 4 participants
  • 26 minutes
discussion
bots
validations
feature
concern
policy
message
small
editing
reviews
youtube image

28 Jul 2020

No description provided.
  • 6 participants
  • 19 minutes
vulnerability
scanning
updates
secure
priority
cognizant
alert
package
importantly
automated
youtube image

21 Jul 2020

No description provided.
  • 6 participants
  • 32 minutes
managed
concern
approvals
gcp
anticipate
host
admins
ultimately
aws
significant
youtube image

17 Jul 2020

No description provided.
  • 1 participant
  • 11 minutes
security
vulnerability
tweak
insights
triage
enhancement
scanners
secure
strategy
noticed
youtube image

16 Jul 2020

GitLab provides Cilium as a managed application enabling you to work with Network Policies. Network policies in Kubernetes, detect and block unauthorized network traffic between pods and to/from the Internet.

This video shows Network Policies in action and how you can install Cilium as a GitLab managed application.

Follow @awkwardferny and @gitlab on twitter. 🐦
Installing Cilium as a Gitlab managed application: https://docs.gitlab.com/ee/user/clusters/applications.html#install-cilium-using-gitlab-cicd
RoadMap for Container Network Security: https://about.gitlab.com/direction/defend/container_network_security/
Network Policy Rules: https://kubernetes.io/docs/concepts/services-networking/network-policies/
Get in touch with Sales: http://bit.ly/2IygR7z
  • 1 participant
  • 4 minutes
kubernetes
configure
gitlab
policies
pods
monitoring
network
security
manages
packets
youtube image

14 Jul 2020

No description provided.
  • 8 participants
  • 23 minutes
ahead
security
transition
monitoring
planning
concerns
finally
backlog
managed
triage
youtube image

8 Jul 2020

design review for alerts MVC (threats monitoring): https://gitlab.com/groups/gitlab-org/-/epics/3438
  • 1 participant
  • 6 minutes
filter
alerts
nbc
overview
cluster
dashboard
policy
order
statuses
filtering
youtube image

7 Jul 2020

No description provided.
  • 4 participants
  • 29 minutes
monitored
security
inspecting
worrying
policies
careful
container
tweaking
threat
discussed
youtube image

2 Jul 2020

Engineers from the Threat Insights group ask Secure engineers about Vulnerability Management related questions.
  • 8 participants
  • 48 minutes
vulnerability
discussion
insights
concern
issuing
happening
threat
informed
assumption
risk
youtube image

1 Jul 2020

No description provided.
  • 1 participant
  • 4 minutes
dashboard
vulnerabilities
filtering
security
message
configured
dashboards
vulnerability
error
improve
youtube image

30 Jun 2020

No description provided.
  • 5 participants
  • 20 minutes
discussion
ism
sam
planing
resolved
kubernetes
security
maintenance
advance
okay
youtube image

30 Jun 2020

Weekly meeting for the Secure:Threat Insights group
  • 8 participants
  • 21 minutes
forewarning
discussions
tomorrow
having
security
ready
updated
progressing
approval
bringing
youtube image

30 Jun 2020

No description provided.
  • 1 participant
  • 4 minutes
dashboard
vulnerabilities
inject
message
filtering
security
vulnerable
presentational
dashboards
injections
youtube image

29 Jun 2020

What is the GitLab CEO shadow program? Why should you apply to participate? How did I see the GitLab values in action?
https://about.gitlab.com/blog/2020/07/08/ceo-shadow-impressions-takeaways/
  • 1 participant
  • 7 minutes
ceo
shadowing
strategy
important
experiences
investors
overall
security
presentations
sid
youtube image

25 Jun 2020

How to associate a management project with your K8S cluster


Documentation: https://docs.gitlab.com/ee/user/clusters/management_project.html
  • 1 participant
  • 2 minutes
project
cluster
configuration
repository
cuban
customize
managed
container
llamo
pipeline
youtube image

24 Jun 2020

  • 1 participant
  • 5 minutes
deployments
armor
profiles
advanced
demo
deploy
configure
deployment
script
prerequisite
youtube image

24 Jun 2020

Documentation: https://docs.gitlab.com/ee/topics/web_application_firewall/



This video demonstrates how to install the Web Application Firewall in logging and blocking modes.


Previous video in the series: https://youtu.be/IN-XGE1X8Mo


OWASP Core Rule Set:

- https://coreruleset.org/

- https://github.com/coreruleset/coreruleset/
  • 1 participant
  • 2 minutes
blocked
kubernetes
helm
server
enable
firewall
owasp
logging
piping
wife
youtube image

23 Jun 2020

Weekly meeting for the Defend:Container Security group
  • 4 participants
  • 19 minutes
planning
discussion
policy
decisions
proposal
future
security
thinking
configuration
plans
youtube image

23 Jun 2020

Weekly meeting for the Secure:Threat Insights (previously Defend:Threat Insights) group
  • 5 participants
  • 28 minutes
endpoints
concerns
backend
supporting
rest
comments
triage
improvements
launched
ahead
youtube image

18 Jun 2020

Documentation: https://docs.gitlab.com/ee/topics/web_application_firewall/quick_start_guide.html

All container security features in GitLab require Kubernetes. This video shows how to quickly create a Kubernetes cluster using the WAF Quickstart guide.
  • 1 participant
  • 2 minutes
kubernetes
labs
quickstart
cluster
firewall
demo
gate
container
security
project
youtube image

17 Jun 2020

No description provided.
  • 11 participants
  • 27 minutes
security
department
defender
revisit
bringing
manager
staff
announce
participating
planning
youtube image

16 Jun 2020

This is a demo of the new Container Host Security feature available in GitLab 13.2. The feature embeds Falco to allow security analysts to monitor containers for potentially anomalous behavior and be confident that they were not compromised by a malicious actor.

https://gitlab.com/gitlab-org/gitlab/-/issues/218026
  • 1 participant
  • 11 minutes
falco
application
security
monitoring
container
configured
kubernetes
advanced
manage
demo
youtube image

16 Jun 2020

No description provided.
  • 6 participants
  • 21 minutes
guidelines
gitlab
security
cluster
policies
monitoring
discussions
managed
issue
tentatively
youtube image

16 Jun 2020

Weekly meeting for the Defend:Threat Insights group
  • 8 participants
  • 30 minutes
dashboards
issue
patch
insights
updated
vulnerabilities
reactions
threat
discussion
push
youtube image

15 Jun 2020

This video demos the vulnerabilities over time chart which is going to be re-added in 13.1.
  • 1 participant
  • 2 minutes
vulnerabilities
vulnerable
security
dashboard
watching
users
severity
milestones
critical
currently
youtube image

11 Jun 2020

Preview session for the upcoming Secure & Defend Section Group Conversation livestream scheduled for 2020-06-15. Hear updates related to the Secure & Defend stages from David DeSanto, Todd Stadelhofer, and Wayne Haber.
  • 3 participants
  • 9 minutes
security
fuzzer
alerts
priority
buzz
secure
stuff
service
management
peach
youtube image

11 Jun 2020

No description provided.
  • 3 participants
  • 43 minutes
security
dashboards
router
previous
planning
monitoring
browser
advanced
concerns
delegated
youtube image

10 Jun 2020

No description provided.
  • 5 participants
  • 28 minutes
webhooks
message
configuring
workflow
interface
editing
slack
fter
users
telepsychic
youtube image

2 Jun 2020

No description provided.
  • 7 participants
  • 26 minutes
policies
deployments
configure
planning
discussion
policy
default
manage
orchestrationgroup
container
youtube image

2 Jun 2020

Weekly meeting for the Defend:Threat Insights group
  • 7 participants
  • 31 minutes
concerns
advance
discussion
security
investigation
pagination
insights
updated
resolution
dashboards
youtube image

2 Jun 2020

No description provided.
  • 1 participant
  • 3 minutes
vulnerabilities
dashboard
overflow
edit
bug
long
text
fix
size
ellipsis
youtube image

2 Jun 2020

  • 1 participant
  • 1 minute
vulnerability
updates
issue
polling
emerge
kerensky
status
gate
confirmed
news
youtube image

2 Jun 2020

  • 1 participant
  • 3 minutes
sticky
dashboards
filter
scrolling
header
security
dashboard
inspect
filters
gitlab
youtube image

28 May 2020

No description provided.
  • 1 participant
  • 3 minutes
persisting
filter
reintroduced
dashboards
refresh
functionality
security
scanning
settings
navigate
youtube image

27 May 2020

Weekly meeting for the Defend:Container Security group
  • 6 participants
  • 24 minutes
security
planning
host
discussion
monitoring
container
configure
future
ready
devops
youtube image

26 May 2020

Issues:
- Create Merge Request from Vulnerability - https://gitlab.com/gitlab-org/gitlab/-/issues/216300
- Download Patch from Vulnerability - https://gitlab.com/gitlab-org/gitlab/-/issues/216300
  • 1 participant
  • 3 minutes
patched
gitlab
button
downloads
vulnerability
resolve
newer
patch
fix
functionality
youtube image

26 May 2020

2020-05-26
  • 5 participants
  • 26 minutes
discussions
workflow
demos
ready
planning
breakdown
taking
assess
ahead
refinement
youtube image

26 May 2020

  • 1 participant
  • 11 minutes
security
dashboard
demo
vulnerabilities
watcher
processing
configured
methods
view
vulnerability
youtube image

21 May 2020

No description provided.
  • 9 participants
  • 49 minutes
policies
discussion
proposal
policy
manage
having
planning
decisions
sam
state
youtube image

20 May 2020

No description provided.
  • 6 participants
  • 7 minutes
attending
dan
thanks
apparently
defending
comments
shirt
english
countries
day
youtube image

20 May 2020

Weekly meeting for the Defend:Container Security group
  • 6 participants
  • 28 minutes
security
deployed
falco
modsecurity
concerns
facilitate
cluster
pod
protection
proxy
youtube image

19 May 2020

Weekly meeting for the Defend:Threat Insights group
  • 7 participants
  • 30 minutes
concerns
pagination
summarizing
discussion
security
dashboards
prioritize
preview
maintain
gitlab
youtube image

18 May 2020

  • 1 participant
  • 4 minutes
dashboards
security
timeouts
vulnerabilities
demo
backend
lately
dashboard
migrated
overtime
youtube image

15 May 2020

No description provided.
  • 5 participants
  • 1:12 hours
discussion
policies
proposal
concerns
reconsidering
brainstorming
users
manage
centralized
decisions
youtube image

15 May 2020

Defend:Threat Insights will look to deliver Exportable Group Security reports along with UX enhancements for 13.1.

https://about.gitlab.com/direction/defend/vulnerability_management/
  • 1 participant
  • 7 minutes
vulnerability
standalone
security
enhancement
dashboards
noticed
vulnerabilities
threat
13
targeting
youtube image

13 May 2020

No description provided.
  • 5 participants
  • 25 minutes
security
plan
staffing
defend
deploying
threaten
manages
assisting
discussion
protecting
youtube image

12 May 2020

Weekly meeting for the Defend:Threat Insights group
  • 8 participants
  • 28 minutes
concerns
caching
backlog
security
updated
vulnerability
query
threat
alert
revisit
youtube image

12 May 2020

  • 1 participant
  • 3 minutes
persisting
cookies
dismiss
alert
storage
resolution
refresh
expire
persistence
merge
youtube image

12 May 2020

No description provided.
  • 1 participant
  • 1 minute
vulnerabilities
demo
vulnerability
security
detected
announce
fix
dismiss
status
severity
youtube image

7 May 2020

No description provided.
  • 7 participants
  • 1:09 hours
monitoring
approved
integrity
deploying
maintainable
process
pod
concern
requiring
fie
youtube image

7 May 2020

No description provided.
  • 1 participant
  • 4 minutes
dashboards
security
project
vulnerabilities
filter
configured
message
dashboard
watching
changes
youtube image

5 May 2020

No description provided.
  • 3 participants
  • 14 minutes
secure
security
protect
securing
proactive
defend
vulnerability
protecting
threat
demoed
youtube image

5 May 2020

No description provided.
  • 6 participants
  • 27 minutes
vulnerability
realizations
remediation
expected
backend
secure
testing
addressed
confirmation
functionality
youtube image

29 Apr 2020

No description provided.
  • 7 participants
  • 26 minutes
policies
modsecurity
minimal
deployment
ui
functionality
policy
configuring
security
cmo
youtube image

29 Apr 2020

Weekly meeting for the Defend:Threat Insights group
  • 5 participants
  • 8 minutes
reporting
defense
issue
insights
id
common
threat
contribute
secure
aware
youtube image

21 Apr 2020

No description provided.
  • 6 participants
  • 24 minutes
ui
discussed
modsecurity
finalized
iam
cilium
configuration
minimal
backend
concerns
youtube image

21 Apr 2020

No description provided.
  • 9 participants
  • 21 minutes
vulnerability
gitlab
maintainer
13o
gone
important
locally
rico
status
issue
youtube image

20 Apr 2020

  • 1 participant
  • 7 minutes
vulnerabilities
standalone
demoing
detected
dismiss
statuses
vulnerability
incidents
notice
critical
youtube image

16 Apr 2020

The Defend:Threat Insights Group is working on Instance-level exportable security reports for 13.0:
https://gitlab.com/groups/gitlab-org/-/boards/1241267?scope=all&utf8=%E2%9C%93&state=opened&label_name[]=devops%3A%3Adefend&label_name[]=direction&label_name[]=group%3A%3Athreat%20insights
  • 1 participant
  • 5 minutes
security
insights
vulnerability
threat
planning
dashboard
disclosure
eventually
management
edit
youtube image

15 Apr 2020

Weekly meeting for the Defend:Container Security group
  • 4 participants
  • 6 minutes
deliverable
stages
reasonably
planning
today
expecting
sam
pass
message
ready
youtube image

15 Apr 2020

  • 3 participants
  • 3 minutes
vulnerabilities
export
backend
csv
button
vulnerability
overviews
cve
loading
dashboards
youtube image

15 Apr 2020

Simple demo to configure the instance level dashboard
  • 1 participant
  • 2 minutes
vulnerabilities
dashboard
demo
security
loading
edit
project
manage
vulnerability
latest
youtube image

9 Apr 2020

Added the multi-dismiss vulnerabilities feature on the the project security dashboard and vulnerability list.
  • 1 participant
  • 3 minutes
dismiss
vulnerabilities
bot
demoing
updates
dashboard
gitlab
checks
functionality
disabled
youtube image

8 Apr 2020

  • 3 participants
  • 29 minutes
dismissing
vulnerability
migrations
concern
batches
bitmerge
significantly
managed
rollback
project
youtube image

8 Apr 2020

Demos of one of the features prepared for https://gitlab.com/gitlab-org/gitlab/-/issues/213598

MR: https://gitlab.com/gitlab-org/gitlab/-/merge_requests/29140

In this demo we are presenting new fields added to GraphQL API: findings (id, projectFingerprint), createVulnerabilityFeedbackDismissalPath and userPermissions.

MR: https://gitlab.com/gitlab-org/gitlab/-/merge_requests/29150

In this demo we are presenting new mutation added to GraphQL API to Dismiss Vulnerabilities.
  • 1 participant
  • 5 minutes
dismiss
vulnerabilities
query
project
vern
ready
user
detected
message
features
youtube image

7 Apr 2020

Weekly meeting for the Defend:Container Security group
  • 9 participants
  • 29 minutes
cilium
managed
kubernetes
configurability
proposed
concerns
process
planning
interface
functioning
youtube image

7 Apr 2020

Weekly meeting for the Defend:Threat Insights group
  • 9 participants
  • 32 minutes
breaking
concerns
swashes
milestones
changes
insights
revisit
targeting
patch
soon
youtube image

7 Apr 2020

The user should only be able to create one issue per vulnerability
  • 1 participant
  • 2 minutes
vulnerability
issue
button
demoing
create
standalone
kalay
status
appear
new
youtube image

3 Apr 2020

# FCV dashboards
## Project security dashboard
This is the most complete dashboard and a lot of what we built here can be re-used on the others.

### Already have
- List
- Filters
- Counts
- Unconfigured state

### Might have
- File path on the vulnerability list
- Filtering for the counts (there’s no backend for this yet)
---
## Group Security Dashboard
This one isn’t too far behind the project dashboard, but does have a few missing features that exist on the current group security dashboard. Most of these are known and were never planned to be part of the MVC

### Already have
- List

### Will have
- Filters
- Unconfigured State

### Might have
- A project filter
- Project path on the vulnerability list

### Won’t have
- Vulnerabilities over time
- Project security status
---
## Instance security dashboard
This is the furthest behind. We don’t currently have all the GraphQL endpoints we need for this, but can still develop the frontend in parallel so we’re ready for them when they do ship.

### Already have

### Will have
- List
- Filters (excluding the project filter)
- Unconfigured state

### Might have
- A project filter
- Project path on the vulnerability list

### Won’t have
- Vulnerabilities over time
- Project security status
---
## General / Vulnerability list
Just a few things that pertain to all the dashboards as they’re features on the vulnerability list.

### Don’t need?
- Pipeline status on the project dashboard

### Won’t have
- Inline linked issues on the vulnerability list (we ran out of time)
- Inline Dismissal comments on the vulnerability list

### Can’t have
- Multiple select dismissals (because we can’t dismiss from the lists any more)
  • 1 participant
  • 20 minutes
filter
vulnerabilities
dismiss
pass
dashboard
status
secure
fetch
scratch
checkbox
youtube image

3 Apr 2020

This is a demo of GitLab's Kubernetes deployment options as well as a discussion of the implications for the Defend roadmap.

Notes: https://docs.google.com/document/d/1OTzDtRV1EOesU_dyrNAUpjibyk0gKUWP5bVrTzTmTw8/edit?usp=sharing
  • 3 participants
  • 50 minutes
installed
git
apps
process
configures
kubernetes
versions
screen
devops
upgrade
youtube image

2 Apr 2020

  • 1 participant
  • 3 minutes
dashboard
vulnerabilities
demo
version
view
security
vulnerability
crash
component
county
youtube image

1 Apr 2020

A demo of the graphQL based filtering on the project security dashboard
  • 1 participant
  • 3 minutes
filter
query
graphical
vulnerabilities
severity
pass
dashboards
filtering
hooks
detected
youtube image

1 Apr 2020

https://about.gitlab.com/blog/2020/04/02/security-trends-in-gitlab-hosted-projects/

Top security risks include using components with known vulnerabilities, XSS, lack of secret management, lack of CSP, CSRF, and SQLi
  • 1 participant
  • 5 minutes
vulnerabilities
security
vulnerability
risks
vulnerable
scanned
site
protection
scripting
concern
youtube image

31 Mar 2020

Weekly meeting for the Defend:Container Security group
  • 7 participants
  • 1:02 hours
monitoring
discussions
users
modsecurity
concerning
intrusion
functioning
deployment
policies
meet
youtube image

31 Mar 2020

Weekly meeting for the Defend:Threat Insights group
  • 8 participants
  • 31 minutes
concerns
security
monitored
threat
insights
mitigated
discussion
policy
approach
notice
youtube image

31 Mar 2020

Frontend Engineer Sam Beckham recorded this demo of the integration of our new Standalone Vulnerabilities (AKA "first class vulnerabilities") into our existing Security Dashboards.
https://gitlab.com/gitlab-org/gitlab/-/merge_requests/27820
  • 1 participant
  • 3 minutes
scrolling
dashboard
feature
pagination
smr
network
fetches
scroll
nodes
vulnerabilities
youtube image

31 Mar 2020

Frontend Engineer Sam Beckham recorded this demo of the new resolution alert component created to notify a user when a vulnerability is resolved on new standalone vulnerability page
https://gitlab.com/gitlab-org/gitlab/-/merge_requests/27696
  • 1 participant
  • 2 minutes
resolved
branch
vulnerability
default
reloads
burner
resolve
functionality
messing
happens
youtube image

24 Mar 2020

No description provided.
  • 10 participants
  • 19 minutes
onboarding
hi
security
nick
iago
introduce
going
interview
maintainer
champaign
youtube image

24 Mar 2020

Weekly meeting for the Defend:Container Security group
  • 6 participants
  • 20 minutes
discussed
cilium
container
demos
functionality
worries
sam
takes
review
planning
youtube image

24 Mar 2020

No description provided.
  • 1 participant
  • 3 minutes
enabling
logging
nginx
blocking
enabled
ingress
waff
cluster
enable
settings
youtube image

23 Mar 2020

Sam has been working on the Security Dashboard Integration recently. As the task has shown to be bigger than expected, we had a talk/planning on how to divide it so that multiple people can work at the same time on different parts of it.

Here is the MR for the plan we decided to follow during this talk: https://gitlab.com/gitlab-org/gitlab/-/merge_requests/27674
  • 2 participants
  • 28 minutes
dashboards
vulnerabilities
security
fixing
backend
dashboard
access
endpoints
vulnerability
ready
youtube image

17 Mar 2020

  • 1 participant
  • 3 minutes
logs
security
gitlab
port
firewall
monitoring
configuration
1210
features
data
youtube image

16 Mar 2020

Vulnerability Management work continues on standalone vulnerability objects.

https://about.gitlab.com/direction/defend/vulnerability_management/
  • 1 participant
  • 5 minutes
security
updates
vulnerability
threat
insights
secure
aware
redoing
tweaked
dashboards
youtube image

10 Mar 2020

No description provided.
  • 10 participants
  • 24 minutes
introduce
cheers
welcoming
denver
alexander
visiting
joining
hi
enjoy
samus
youtube image

10 Mar 2020

Weekly meeting for the Defend:Threat Management group
  • 7 participants
  • 29 minutes
threat
insights
security
vulnerabilities
careful
vulnerability
advance
updated
dashboards
discussion
youtube image

10 Mar 2020

Weekly meeting for the Defend:Container Security group
  • 6 participants
  • 27 minutes
demos
discussions
recorded
workflow
scheduled
logging
security
demo
deploying
report
youtube image

10 Mar 2020

No description provided.
  • 1 participant
  • 5 minutes
abilities
vulnerabilities
fetched
graph
ql
cower
set
pass
query
method
youtube image

25 Feb 2020

Defend engineers working with PM to breakdown upcoming issues into components, clarify requirements, and identify work boundaries.
  • 6 participants
  • 30 minutes
finalizing
planning
prioritization
discussion
policies
proposal
sections
configuration
breakdown
centralized
youtube image

25 Feb 2020

Defend engineers working with PM to breakdown upcoming issues into components, clarify requirements, and identify work boundaries.
  • 7 participants
  • 18 minutes
planning
concern
breakdowns
discussion
workflow
dismiss
having
slack
threat
management
youtube image

24 Feb 2020

No description provided.
  • 10 participants
  • 20 minutes
security
manage
defend
monitoring
capabilities
compromised
protect
policies
intel
deploy
youtube image

18 Feb 2020

Defend engineers working with PM to breakdown upcoming issues into components, clarify requirements, and identify work boundaries.
  • 7 participants
  • 27 minutes
concerns
demoing
functionality
ensuring
planning
workflow
container
security
approval
notice
youtube image

17 Feb 2020

12.9 release kickoff for Threat Management covering the MVC for First Class Vulnerabilities and Exportable project-level Dashboard reports.
  • 1 participant
  • 8 minutes
vulnerability
security
mvc
capabilities
notice
vulnerabilities
redoing
thread
access
severity
youtube image

16 Feb 2020

Senior frontend engineer Daniel Tian shares a demo of the status header created for the new standalone vulnerability page being developed in the Defend Stage.
  • 1 participant
  • <1 minute
status
drop
button
updates
vulnerability
cancel
enabled
reset
daniel
selected
youtube image

12 Feb 2020

Defend engineers working with PM to breakdown upcoming issues into components, clarify requirements, and identify work boundaries.
  • 7 participants
  • 20 minutes
grooming
planning
discussed
preparation
grooms
having
groomed
concern
decision
consulting
youtube image

11 Feb 2020

No description provided.
  • 6 participants
  • 14 minutes
scheduled
discussions
alright
streaming
presidents
weekly
discretionary
planning
happening
important
youtube image

10 Feb 2020

Defend engineers working with PM to breakdown upcoming issues into components, clarify requirements, and identify work boundaries.
  • 9 participants
  • 32 minutes
enabled
reinstallation
discussion
nginx
security
users
updated
settings
interface
toggle
youtube image

5 Feb 2020

Defend engineers working with PM to breakdown upcoming issues into components, clarify requirements, and identify work boundaries.
  • 9 participants
  • 33 minutes
modsecurity
planning
cloud
discussions
deliverables
sync
threat
deployments
manage
centralizer
youtube image

5 Feb 2020

Defend engineers working with PM to breakdown upcoming issues into components, clarify requirements, and identify work boundaries.
  • 7 participants
  • 29 minutes
planning
concerns
reviewing
management
process
prioritize
decisions
discussion
milestones
behavior
youtube image

4 Feb 2020

This is a demo of the new Container Network Security feature available in GitLab 12.8. The feature embeds Cilium to allow users to write NetworkPolicy rules that can restrict traffic between Kubernetes pods in a GitLab managed deployment.
  • 2 participants
  • 8 minutes
deploying
managed
configuration
provider
policies
interface
process
network
support
application
youtube image

28 Jan 2020

No description provided.
  • 8 participants
  • 29 minutes
concern
planing
sharing
discussions
practices
workflow
interim
proposal
brainstorming
having
youtube image

28 Jan 2020

  • 5 participants
  • 21 minutes
deployments
ci
interface
managed
provider
configuration
network
policies
process
deploying
youtube image

27 Jan 2020

Includes a demo at the beginning of the current state of first-class vulnerabilities: https://gitlab.com/gitlab-org/gitlab/issues/13561
  • 6 participants
  • 31 minutes
vulnerabilities
demo
vulnerability
hacked
feature
security
concern
ready
access
detected
youtube image

21 Jan 2020

No description provided.
  • 9 participants
  • 37 minutes
sam
candidate
introduce
policies
volunteers
senator
like
interviewers
discussions
taking
youtube image

20 Jan 2020

We are hiring: https://about.gitlab.com/jobs/apply/


We defend our customers' applications and infrastructure from the ever-evolving exploitation techniques employed by those who wish to harm our customers.


Launch GitLab developed security technologies and integrate open-source projects to provide security controls for customers.

Employ security controls for our customers at the container, network, host, and application layers.

Provide features to allow customers to manage their security risks effectively and efficiently.



Defend team: https://about.gitlab.com/handbook/engineering/development/defend/
  • 4 participants
  • 5 minutes
security
gitlab
defense
devops
lab
deployments
manage
infrastructure
protect
software
youtube image

20 Jan 2020

Demo portion of the Defend team's weekly discussion and demo of the Standalone Vulnerability MVC progress (https://gitlab.com/gitlab-org/gitlab/issues/13561)
  • 7 participants
  • 16 minutes
vulnerability
demo
findings
v1
identifying
launch
introduced
vulnerabilities
showing
status
youtube image

20 Jan 2020

Defend team's weekly discussion and demo of the Standalone Vulnerability MVC progress (https://gitlab.com/gitlab-org/gitlab/issues/13561)
  • 7 participants
  • 23 minutes
prerequisite
contribution
lab
question
community
status
requesting
gitlab
project
issue
youtube image

16 Jan 2020

See the new audit (listen-only) mode we're introducing as a follow up to the new Container Network Security MVC released in 12.7. This will involve another upstream contribution to the Cilium project.
  • 1 participant
  • 3 minutes
security
deploying
minimal
policies
monitoring
network
mvc
plan
allowing
container
youtube image

16 Jan 2020

We're continuing work on the First Class Vulnerabilities MVC for 12.8.
  • 1 participant
  • 3 minutes
vulnerability
security
threat
capabilities
approach
thing
release
defend
incrementally
manager
youtube image

14 Jan 2020

No description provided.
  • 10 participants
  • 24 minutes
lab
onboarding
thanks
tasks
amy
staff
advance
joining
notes
present
youtube image

13 Jan 2020

No description provided.
  • 8 participants
  • 17 minutes
firewall
issue
users
security
providers
policy
discussion
tweaking
contribution
community
youtube image

17 Dec 2019

Be sure to check out the Application Infrastructure Security planning board: https://gitlab.com/groups/gitlab-org/-/boards/1420731?label_name[]=group%3A%3Aapplication%20infrastructure%20security
  • 1 participant
  • 7 minutes
deployments
intrusion
security
monitoring
mvc
container
dashboards
falco
groundwork
advanced
youtube image

17 Dec 2019

Be sure to check out the Threat Management planning board: https://gitlab.com/groups/gitlab-org/-/boards/1420734?&label_name[]=group%3A%3Athreat%20management
  • 1 participant
  • 5 minutes
security
vulnerability
threat
vulnerabilities
manage
targeting
important
vulnerable
detection
accountability
youtube image

22 Nov 2019

No description provided.
  • 6 participants
  • 13 minutes
defensive
security
upgraded
deployment
manage
defending
come
defend
protecting
firewall
youtube image

21 Oct 2019

No description provided.
  • 11 participants
  • 22 minutes
defense
security
defensive
defend
blue
defending
protecting
clarify
threat
modsecurity
youtube image

17 Oct 2019

Walk through of planned priorities for 12.5 iteration of GitLab, focused on Defend stage and Secure::Static Analysis group.
  • 2 participants
  • 15 minutes
reporting
firewall
ahead
secure
initiatives
dashboard
provide
capabilities
kickoff
currently
youtube image

16 Sep 2019

Kickoff for the GitLab 12.4 release, for the Defend stage and the Static Analysis and Dynamic Analysis groups for Secure stage
  • 4 participants
  • 9 minutes
sas
kubernetes
security
capabilities
cluster
seck
exposing
detection
manifests
vulnerabilities
youtube image

13 Sep 2019

Demo of the Web Application Firewall introduced in GitLab 12.3
  • 1 participant
  • 3 minutes
deploying
firewall
git
kubernetes
software
cluster
web
users
malicious
log
youtube image

9 Sep 2019

Quick demo on progress for enabling Web Application Firewall for Kubernetes

Issue: https://gitlab.com/gitlab-org/gitlab-ce/issues/65192
  • 5 participants
  • 29 minutes
kubernetes
workflow
firewall
devops
enabling
ajax
project
screens
docker
ip
youtube image

27 Aug 2019

No description provided.
  • 10 participants
  • 23 minutes
defense
announcing
capabilities
plan
secure
incremental
nbc
future
increasingly
expect
youtube image