Conference

NorthSec 2026

Living Off The Pipeline: Defensive Research, Weaponized

May 14-15, 2026
Montréal, QC, Canada 🇨🇦
François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

For years, we wrote the defensive manuals. We built the “Living Off The Pipeline” (LOTP) inventory and released poutine to help you find the vulns. We even spoke at NorthSec about the theoretical risks of Build Pipeline compromise.

We have bad news: The Threat Actors were “in the room” taking notes.
In early 2025, we found the “smoking gun.” A Threat Actor on BreachForums laid out the full attack plan for a 0-day compromise of a major Open Source project, giving a direct shout-out to our poutine scanner and LOTP research as the source. Our defensive work has become their offensive playbook.

In this talk, we stop playing defense.

Introducing SmokedMeat: The “Metasploit for CI/CD.”

Our research team has a saying: 2025's Build Pipelines look like the average 2005 PHP Web App in terms of secure coding. They are wide open to “pwn requests” and command injections that lead to secrets exfiltration or privilege escalation via overprivileged tokens. SmokedMeat is the first Open Source Red Team framework designed to commoditize these compromises, demonstrating exactly what happens when a Threat Actor turns your infrastructure against you.

We will demonstrate a full exploitation chain: pivoting from unprivileged anonymous access on public repositories to private repository and intellectual property theft, the “gone in 60 seconds” jump from a workflow runner directly to permanent Cloud Admin, and the ability to escape ephemeral job contexts to implant permanent backdoors on your build infrastructure.

The era of “awareness” is over. This talk is a live demonstration of why your current CI/CD security strategy is already obsolete.

Read full abstract

### 2025

PolySécure Dec 4, 2025

Teknik - Don't Go with the Flaw

Garance De La Brosse
Garance De La Brosse
Garance De La Brosse ex-Junior Security Researcher

Garance completed her M. Eng thesis with the team, focusing on distribution threats to the Go ecosystem and package manager vulnerabilities.

, François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

PolySécure Nov 11, 2025

Teknik - Split-Second Side Doors: How Bot-Delegated TOCTOU Breaks The CI/CD Threat Model

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

, Alexis-Maurer Fortin
Alexis-Maurer Fortin
Alexis-Maurer Fortin Senior Product Security Engineer

Alexis-Maurer is a co-creator of poutine and the architect behind Boost Security's large-scale cloud scanning infrastructure. A prolific Go developer, he wrote the majority of the codebase powering the team's automated vulnerability discovery systems.

, Sébastien Graveline
Sébastien Graveline
Sébastien Graveline Security Researcher

Sébastien brings Red Team expertise to the research team and is a major contributor to the Living Off The Pipeline (LOTP) project. An avid CTF player who has won several prestigious competitions, he specializes in offensive CI/CD exploitation techniques and turning theoretical attack patterns into practical demonstrations.

The Security Repo Oct 29, 2025

Supply Chain Warfare: CI/CD Threats and Open Source Security

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

CRISIS 2025 🇨🇦 Gatineau, QC Oct 22, 2025

Panel sur la Cybersécurité dans les chaînes d'approvisionnement

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

OWASP AppSec Days France 🇫🇷 Paris Sep 23, 2025

OWASP AppSec Days France 2025

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

Munich Cyber TTP (MCTTP) 🇩🇪 Munich Sep 17, 2025

Living Off the Pipeline: From Supply Chain 0-Days to Predicting the next XZ-like attacks

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

OWASP Montréal / Cybereco 🇨🇦 Montréal, QC Aug 28, 2025

Living Off the Pipeline / À l'Ombre du Pipeline

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

OpenSSF SOSS Community Day NA 2025 🇺🇸 Denver, CO Jun 26, 2025

Living Off The Pipeline: From Supply Chain 0-Days to Predicting the Next XZ-Like Attacks

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

PolySécure May 15, 2025

Teknik - Living Off the Pipeline: From Supply Chain 0-Days to Predicting the next XZ-like attacks

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

NorthSec 2025 🇨🇦 Montréal, QC May 15, 2025

Living Off The Pipeline: From Supply Chain 0-Days to Predicting the next XZ-like attacks

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

NorthSec 2025 🇨🇦 Montréal, QC May 15, 2025

AppSec Q&A

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

PolySécure 🇨🇦 Montréal, QC May 15, 2025

Spécial - Panel à NorthSec 2025

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

Cyberconférence Cybereco 2025 🇨🇦 Montréal, QC Apr 8, 2025

Panel sur la valeur du DevSecOps dans les processus de GIA

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

The Elephant in AppSec Mar 19, 2025

The Open Source Security Crisis: Is Trust the Weakest Link in Supply Chain?

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

Why do we keep ignoring CI security

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

DSO Overflow Jan 31, 2025

Securing the Software Supply Chain

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

### 2024

Arbitrary Code Execution 0-day in Build Pipelines

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

SecTOR (Black Hat Summit) 🇨🇦 Toronto, ON Oct 22, 2024

Under The Radar: How we found 0-days in the Build Pipeline of OSS Packages

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

OWASP Global AppSec 2024 🇺🇸 San Francisco, CA Sep 26, 2024

Under The Radar: How we found 0-days in the Build Pipeline of OSS Packages

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

FLOSS Weekly May 22, 2024

I'll Buy You A Poutine

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

PolySécure May 16, 2024

Teknik - Build Pipeline Supply Chain Attack

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

NorthSec 2024 🇨🇦 Montréal, QC May 16, 2024

Under the Radar: How we found 0-days in the Build Pipeline of OSS Packages

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

, Benoît Côté-Jodoin
Benoît Côté-Jodoin
Benoît Côté-Jodoin ex-Senior Product Security Engineer

Benoît was a co-creator of both poutine and the Living Off The Pipeline (LOTP) project. He contributed extensively to supply chain security research and built core tooling that powers Boost Security's vulnerability discovery capabilities.

OpenSSF SOSS Community Day NA 2024 🇺🇸 Seattle, WA Apr 15, 2024

Under the Radar: How We Found 0-Days in the Build Pipeline of OSS Packages

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

, Benoît Côté-Jodoin
Benoît Côté-Jodoin
Benoît Côté-Jodoin ex-Senior Product Security Engineer

Benoît was a co-creator of both poutine and the Living Off The Pipeline (LOTP) project. He contributed extensively to supply chain security research and built core tooling that powers Boost Security's vulnerability discovery capabilities.

### 2023

Cloudanix Oct 13, 2023

Shielding Software Supply Chain: Strengthening Security Measures

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

Actionable Software Supply Chain Security

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

NorthSec 2023 🇨🇦 Montréal, QC May 18, 2023

Broken Links: Behind the scenes of Supply Chain breaches

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

Wiz Webinar May 10, 2023

Cloudy with a Chance of Security: How Mid-Sized Organizations are Solving for 2023's Biggest Cloud Security Challenges

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

BSides NYC 🇺🇸 New York City, NY Apr 22, 2023

Broken Links: Behind the scenes of Supply Chain breaches

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

### 2022

BSides Montréal 🇨🇦 Montréal, QC Sep 10, 2022

2021 – The Year Of Supply Chain Breaches

François Proulx
François Proulx
François Proulx VP of Security Research

François is the VP of Security Research at Boost Security and co-creator of the poutine Open Source CI/CD scanner. He co-founded the Living Off The Pipeline (LOTP) project to describe the abuse of build tools for lateral movement. After spending years teaching defenders how to secure their workflows, he is now demonstrating how attackers are dismantling them.

, Zaid Al Hamami
// abstract