Masterclass: Incident Response in the Cloud
- Course Code IRC
- Duration 4 days
Course Delivery
Jump to:
Course Delivery
This course is available in the following formats:
-
Virtual Learning
Learning that is virtual
Request this course in a different delivery format.
Course Overview
Top
This immersive training delivers a complete, hands-on journey through Azure security, identity abuse, threat detection, and cloud incident response. Students begin by establishing core foundations – Azure architecture, governance, logging, and the security stack, before progressing into the full Azure Cyber Kill Chain. Participants will perform real-world attacks across identity, compute, storage, and control-plane layers, including token theft, AiTM phishing, privilege escalation, service principal compromise, misconfigurations, and persistence techniques unique to Azure.
Course Schedule
TopTarget Audience
TopThe course is perfect for security architects, Entra ID administrators, security administrators, and security auditors.
Enterprise administrators, infrastructure architects, security professionals, systems engineers, network administrators, IT professionals, security consultants and other people responsible for implementing network and perimeter security.
Course Objectives
TopCourse Content
Top
Module One: Azure Security and Incident Response Fundamentals
Module Two: Deep Dive into Entra ID and Governance
Module Three: Core Controls, Benchmarks, and Logging
Module Four: Reconnaissance and Initial Access
Module Five: Infrastructure and Network Attacks
Module Six: Execution and Privilege Escalation
Module Seven: Advanced Identity Attacks and Credential Access
Module Eight: Persistence Technique
Module Nine: Exfiltration and Impact
Module Ten: KQL for Incident Response
Module Eleven: Advanced Hunting and Detection
Module Twelve: Graph API for Incident Response
Module Thirteen: Responding to Azure Attacks (NIST)
Module Fourteen: Remediation and Strategic Hardening
Module Fifteen: Advanced and Strategic Best Practices
Module Two: Deep Dive into Entra ID and Governance
Module Three: Core Controls, Benchmarks, and Logging
Module Four: Reconnaissance and Initial Access
Module Five: Infrastructure and Network Attacks
Module Six: Execution and Privilege Escalation
Module Seven: Advanced Identity Attacks and Credential Access
Module Eight: Persistence Technique
Module Nine: Exfiltration and Impact
Module Ten: KQL for Incident Response
Module Eleven: Advanced Hunting and Detection
Module Twelve: Graph API for Incident Response
Module Thirteen: Responding to Azure Attacks (NIST)
Module Fourteen: Remediation and Strategic Hardening
Module Fifteen: Advanced and Strategic Best Practices
Course Prerequisites
Top- To attend this training, you should have a good hands-on experience in administering Windows infrastructure. At least 5 years in the field is recommended. All attendees should have experience with Active Directory Domain Services (AD DS) administration.
Test Certification
Top- After completing the course, participants will receive a CQURE Certificate of Completion and will also be eligible for CPE points.