Group Purchasing
Group Purchasing

SEC541: Cloud Security Threat Detection

SEC541Cloud Security
  • 5 Days (Instructor-Led)
  • 30 Hours (Self-Paced)
Course authored by:
Shaun McCulloughRyan Nicholson
Shaun McCullough & Ryan Nicholson
SEC541: Cloud Security Attacker Techniques, Monitoring, and Threat Detection
Course authored by:
Shaun McCulloughRyan Nicholson
Shaun McCullough & Ryan Nicholson
  • GIAC Cloud Threat Detection (GCTD)
  • 30 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 22 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Acquire elite cloud threat detection capabilities to identify, analyze, and respond to sophisticated attacks in AWS and Azure environments.

Course Overview

SEC541: Cloud Security Threat Detection immerses students in hands-on labs that focus on detecting threats and investigating attacks across AWS, Azure, and Microsoft 365 environments. Threat-driven curriculum to equips security professionals with practical cloud threat detection techniques through analyses of real-world attacks.

The course begins with an analysis of real-world case studies, followed by implement detection controls and investigate suspicious activities. From there, you’ll build a detection engineering process, and explore cloud-native logging, API monitoring, and effective detection systems tailored to cloud environments. You’ll also gain exposure to cloud threat hunting strategies that enhance proactive detection and reduce response times.

By the end of the course, you’ll have developed practical skills to detect, investigate, and respond to sophisticated cloud threats. Security professionals will gain expertise beyond theory, implementing cloud threat detection strategies that address the critical differences between on-premises and cloud security monitoring.

Cloud Defense: Advanced Threat Detection for AWS and Azure

It's undeniable that cloud environments offer unparalleled benefits; however, poorly trained personnel can expose your organization to an ever-expanding list of dynamic threats. SEC541: Cloud Security Threat Detection is designed to address these challenges by equipping professionals with the skills to identify, detect, and respond to threats in cloud infrastructures. This comprehensive course delves into cloud-native logging, threat models, intrusion detection, and continuous monitoring, ensuring that your organization can maintain a robust security posture in AWS, Azure, and Microsoft 365 environments.

SEC541 immerses students in real-world scenarios, teaching them to navigate cloud-specific logs, build effective threat detection systems, and understand the unique aspects of cloud architecture. By mastering these skills, your team can significantly reduce detection and response times, enhance visibility into the cloud threat landscape, and effectively defend against sophisticated attacks.

SEC541 boosts the proficiency of cloud security analysts and empowers teams to operate more efficiently and effectively, maximizing your organization's security capabilities. Equip your workforce with the latest knowledge in cloud security threat detection and ensure your organization is prepared to tackle the complexities of modern cloud security challenges.

Author Statement

"Cloud service providers are giving us new tools faster than we can learn how to use them. As with any new and complex tool, we need to get past the surface-level "how-to" so we can radically reshape our infrastructure. SEC541 is an overview of the elements of AWS and Azure that you may have used before but are now ready to truly explore. By the end of the class, you'll be confident knowing that you have the skills to start looking for threats and building a true threat detection program in AWS and Azure."

- Shaun McCullough and Ryan Nicholson

What You'll Learn

  • Learn how to build a detection engineering program
  • Analyze cloud API logs to detect unauthorized activity
  • Implement effective cloud-native security monitoring
  • Utilize Azure and AWS detection services effectively
  • Apply threat intelligence and generative AI to cloud security
  • Build automation for incident response in the cloud

Business Takeaways

  • Reduce cloud breach detection time and impact
  • Implement cloud-specific security monitoring strategies
  • Establish effective cloud detection engineering program
  • Enhance visibility across multi-cloud environments
  • Leverage native tooling to minimize security costs
  • Align detection capabilities to actual cloud threats
  • Accelerate incident response with automation

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC541: Cloud Security Threat Detection.

Section 1Detection of Cloud API and Network Attacks

The course begins with an investigation of a real-world cloud attack, breaking down the tactics and demonstrating how to monitor cloud management APIs. You will analyze API logs, implement network monitoring, and develop detection strategies for unauthorized activities in cloud environments.

Topics covered

  • Cloud attack analysis methodology
  • Detecting engineering
  • JSON log parsing techniques
  • Network traffic analysis in cloud
  • Detection strategy implementation

Labs

  • Investigate attacker evasions with CloudTrail
  • Building detections in CloudWatch
  • Deploying and operating a decoy honey network
  • Network Analysis in the Cloud

Overview

Section one focused on the building blocks of a cloud-based detection engineering program by applying threat intelligence to build detections, perform investigations, and building deception engineering resources.

Full Lab Details

  • Investigate defense evasions
  • Investigate and detect with CloudWatch
  • The decoy network
  • Network analysis with VPC flow logs

Full Topic Details

  • Code Spaces case study
  • Detection engineering
  • Cloud management API
  • Building detections
  • Deception engineering
  • Network flow investigations

Section 2Compute and Application Attacks

Students focus on monitoring compute resources including virtual machines, containers, and serverless functions. You’ll then analyze the Tesla Kubernetes attack, implement logging for compute environments, and develop detection strategies for abnormal behavior patterns in cloud workloads.

Topics covered

  • Virtual machine and container logging architecture
  • Metadata service risks and exploitation techniques
  • Kubernetes and container monitoring and investigation
  • Cloud database attack detection and data exfiltration
  • eBPF and log agent customization for threat detection

Labs

  • Threat intelligence generation
  • Enhanced host visibility
  • Kubernetes command and control
  • Cryptojacking cloud services
  • Cloud storage ransomware

Overview

In section 2, dig deeper into your applications, serverless deployments and compute systems running within the cloud environment.

Full Lab Details

  • Leverage KQL to correlate threat intelligence with activities
  • Detect source of web application attack using Falco monitoring local network activity
  • Investigate attack against Azure Kubernetes cluster
  • Detect resource hijacking in cloud infrastructure
  • Detect and investigate ransomware attack on Azure storage container.

Full Topic Details

  • Telsa case study
  • Host visibility
  • Metadata services
  • Application component logging
  • Managed container services
  • Operational logging techniques
  • Identify data exfiltration

Section 3Security Services and Investigations

You’ll learn to implement and leverage cloud-native detection services, discovering the best ways to conduct resource inventory, identify sensitive data in unauthorized locations, and centralize security data for comprehensive threat monitoring across cloud environments.

Topics covered

  • Leveraging CSPM and CWP services in Azure and AWS
  • Cloud resource inventory techniques
  • Detecting cross-account role persistence attacks
  • Data exposure and risk evaluation
  • Analyzing activities across log types

Labs

  • Metadata services and GuardDuty setup
  • Detecting command injection in Lambda
  • Macie configuration for data discovery
  • Inspector deployment for vulnerabilities
  • Centralized logging with ElasticSearch

Overview

In section 3, learn to leverage cloud providers’ security services to detect activity, investigate resources, identify data compromises, understand vulnerability systems, and pivot through many different telemetry types.

Full Lab Details

  • Attacking Sherlock’s blog
  • Purple-teaming lambda
  • Detecting sensitive data
  • Vulnerability analysis
  • SIEM analysis

Full Topic Details

  • Capital One case study
  • GaurdDuty and defender
  • Cross-account role persistence
  • Function attack surface
  • Investigating resources
  • Vulnerability analysis services
  • Tracking across logs

Section 4Microsoft Ecosystem

You’ll examine Microsoft 365 and Azure-specific detection capabilities and incorporating AI into their security program. This section concentrates on techniques to investigate Exchange attacks, utilize Kusto Query Language for log analysis, and implement Microsoft Defender and Sentinel for comprehensive threat detection in Microsoft cloud environments.

Topics covered

  • Microsoft 365 attack analysis
  • Sentinel strategies and advanced KQL
  • Defender XDR
  • Storage account monitoring
  • Cloud services using AI

Labs

  • Baker221b onboarding and active incidents
  • Suspicious email investigation
  • Authentication attacks and rogue Activities
  • Sherlock's Data Breach
  • Sherlock’s AI Assistant

Overview

In section 4, dive deep into Azure's ecosystem and tackle the unique threats that can occur.

Full Lab Details

  • Approaching security investigations as an MSSP
  • Microsoft 365 Exchange investigation
  • Detecting authentication attacks and investigating activities
  • Evaluating a data breach in Azure.
  • Using Azure AI Foundry to build tools to support security operations.

Full Topic Details

  • Malware Bytes case study
  • Microsoft Sentinel
  • Microsoft 365 and Microsoft XDR
  • Entra ID
  • Command and control
  • Storage monitoring
  • AI tooling in the cloud

Section 5Data Shipping, Automation and CloudWars

You will begin by automating incident response in cloud environments and then culminate the course by participating in the CloudWars Challenge. You’ll walk away with strategies to implement automated forensic workflows and develop skills in a capstone exercise designed to test their ability to detect and respond to cloud-based threats.

Topics covered

  • Cloud incident response automation
  • Forensic workflow implementation
  • Detection engineering principles
  • Multi-cloud security integration
  • Threat hunting methodologies

Labs

  • Automated forensics workflow setup
  • Results analysis techniques
  • CloudWars Challenge participation

Overview

In this final section, learn how to cross pull logs across multiple clouds, automate response actions, and put your new skills to the test in a Capture the Flag event.

Full Lab Details

  • Cross-Cloud Log Shipping
  • Automated Anomaly Detection
  • CloudWars Challenge

Full Topic Details

  • Data Shipping, Enrichment and Export
  • Automating Detection and Response Actions

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration And Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 10.15.x or newer.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.

If you have additional questions about the laptop specifications, please contact customer service.

SEC541 training is recommended for a diverse range of individuals, including:

  • Cloud Security Analysts
  • Threat Detection Engineers
  • Security Operations Center (SOC) Operators
  • Security Incident Responders
  • Cloud Security Architects
  • Penetration Testers
  • SOC Managers
  • Blue Team Members
  • Forensic Analysts
  • Offensive Security Professionals looking to understand defensive techniques
  • IT Professionals transitioning to cloud security roles
  • Anyone responsible for securing cloud environments in any industry

The GIAC Cloud Threat Detection (GCTD) certification validates a practitioner's ability to detect and investigate suspicious activity in cloud infrastructure. GCTD-certified professionals are experienced in cyber threat intelligence, secure cloud configuration, and other practices needed to defend cloud solutions and services.

  • Detecting attacks in the cloud
  • Cloud investigations and cyber threat intelligence
  • Assessments and automation in AWS and Azure

More Certification Details

  • Printed and electronic courseware
  • MP3 audio files of the complete course lecture
  • Access to virtual machine in the AWS cloud
  • SANS provided AWS account
  • SANS provided Azure account

Students should be familiar and have hands-on experience with AWS or Azure, especially security professionals working in the cloud security field who understand basic threats and attack vectors. 

The course assumes that students can understand or do the following without help:

  • Understand basic cloud resources such as virtual machines, storage services, and Identity Access Management
  • Use the Linux command line console.
  • Understand how identity access roles/policies work in cloud environments
  • Understand basic cloud networking capabilities

Common prerequisite SANS courses for SEC541 are either:

The SEC541 course is part of both the Cloud Security Analyst and Cloud Detection and Response journeys. The journeys prepare professionals to utilize security solutions to enable defenses, detect attacks, and monitor and test cloud environments to identify and investigate threats.

Cloud security threat detection involves monitoring, analyzing, and responding to suspicious activities across cloud environments. This approach uses cloud-native logs, specialized monitoring tools, and detection services to identify unauthorized access, data exfiltration, and other security threats in AWS, Azure, and other cloud platforms.

This course enhances your value as a security professional by providing rare hands-on experience in cloud-specific threat detection, a skill in high demand as organizations migrate critical systems to the cloud. You'll develop practical expertise that bridges on-premises and cloud security, positioning you for roles in SOC operations, detection engineering, and cloud security architecture.

Relevant Job Roles

Cloud Security Analyst Training, Salary, and Career Path

Cloud Security

A Cloud Security Analyst monitors and analyzes activity across cloud environments, proactively detects and assesses threats, and implements preventive controls and targeted defenses to protect critical business systems and data.

Explore learning path

Cyber Intelligence Analyst Training, Salary, and Career Path

European Cybersecurity Skills Framework

Cyber Intelligence Analysts analyze evolving cyber threats, profile adversaries, and leverage intelligence platforms to proactively inform security decisions and mitigation strategies, bridging technical insights with strategic awareness.

Explore learning path

Threat Management

SCyWF: Protection And Defense

This role collects and analyzes information about threats, searches for undetected threats and provides actionable insights to support cybersecurity decision-making. Find the SANS courses that map to the Threat Management SCyWF Work Role.

Explore learning path

Cloud Threat Detection and Response

Cloud Security

Monitor, test, detect, and investigate threats to cloud environments.

Explore learning path

Incident Response (OPM 531)

NICE: Protection and Defense

Responsible for investigating, analyzing, and responding to network cybersecurity incidents.

Explore learning path

Cybersecurity Implementer

European Cybersecurity Skills Framework

Develop, deploy and operate cybersecurity solutions (systems, assets, software, controls and services) on infrastructures and products.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 11

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources