SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCloud-based identity security is notoriously slippery: every cloud has a different security philosophy and the actions that cloud logs describe are not always easy for a defender to visualize.
This is especially true for Azure, with its complex web of roles, groups, subscriptions, and similar-sounding settings. Luckily, with a little grit, purple-teaming, and the scientific method, we can wrangle actionable understanding out of whatever cloud dens we may find ourselves in.
This presentation provides a repeatable framework for purple-teaming cloud threat detection and explains key descriptors that should be captured as part of Azure threat research.
Learning Objectives:
- Overview of cloud purple teaming as applied to Azure
- Research framework for cloud purple teaming
- Key descriptors to include in threat detection research
Lydia Graslie is a Threat Detection Engineer at a Fortune 500 specializing in SaaS security.
Read more about Lydia Graslie