Talk With an Expert

SANS Security West 2023 - Hands-On Workshop: Building Detections in Azure

  • Tue, May 16 - Wed, May 17, 2023
  • 10:15PM - 12:15PM UTC
  • English
  • Ryan Nicholson
  • Technical Presentation
Webcast Hero

This is a 2-hour hands-on workshop. As with any enterprise environment, we can (and should) focus on hardening our defenses to keep the adversaries out, but these defenses may some day be evaded via a variety of methods. Cloud is no different. In this workshop, which is a follow-on from the talk “Building Better Cloud Detections... By Hacking? (Azure Edition)“, we will work through the process of creating a detection that we can use as defenders to spot an adversary performing attack techniques against our Azure environments. The overall process and takeaways will be:

- Establish proper logging to detect the adversarial activity

- Perform the attack to generate the appropriate artifacts

- Review the log event data

- Create an automated process to quickly discover this activity

- Test that the automated process is working effectively by “re-attacking” the Azure account

Prerequisites: An Azure account with administrator access

System Requirements: A modern web browser

Meet the speaker

Ryan Nicholson
Ryan Nicholson

Ryan Nicholson

Owner

Ryan’s extensive experience, including roles as a cybersecurity engineer for major Department of Defense cloud projects and as a lead auditor, underscores his dedication to enhancing the security posture of critical systems.

Read more about Ryan Nicholson