Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Core

Enterprise Cloud Forensics and Incident Response

Cloud forensics breaks the habits endpoint examiners rely on. There is no drive to image, and the evidence you need may expire in ninety days. This course teaches what each provider records, and how to get it while it still exists.

You work in AWS, Azure, Google Cloud and Microsoft 365, rebuilding incidents from control plane logs, identity events and provider-native snapshots rather than from disks.

Duration
8 weeks
Format
Live online, instructor-led
Prerequisites
Advanced Incident Response and Threat Hunting
Class size
Capped at 12 learners
Enterprise Cloud Forensics and Incident Response

What you will be able to do

  • State which logs each major provider keeps by default and for how long
  • Acquire CloudTrail, Azure activity, GCP audit and Microsoft 365 unified audit data before it ages out
  • Snapshot and analyse cloud volumes without disturbing the running workload
  • Trace identity abuse including token theft, consent grants and role assumption
  • Reconstruct a business email compromise from mailbox audit and sign-in data
  • Investigate container and serverless activity where no host survives
  • Recommend logging changes that make the next incident investigable
  • Report a cloud incident in terms a regulator or insurer will accept

Course outline

6 modules

  • Shared responsibility and what you are permitted to collect
  • Control plane versus data plane evidence
  • Retention windows and how they end investigations
  • Provider preservation requests and their practical limits
  • PIPEDA breach reporting considerations for cloud held data

What you need before you start

  • Prior incident response experience, ideally the advanced hunting course
  • Basic familiarity with at least one cloud provider console
  • Ability to read JSON output and run command line tools
  • A personal or free tier cloud account is useful but not required

Who this course is for

  • Incident responders whose casework has moved into cloud tenants
  • Cloud engineers who get pulled into investigations
  • SOC leads designing cloud logging and retention
  • Consultants scoping cloud breaches for clients and insurers
  • Privacy and compliance staff who must understand cloud evidence

Where this leads

Prepares you for

CCSP

Awarded by ISC2

The evidence, logging and legal content here overlaps the Certified Cloud Security Professional body of knowledge. ISC2 sets that exam, verifies experience and confers CCSP on successful candidates. This course is preparation and practice; we issue no credential ourselves.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.