Cloud Threat Detection
Cloud threat detection training in Toronto for analysts who can read an endpoint alert but freeze in front of a CloudTrail event. The whole course sits in the audit log, which is where cloud attacks are visible or not visible at all.
You learn the structure of AWS, Azure and Google Cloud audit records, the attacker techniques each one exposes, and how to write detections that fire on real behaviour instead of on every automated job in the estate.
- Duration
- 8 weeks
- Format
- Live online, instructor-led
- Prerequisites
- Cloud Security Essentials
- Class size
- Capped at 12 learners

What you will be able to do
- Read a CloudTrail, Azure Activity and GCP audit record field by field
- Distinguish routine automation from attacker activity in a noisy log stream
- Map cloud attacker behaviour to the MITRE ATT&CK cloud matrix
- Write detections for credential abuse, privilege escalation and persistence
- Detect data exfiltration signals in storage and egress telemetry
- Measure a detection's false positive rate before it goes live
- Build a log coverage map and identify blind spots in your telemetry
- Hand a tuned detection to a SOC with the context an analyst needs
Course outline
6 modules
- CloudTrail record structure, management against data events
- Azure Activity Log, diagnostic settings and Entra ID sign in logs
- GCP admin activity, data access and system event logs
- What each provider does not log by default
- Building a coverage map before writing any rules
What you need before you start
- Cloud Security Essentials or equivalent cloud platform familiarity
- Experience reading logs and writing basic queries in a SIEM or log tool
- Comfort with JSON structure and simple regular expressions
- A laptop able to run a local log analysis environment
Who this course is for
- SOC analysts whose alert queue now includes cloud sources
- Detection engineers adding cloud coverage to an existing rule set
- Threat hunters working across cloud tenancies
- Cloud engineers who own the logging pipeline and want to use it
- Incident responders who need to find the evidence faster
Where this leads
Prepares you for
CySA+
Awarded by CompTIA
Detection, analysis and monitoring work in this course lines up with the CompTIA CySA+ objectives, with a cloud emphasis CySA+ treats more broadly. CompTIA awards the certification through its own exam. The academy provides the training only.
Questions about this course
More in cloud security
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



