Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Core

Cloud Threat Detection

Cloud threat detection training in Toronto for analysts who can read an endpoint alert but freeze in front of a CloudTrail event. The whole course sits in the audit log, which is where cloud attacks are visible or not visible at all.

You learn the structure of AWS, Azure and Google Cloud audit records, the attacker techniques each one exposes, and how to write detections that fire on real behaviour instead of on every automated job in the estate.

Duration
8 weeks
Format
Live online, instructor-led
Prerequisites
Cloud Security Essentials
Class size
Capped at 12 learners
Cloud Threat Detection

What you will be able to do

  • Read a CloudTrail, Azure Activity and GCP audit record field by field
  • Distinguish routine automation from attacker activity in a noisy log stream
  • Map cloud attacker behaviour to the MITRE ATT&CK cloud matrix
  • Write detections for credential abuse, privilege escalation and persistence
  • Detect data exfiltration signals in storage and egress telemetry
  • Measure a detection's false positive rate before it goes live
  • Build a log coverage map and identify blind spots in your telemetry
  • Hand a tuned detection to a SOC with the context an analyst needs

Course outline

6 modules

  • CloudTrail record structure, management against data events
  • Azure Activity Log, diagnostic settings and Entra ID sign in logs
  • GCP admin activity, data access and system event logs
  • What each provider does not log by default
  • Building a coverage map before writing any rules

What you need before you start

  • Cloud Security Essentials or equivalent cloud platform familiarity
  • Experience reading logs and writing basic queries in a SIEM or log tool
  • Comfort with JSON structure and simple regular expressions
  • A laptop able to run a local log analysis environment

Who this course is for

  • SOC analysts whose alert queue now includes cloud sources
  • Detection engineers adding cloud coverage to an existing rule set
  • Threat hunters working across cloud tenancies
  • Cloud engineers who own the logging pipeline and want to use it
  • Incident responders who need to find the evidence faster

Where this leads

Prepares you for

CySA+

Awarded by CompTIA

Detection, analysis and monitoring work in this course lines up with the CompTIA CySA+ objectives, with a cloud emphasis CySA+ treats more broadly. CompTIA awards the certification through its own exam. The academy provides the training only.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.