Build cloud threat detection capabilities to identify, analyze, and respond to sophisticated attacks in AWS and Azure environments. This course covers cloud-native logging, threat models, intrusion detection, and continuous monitoring across AWS, Azure, and Microsoft 365 to help you maintain a robust security posture.
Develop elite cloud threat detection capabilities for AWS and Azure environments. SEC541 equips you to identify, detect, and respond to sophisticated attacks targeting cloud infrastructure.
Through real-world scenarios and 22 hands-on labs, you will master cloud-native logging, build effective threat detection systems, and understand the unique aspects of cloud architecture that attackers exploit.
What You Will Learn:
Detection Engineering Fundamentals
Analyze real-world cloud attacks like Code Spaces and Tesla Kubernetes
Build detections from threat intelligence
Implement deception engineering with decoy networks
Investigate using CloudTrail, CloudWatch, and VPC flow logs
Compute and Application Security
Monitor virtual machines, containers, and serverless functions
Detect resource hijacking and ransomware attacks
Leverage CSPM and CWP services in AWS and Azure
Investigate attacks against Kubernetes clusters
Security Services and SIEM Integration
Implement GuardDuty, Microsoft Defender, and Sentinel
Centralize security data across multi-cloud environments
Conduct vulnerability analysis and SIEM correlation
Track attackers across multiple log sources
Microsoft Ecosystem and Automation
Investigate Exchange and Entra ID attacks
Master KQL for log analysis
Build AI tools with Azure AI Foundry for security operations
Automate incident response and forensic workflows
Culminates in CloudWars Challenge to test detection and response skills. Prepares for GCTD certification. 30 CPEs across 5 days.
Highlights
Build cloud-native detection systems using CloudTrail, CloudWatch, GuardDuty, Microsoft Sentinel, and KQL for threat hunting across AWS and Azure environments
22 hands-on labs including real attack investigations, ransomware detection, Kubernetes security, automated forensics, and the CloudWars Challenge
Certification: Prepares for GCTD. For cloud security analysts and detection engineers. 30 CPEs across 5 days.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing offers one pricing option: a single-user license for SEC541: Cloud Security Threat Detection. You buy access under a contract model, billed per unit. Each unit covers one individual learner. To train more people, you add more units, so cost scales with the number of users. There are no separate tiers, instance sizes, or usage add-ons to choose from. The pricing structure is straightforward: pick the quantity of single-user licenses you need.
Top-of-mind questions for buyers
What does one single-user license cover, and how is a user counted?
One unit is one individual learner's license for the SEC541 course. Course materials are for your individual use only and cannot be shared or resold. To train additional people, you buy a separate unit for each learner. Each user needs their own license.
How long does my access to the course last after purchase?
Self-paced OnDemand access runs for a set period of calendar time after you start. OnDemand access begins when you click the Start Course button, or 14 days after the course is available if you do not start it. Access does not renew automatically once the period ends.
Does the license include the GIAC certification exam, or is that separate?
The single-user license covers the course itself. GIAC certification is not required and is purchased separately. SANS training and GIAC certifications can be bought together, but you are not obligated to add the certification exam. The course teaches skills you can apply without taking the exam.
www.sans.org
Helpful?
Vendor refund policy
Refund requests must be submitted by the deadline date specific to User's training event. To find the specific deadline date for User's training event, please go to training event link at <www.sans.org> and click on the cancellations link.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
CloudFastener is a fully managed security service that comprehensively manages and operates various AWS security services. It protects and monitors the AWS environment 24/7/365, prioritizes risks that need to be addressed, and supports appropriate handling and response to security alerts. It strengthens AWS security and provides a secure environment to focus on your business.
Cyber Security Cloud Managed Rules are designed to mitigate and minimize vulnerabilities, including all those on OWASP Top 10 Threats list. With the OWASP Set, you can start protecting your web applications right away with a low false-positive rate and a higher defense capability.
Cyber Security Cloud Managed Rules are designed to mitigate and minimize vulnerabilities, including all those on OWASP API Security Top 10 Threats list. By using our rulesets, you can start protecting your API Gateway right away with a low false-positive rate and a higher defense capability.
We offer a cost-effective, proven approach and an established workflow to conduct comprehensive cloud security assessments led by our experts and augmented by ML and purpose-built AI engine. Our approach combines understanding of your cloud architecture, review of processes and technical assessment of cloud misconfigurations. We partner with Secberus for configuration information gathering.
Our detailed and actionable recommendations and prioritized implementation roadmap address critical and high-risk findings to empower your business to effectively manage and mitigate cyber threats of today and tomorrow.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.