Detection engineering and automation
Having worked the breach by hand, the cohort now writes the detections that would have surfaced it on day one, and automates the response steps that were done manually in earlier sessions.
- When
- Sat 21 Nov 2026 · 10:30–13:30 IST
- Where
- Bangalore or virtual
- Cohort size
- 25 in person · 40 including virtual
Sessions can be booked individually, or take the full six-session cohort.
What you leave able to do
- Write KQL detections against the evidence from earlier sessions
- Tune a detection to survive contact with real traffic
- Automate a containment playbook end to end
Run of play
- 1
Writing the detection
From an incident you worked to a rule that catches the next one.
- 2
Tuning
A rule that fires on everything is the same as no rule.
- 3
Automation
The response playbook, run without a human in the loop.
The case
Where this sits in the story
All six Saturdays run on one continuous breach, so every session picks up where the last one left off.
The intrusion moves to the cloud control plane, which is where modern incidents become serious. A stolen service account assumes AdminRole in AWS; a Lambda named backup-cleanup is deployed during the breach window and runs for six hours before anyone notices. Every API call is in CloudTrail, if you can read it.
Who this session suits
Analysts who need cloud fluency and the detection-engineering side: writing the rules and automating the response rather than working alerts by hand.
Scope
What this session covers
- Writing a KQL detection, measuring its false-positive rate, and tuning it
- Incident reporting that survives an auditor: sourced timeline, SLA maths
- CloudTrail, Azure Activity Logs and VPC Flow as evidence sources
- IAM privilege escalation and persistent access-key backdoors
- S3 exfiltration and the bucket policy quietly made public
- Lambda persistence and confirming attacker control from configuration
- Cross-account role assumption, and CloudTrail being disabled
- SOAR playbook design: detect, block, delete and page inside 90 seconds
- The phishing playbook re-run in KQL — six hours of work in twenty minutes
Hands-on
The labs you work
9 hands-on labs, 490 minutes of lab time. Each runs in a cloud terminal against real evidence — logs, PCAPs, event data — and is graded on what you find, not on a multiple-choice answer. Lab access continues for 3 months, so the work does not stop when the session ends.
- 1Detection Engineering — Write, Test, Tunesoc-sentinel-ready65 min
- 2SIEM Incident Reporting from Sentinel Datasoc-sentinel-ready55 min
- 3Cloud Logging: CloudTrail, Activity Logs, VPC Flowsoc-cloud-soar40 min
- 4IAM Privilege Escalation: The Cloud Kill Chainsoc-cloud-soar55 min
- 5S3 Exfiltration: Hunting the Quiet Drainsoc-cloud-soar50 min
- 6Lambda Persistence: Backdoor Analysissoc-cloud-soar55 min
- 7Cross-Account Lateral Movement Detectionsoc-cloud-soar55 min
- 8SOAR Playbooks: Automating the SOC Responsesoc-cloud-soar55 min
- 9Chapter 32: Phishing Playbook in KQLsoc-cloud-soar60 min
Tools used
- AWS CloudTrail
- Azure Activity Logs
- VPC Flow Logs
- KQL
- SOAR playbooks
- Sentinel
MITRE ATT&CK coverage (27)
- T1021.003 Remote Services: Distributed Component Object Model
- T1041 Exfiltration Over C2 Channel
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1059 Command and Scripting Interpreter
- T1068 Exploitation for Privilege Escalation
- T1071.001 Application Layer Protocol: Web Protocols
- T1074.002 Data Staged: Remote Data Staging
- T1078.004 Valid Accounts: Cloud Accounts
- T1087.004 Account Discovery: Cloud Account
- T1098.001 Account Manipulation: Additional Cloud Credentials
- T1114.002 Email Collection: Remote Email Collection
- T1199 Trusted Relationship
- T1211 Exploitation for Defense Evasion
- T1222 File and Directory Permissions Modification
- T1486 Data Encrypted for Impact
- T1525 Implant Internal Image
- T1530 Data from Cloud Storage Object
- T1548 Abuse Elevation Control Mechanism
- T1562.001 Disable or Modify Tools
- T1562.001 Impair Defenses: Disable or Modify Tools
- T1566 Phishing
- T1566.001 Spearphishing Attachment
- T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
- T1578.001 Modify Cloud Compute Infrastructure: Create Snapshot
- T1580 Cloud Infrastructure Discovery
- T1588 Obtain Capabilities
- T1619 Cloud Storage Object Discovery
Schedule
The full cohort
One continuous case across six Saturdays. Sessions build on each other, and each one can also be booked on its own.
- Sat 17 Oct 2026Foundations and the first alert10:30–13:30 ISTDetails →
- Sat 24 Oct 2026AI-era phishing and the initial foothold10:30–13:30 ISTDetails →
- Sat 31 Oct 2026Endpoint investigation and containment10:30–13:30 ISTDetails →
- Sat 7 Nov 2026Diwali holiday — no sessionNo session
- Sat 14 Nov 2026Cloud SOC and lateral movement10:30–13:30 ISTDetails →
- Sat 21 Nov 2026Detection engineering and automation10:30–13:30 ISTYou are here
- Sat 28 Nov 2026Immersive day and certification exam10:30–17:30 IST · full dayDetails →
Taking the whole cohort?
The six sessions are one continuous case, and the full course page carries the curriculum, the certification detail and the cohort pricing.

