Sign up for our free What in the Actual Cyber?! 2026 in Review Summit December 9 Register Here

Workshop: Azure Incident Response

Course Authored by .

In this four-hour workshop, incident response professional Gerard Johansen will guide you through the key aspects of responding to incidents in the Azure public cloud and M365 solutions.

Course Length: 4 Hours

Includes a Certificate of Completion



Next scheduled date: November 6th, 2026 @ 12:00 PM ET

Description

In this four-hour workshop, incident response professional Gerard Johansen will guide you through the key aspects of responding to incidents in the Azure public cloud and M365 solutions.

Using a combination of analyzing common attacks and labs, students will walk through evidence acquisitor, processing and analysis using the SOF-ELK platform. From here, they will examine immediate actions to contain compromised credentials and isolated impacted systems. Further examination of post-compromise activity will also be covered, concluding with proper Eradication and Recovery. Rounding out the workshop will be a discussion on post-incident activity and additional resources.

Who Should Take This Workshop

  • Security operations practitioners
  • Cloud security engineers
  • DFIR analysts

What You’ll Learn

  • Understand the unique nature of cloud incidents
  • Adequately prepare an Azure & M365 environment for immediate incident response
  • Identify log sources and analyze common attacks
  • Isolate and contain common identity-based attacks
  • Extract additional evidence from Azure resources
  • Eradication and recovery of Azure & M365 services
  • System Requirements
    • Students will need to download and run the SANS SOF-ELK VM on their local system.
  • VM/Lab/Student Requirements
    • Students should download the SANS SOF-ELK platform prior to the workshop. Sample evidence files will be provided prior to labs. https://github.com/philhagen/sof-elk/wiki/Virtual-Machine-README. Additionally, students should get a Maxmind account. From here, we will be using the GeoLite IP Location database

Syllabus

  • The Azure & M365 Environment and the Shared Responsibility Model
  • Preparation for Azure Incident Response
  • A deep dive into Azure & M365 logging
  • Adversary in the Middle / Business Email Compromise Attacks
  • Extracting the Unified Audit Log
  • Configuring the SOF-ELK log analysis platform
  • Investigating AitM and BEC attacks
  • Immediate Isolation and Containment actions
  • Extracting the Azure Activity Logs
  • Analyzing Post-access activity
  • Eradication and Recovery of Azure Resources and M365 credentials
  • Post Incident Activity
  • Additional Resources

FAQ

Difficulty

Beginner to Intermediate

Prerequisites

The workshop will cover some of the key points of Azure & M365 but a working knowledge of core Azure concepts will be helpful.

About the Instructor

Pixel splash background
"Digital Forensics and Incident Responder"
Bio

A cyber security professional with over a decade of experience specializing in digital forensics, incident response, and threat intelligence. After a decade in law enforcement, transitioned into the private sector working in large enterprise and consulting. During my tenure in cyber security, I have been fortunate enough to work on complex digital investigations as well as develop training and enablement programs for cyber security defenders all over the world.

Register for Upcoming

Workshop: Azure Incident Response

Live Training Gerard Johansen

  • Certificate of participation
  • Six months access to class recordings
  • Our appreciation

$25
November 6, 2026 12:00 pm - 4:00 pm ET
Shopping Cart

No products in the cart.