
In this four-hour workshop, incident response professional Gerard Johansen will guide you through the key aspects of responding to incidents in the Azure public cloud and M365 solutions.
Course Length: 4 Hours
Includes a Certificate of Completion
Next scheduled date: November 6th, 2026 @ 12:00 PM ET
Description
In this four-hour workshop, incident response professional Gerard Johansen will guide you through the key aspects of responding to incidents in the Azure public cloud and M365 solutions.
Using a combination of analyzing common attacks and labs, students will walk through evidence acquisitor, processing and analysis using the SOF-ELK platform. From here, they will examine immediate actions to contain compromised credentials and isolated impacted systems. Further examination of post-compromise activity will also be covered, concluding with proper Eradication and Recovery. Rounding out the workshop will be a discussion on post-incident activity and additional resources.
Who Should Take This Workshop
- Security operations practitioners
- Cloud security engineers
- DFIR analysts
What You’ll Learn
- Understand the unique nature of cloud incidents
- Adequately prepare an Azure & M365 environment for immediate incident response
- Identify log sources and analyze common attacks
- Isolate and contain common identity-based attacks
- Extract additional evidence from Azure resources
- Eradication and recovery of Azure & M365 services
-
System Requirements
- Students will need to download and run the SANS SOF-ELK VM on their local system.
-
VM/Lab/Student Requirements
- Students should download the SANS SOF-ELK platform prior to the workshop. Sample evidence files will be provided prior to labs. https://github.com/philhagen/sof-elk/wiki/Virtual-Machine-README. Additionally, students should get a Maxmind account. From here, we will be using the GeoLite IP Location database
Syllabus
- The Azure & M365 Environment and the Shared Responsibility Model
- Preparation for Azure Incident Response
- A deep dive into Azure & M365 logging
- Adversary in the Middle / Business Email Compromise Attacks
- Extracting the Unified Audit Log
- Configuring the SOF-ELK log analysis platform
- Investigating AitM and BEC attacks
- Immediate Isolation and Containment actions
- Extracting the Azure Activity Logs
- Analyzing Post-access activity
- Eradication and Recovery of Azure Resources and M365 credentials
- Post Incident Activity
- Additional Resources
FAQ
Beginner to Intermediate
The workshop will cover some of the key points of Azure & M365 but a working knowledge of core Azure concepts will be helpful.
About the Instructor
Gerard Johansen
"Digital Forensics and Incident Responder"Bio
A cyber security professional with over a decade of experience specializing in digital forensics, incident response, and threat intelligence. After a decade in law enforcement, transitioned into the private sector working in large enterprise and consulting. During my tenure in cyber security, I have been fortunate enough to work on complex digital investigations as well as develop training and enablement programs for cyber security defenders all over the world.
Register for Upcoming
Workshop: Azure Incident Response
Live Training Gerard Johansen
- Certificate of participation
- Six months access to class recordings
- Our appreciation
Related products
-
Dale HobbsLive4 Hrs
Workshop: Intro to Active Directory
View Course This product has multiple variants. The options may be chosen on the product page -
Patterson CakeLive4 Hrs
Workshop: Investigating M365 Business Email Compromise
View Course This product has multiple variants. The options may be chosen on the product page -
BB KingLive4 Hrs
Workshop: Getting Comfortable in Burp Suite
View Course -
Chris TraynorLive4 Hrs
Workshop: Offensive Tooling Foundations
View Course

