Cloud SOC and lateral movement
The breach moves from an endpoint to the cloud control plane, which is where most modern incidents actually become serious. Work the CloudTrail evidence and follow the identity rather than the host.
- When
- Sat 14 Nov 2026 · 10:30–13:30 IST
- Where
- Bangalore or virtual
- Cohort size
- 25 in person · 40 including virtual
Sessions can be booked individually, or take the full six-session cohort.
What you leave able to do
- Investigate lateral movement through cloud identity rather than network
- Read CloudTrail evidence for role assumption and privilege escalation
- Recognise a cloud takeover in progress
Run of play
- 1
Following the identity
Why host-centric investigation loses the trail in cloud.
- 2
Escalation
Role assumption, and the moment the blast radius widens.
The case
Where this sits in the story
All six Saturdays run on one continuous breach, so every session picks up where the last one left off.
Silent Phantom reaches the domain controller. Sysmon shows secretsdump activity within four minutes of the lateral move from WKS12 — if they pulled NTDS.dit, every password hash at NoowaPay is compromised. Meanwhile an Entra ID alert fires: a sign-in from Lagos eleven minutes after one from London, on a Global Administrator account.
Who this session suits
Analysts moving to enterprise SIEM work. This is the Microsoft Sentinel and query-language session, and the one that maps most directly to SOC job descriptions.
Scope
What this session covers
- KQL from first principles: pipe, where, project, summarize, let
- Navigating a Sentinel workspace under alert pressure
- Impossible travel, legacy-auth password spray and MFA bypass
- Service account token abuse and the full identity attack chain
- Kerberoasting, secretsdump and DCSync as one credential-theft chain
- Why NTLM hashes enable Pass-the-Hash without cracking anything
- DNS TXT tunnelling and malicious OAuth consent grants
- Splunk SPL: stats, rex, timechart, eval and subsearch
Hands-on
The labs you work
6 hands-on labs, 350 minutes of lab time. Each runs in a cloud terminal against real evidence — logs, PCAPs, event data — and is graded on what you find, not on a multiple-choice answer. Lab access continues for 3 months, so the work does not stop when the session ends.
- 1KQL for Security Analysis and SOC Threat Huntingsoc-sentinel-ready55 min
- 2Microsoft Sentinel Workspace Navigationsoc-sentinel-ready50 min
- 3Entra ID Identity Threat Investigationsoc-sentinel-ready65 min
- 4Active Directory Credential Attack Forensicssoc-sentinel-ready65 min
- 5DNS Tunneling and OAuth Token Abuse Investigationsoc-sentinel-ready60 min
- 6Splunk SPL for Security Analysis and Advanced Threat Detectionsoc-sentinel-ready55 min
Tools used
- Microsoft Sentinel
- KQL
- Splunk SPL
- Entra ID sign-in logs
- Sysmon
MITRE ATT&CK coverage (23)
- T1003.001 OS Credential Dumping: LSASS Memory
- T1003.002 OS Credential Dumping: Security Account Manager
- T1005 Data from Local System
- T1046 Network Service Discovery
- T1048.003 Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1069.003 Permission Groups Discovery: Cloud Groups
- T1071.004 Application Layer Protocol: DNS
- T1078 Valid Accounts
- T1078.002 Valid Accounts: Domain Accounts
- T1078.004 Valid Accounts: Cloud Accounts
- T1087.004 Account Discovery: Cloud Account
- T1110.003 Brute Force: Password Spraying
- T1114.002 Email Collection: Remote Email Collection
- T1134 Access Token Manipulation
- T1190 Exploit Public-Facing Application
- T1207 Rogue Domain Controller
- T1528 Steal Application Access Token
- T1530 Data from Cloud Storage
- T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting
- T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
- T1572 Protocol Tunneling
Schedule
The full cohort
One continuous case across six Saturdays. Sessions build on each other, and each one can also be booked on its own.
- Sat 17 Oct 2026Foundations and the first alert10:30–13:30 ISTDetails →
- Sat 24 Oct 2026AI-era phishing and the initial foothold10:30–13:30 ISTDetails →
- Sat 31 Oct 2026Endpoint investigation and containment10:30–13:30 ISTDetails →
- Sat 7 Nov 2026Diwali holiday — no sessionNo session
- Sat 14 Nov 2026Cloud SOC and lateral movement10:30–13:30 ISTYou are here
- Sat 21 Nov 2026Detection engineering and automation10:30–13:30 ISTDetails →
- Sat 28 Nov 2026Immersive day and certification exam10:30–17:30 IST · full dayDetails →
Taking the whole cohort?
The six sessions are one continuous case, and the full course page carries the curriculum, the certification detail and the cohort pricing.

