All Modules CLOUD SECURITY

Cloud Security · Complete Guide

Eight chapters covering cloud security from the shared responsibility model through applied detection engineering: Azure AD/Entra ID and AWS IAM attack techniques, the telemetry sources that actually catch them, cloud-native threat hunting methodology, detection queries in KQL/SPL/Sigma, real-world threat actor campaigns, and the Zero Trust/CIEM/CSPM controls that reduce how often any of this becomes an active incident. Built for SOC analysts and detection engineers extending coverage beyond the endpoint.

8 CHAPTERS
~11 HRS CONTENT
BEGINNER to ADVANCED SKILL RANGE
AUG 2026 LAST UPDATED
MODULE PROGRESS 0 / 8 chapters complete
shared responsibility Azure AD / Entra ID AWS IAM CloudTrail cloud threat hunting KQL / Sigma / SPL threat actor TTPs Zero Trust

ALL CHAPTERS

/
01
BEGINNER 25 min

Cloud Security Foundations

The shared responsibility model across IaaS/PaaS/SaaS, why the cloud attack surface has no fixed perimeter, and why identity becomes the control plane everything else depends on.

shared responsibility attack surface IAM basics
02
INTERMEDIATE 35 min

Azure AD & Entra ID Attacks

Password spray and legacy auth bypass, consent phishing and OAuth abuse, adversary-in-the-middle token theft, and conditional access bypass techniques.

password spray consent phishing token theft
03
INTERMEDIATE 35 min

AWS Enumeration & Attacks

IAM enumeration with a compromised key, S3 misconfiguration patterns, IAM privilege escalation paths, and the CloudTrail events that expose them.

IAM enumeration S3 misconfig privilege escalation
04
INTERMEDIATE 30 min

Cloud Telemetry & Data Sources

CloudTrail management vs. data events, Entra sign-in and audit logs, VPC/NSG flow logs and DNS logging, and building a minimum viable logging baseline.

CloudTrail Entra logs flow logs
05
INTERMEDIATE 35 min

Cloud-Native Threat Hunting

Adapting ABLE hypothesis generation to identity, control-plane, and network layers, and pivoting on identity when the infrastructure itself is ephemeral.

hypothesis generation identity pivoting ephemeral infra
06
INTERMEDIATE 40 min

Detection Queries

KQL against Entra sign-in and audit logs, Sigma rules for CloudTrail, SPL for Splunk-ingested CloudTrail, and tuning cloud detections against automation noise.

KQL Sigma SPL
07
ADVANCED 35 min

Cloud Threat Actor Campaigns

Scattered Spider's help-desk social engineering, Nobelium's federated trust abuse, and how ransomware operators target cloud backups for extortion leverage.

Scattered Spider Nobelium cloud ransomware
08
ADVANCED 40 min

Advanced Cloud Defense

Zero Trust as continuous verification, CIEM for right-sizing entitlements, CSPM for catching configuration drift, and the hardening baseline that ties the module together.

Zero Trust CIEM CSPM

PREREQUISITES & OUTCOMES

WHAT YOU SHOULD KNOW

  • Basic identity and access concepts: what a user, role, and permission grant are
  • No prior cloud platform experience required, Chapter 1 builds the shared responsibility model from scratch
  • General awareness of MITRE ATT&CK: what tactics and techniques are, how T-numbers work
  • Some exposure to KQL, SPL, or Sigma helps for Chapter 6 but is not required going in

WHAT YOU WILL KNOW AFTER

  • How the shared responsibility model shifts across IaaS/PaaS/SaaS and why identity is the real cloud perimeter
  • How Azure AD/Entra ID and AWS environments are actually attacked: password spray, consent phishing, token theft, IAM privilege escalation, S3 misconfiguration
  • Which cloud telemetry sources exist and which ones are silent by default until someone turns them on
  • How to build and pivot cloud-specific hunt hypotheses across identity, control-plane, and network layers
  • How to write and tune detections in KQL, SPL, and Sigma against real cloud attack patterns
  • How Zero Trust, CIEM, and CSPM fit together as the architectural layer that reduces incident frequency

RECOMMENDED TOOLS

H3AD-SEC tools that pair directly with this module's content.