Opleidingen
56.827
resultaten
Masterclass: Linux Security and Hardening (Advanced) [LXA]
CQure Virtual English
do 12 nov. 2026
OVERVIEW
This is a 2-day deep dive course on infrastructure services security, a must-go for enterprise administrators, security officers and architects.
This advanced course expands on the concepts introduced in Linux Security and Hardening Basics and can be taken either as a follow-on to the foundational three-day program or as a standalone course. It focuses on advanced techniques for securing and hardening Linux systems through access control, isolation, and proactive threat detection.
It is delivered by one of the best people in the market in the security field and what is more, this is an international Live Virtual Class so you will be able to share the learning experience with a group of IT pros from around the world without leaving your home or office!
Virtual Learning
This interactive training can be taken from any location, your office or home and is delivered by a trainer. This training does not have any delegates in the class with the instructor, since all delegates are virtually connected. Virtual delegates do not travel to this course, Global Knowledge will send you all the information needed before the start of the course and you can test the logins.
OBJECTIVES
Implement advanced Linux security and hardening techniques.
Configure access control using ACLs, SELinux, and AppArmor.
Apply kernel hardening and process isolation methods.
Mitigate privilege escalation risks in Linux systems.
Strengthen systems through proactive threat detection.
AUDIENCE
The course is perfect for enterprise administrators, infrastructure architects, security professionals, systems engineers, network administrators, IT professionals, security consultants and other people responsible for implementing network and perimeter security.
CERTIFICATION
After completing the course, participants will receive a CQURE Certificate of Completion and will also be eligible for CPE points.
CONTENT
Module 1: Mastering Discretionary Access Control (DAC)
Module 2: Access Control Lists and Shared Directory Management
Module 3: Implementing Mandatory Access Control with SELinux and AppArmor
Module 4: Kernel Hardening and Process Isolation
Module 5: Scanning, Auditing, and Hardening
Module 6: Logging and Log Security
Module 7: Vulnerability Scanning and Intrusion Detection
Module 8: Prevent Unwanted Programs from Running
€2.275
Klassikaal
max 16
Masterclass: Linux Security and Hardening (Basics) [LXB]
CQure Virtual English
ma 9 nov. 2026
OVERVIEW
This course provides a comprehensive introduction to Linux security and system hardening practices. Participants will learn to strengthen Linux environments through secure configuration, user privilege management, and robust authentication policies.
Virtual Learning
This interactive training can be taken from any location, your office or home and is delivered by a trainer. This training does not have any delegates in the class with the instructor, since all delegates are virtually connected. Virtual delegates do not travel to this course, Global Knowledge will send you all the information needed before the start of the course and you can test the logins.
OBJECTIVES
Configure and manage Linux systems in virtual environments.
Secure administrative and standard user accounts.
Implement firewall security for Linux servers.
Apply encryption technologies to protect systems and data.
Perform SSH auditing and hardening to improve system security.
AUDIENCE
The course is perfect for enterprise administrators, infrastructure architects, security professionals, systems engineers, network administrators, IT professionals, security consultants and other people responsible for implementing network and perimeter security.
CERTIFICATION
After completing the course, participants will receive a CQURE Certificate of Completion and will also be eligible for CPE points.
CONTENT
Module 1: Running Linux in a Virtual Environment
Module 2: Securing Administrative User Accounts
Module 3: Securing Normal User Accounts
Module 4: Securing Your Server with a Firewall
Module 5: Encryption Technologies
Module 6: SSH Audit and Hardening
€2.575
Klassikaal
max 16
Masterclass: Malware Analysis & Reverse Engineering [MAR]
CQure Virtual English
ma 21 sep. 2026
en 1 andere data
OVERVIEW
This advanced, hands-on training is designed for cybersecurity professionals focused on incident response, malware analysis, and threat hunting. Participants will gain a deep understanding of how advanced threats operate, how malware behaves, and how to analyze and respond to real-world attacks using modern tools and techniques. This course is based on practical knowledge from tons of successful projects, many years of real-world experience and no mercy for misconfigurations or insecure solutions All exercises are based on Windows Server, Windows 10, Kali Linux, and Ubuntu.
After finishing the course, you will be granted a CQURE Certificate of Completion. Please note that after completing the course you will also be eligible for CPE points!
OBJECTIVES
Understand the lifecycle and tactics of Advanced Persistent Threats (APTs)
Identify common attack vectors and malware delivery techniques
Extract useful information using basic static analysis tools
Leverage sandboxing tools to detect malicious activity
Understand attack chains
Understand fundamental assembly language concept
Identify core malware capabilities
Analyze encryption routines and key management
AUDIENCE
This course is designed for cybersecurity professionals who want to sharpen their skills in analyzing and defending against advanced threats. Whether you are a malware analyst, incident responder, threat hunter, SOC analyst, forensic specialist, security engineer, or red teamer
CERTIFICATION
After finishing the course, you will be granted a CQURE Certificate of Completion. Please note that after completing the course you will also be eligible for CPE points!
CONTENT
Module 1: APT Attacks & Malware Analysis
Module 2: Basic Static Analysis
Module 3: Behavioral Analysis & Sandboxing
Module 4: Spear-phishing Attacks with Malicious Documents
Module 5: Intro to x86/x64 Assembly
Module 6: Static & Dynamic Code Analysis
Module 7: Malware Functionalities Analysis
Module 8: Unpacking Packed Samples
Module 9: Dealing with Encryption
Module 10: Ransomware Analysis
Module 11: Windows Forensics & Timeline Analysis
Module 12: Advanced Techniques: Fileless Malware & API Hooking
Module 13: Memory Forensics & Volatility
Module 14: Reporting & Threat Hunting
€3.500
Klassikaal
max 16
Administer Windows Server [M-AZ802]
VIRTUAL TRAINING CENTRE
ma 12 okt. 2026
en 9 andere data
OVERVIEW
AZ-802 equips IT professionals with the skills to deploy, manage, secure, monitor, and troubleshoot Windows Server environments across on-premises, cloud, and hybrid infrastructures.
The course covers Active Directory Domain Services (AD DS), networking, storage, virtualization, security, high availability, disaster recovery, workload migration, and hybrid management using Microsoft Azure and Windows Server administration tools. It is designed for administrators responsible for maintaining modern Windows Server environments and supporting business-critical workloads in hybrid IT environments.
Updated August 2026
OBJECTIVES
After this course participants should be able to:
Deploy and manage Active Directory Domain Services (AD DS).
Manage Windows Server instances and workloads in hybrid environments.
Deploy, configure, and administer virtual machines.
Implement and manage on-premises and hybrid networking infrastructure.
Manage storage and file services in Windows Server.
Secure, monitor, and troubleshoot Windows Server environments.
AUDIENCE
This course is intended for Windows Server administrators who deploy, implement, manage, and troubleshoot Windows Server as a workload in on-premises, cloud, or hybrid environments. Candidates administer identity, security, compute, networking, storage, and monitoring for Windows Server, and they typically collaborate with architects, administrators, and engineers. Candidates should have experience administering Windows Server using technologies such as Windows Admin Center, Hyper-V, PowerShell, Azure Arc, Azure Monitor, Azure Update Manager, and Microsoft Defender for Cloud, and should be familiar with Active Directory Domain Services (AD DS).
CERTIFICATION
None
NEXT STEP
The following courses are recommended for further learning and development:
CONTENT
Module 1: Deploy and manage Active Directory Domain Services
Deploy and manage Active Directory Domain Services domain controllers
Deploy and manage Azure IaaS Active Directory domain controllers in Azure
Manage AD DS domain controllers and FSMO roles
Create and manage Active Directory objects
Implement hybrid identity with Windows Server
Create and configure Group Policy Objects in Active Directory
Implement Group Policy Objects
Manage advanced features of AD DS
Module 2: Manage Windows Server instances and workloads in a hybrid environment
Administer and manage Windows Server IaaS Virtual Machine remotely
Describe Windows Server administration tools
Just Enough Administration in Windows Server
Perform Windows Server secure administration
Use advanced Windows PowerShell remoting techniques
Manage single and multiple computers by using Windows PowerShell remoting
Manage hybrid workloads with Azure Arc
Manage Azure updates
Automate the configuration of Windows Server IaaS Virtual Machines
Enforce VM security configuration with Azure Machine Configuration
Explore Azure Automation with DevOps
Module 3: Manage virtual machines
Configure and manage Hyper-V virtual machines
Configure and manage Hyper-V
Secure Hyper-V workloads
Implement high availability of Windows Server VMs
Plan and deploy Windows Server IaaS Virtual Machines
Implement scale and high availability with Windows Server VM
Implement Windows Server IaaS VM IP addressing and routing
Implement Windows Server IaaS VM network security
Administer and manage Windows Server IaaS Virtual Machine remotely
Module 4: Implement and manage an on-premises and hybrid networking infrastructure
Implement Windows Server DNS
Implement DNS for Windows Server IaaS VMs
Secure Windows Server DNS
Deploy and manage DHCP
Implement IP Address Management
Implement Windows Server IaaS VM IP addressing and routing
Module 5: Manage storage and file services
Implement a hybrid file server infrastructure
Manage Windows Server file servers
Implement Storage Spaces and Storage Spaces Direct
Implement Windows Server Data Deduplication
Implement Windows Server iSCSI
Implement Windows Server Storage Replica
€2.595
Klassikaal
max 16
Masterclass: M365 Security & M365 Copilot [MCO]
CQure Virtual English
wo 28 okt. 2026
en 1 andere data
OVERVIEW
This intensive training equips IT professionals with the skills to secure and harden their Microsoft 365 tenant using proven best practices. Participants learn how to implement a holistic Zero Trust security model, configure identity and access management, and protect users across cloud and mobile environments. The course delivers practical guidance to safeguard sensitive data while enabling secure collaboration and productivity.
We’ll dive deeper into securing Microsoft 365 through robust administrative controls, data protection, and governance. Attendees gain hands-on insight into Microsoft Defender, Purview, secure guest access, and compliance strategies aligned with GDPR. The course empowers IT professionals to confidently protect complex cloud and hybrid environments at scale.
We’ll introduce Copilot and Agents in Microsoft 365 securely, strategically, and with maximum business impact. Participants explore real-world use cases, technical architecture, governance models, and security frameworks required for a compliant AI rollout. The course ensures IT leaders can unlock AI-driven productivity while maintaining control, privacy, and trust. All exercises are based on M365 environment. This course is based on practical knowledge from tons of successful projects, many years of real-world experience and no mercy for misconfigurations or insecure solutions
Virtual Learning
This interactive training can be taken from any location, your office or home and is delivered by a trainer. This training does not have any delegates in the class with the instructor, since all delegates are virtually connected. Virtual delegates do not travel to this course, Global Knowledge will send you all the information needed before the start of the course and you can test the logins.
OBJECTIVES
Understand the core security architecture of Microsoft 365
Identify key security services and their roles
Implement advanced threat protection capabilities
Configure and optimize security policies for organizational needs
Understand security and compliance requirements when deploying Copilot and AI agents
Manage data protection, privacy, and access controls for AI-powered features
AUDIENCE
The course is best suited for IT administrators, security engineers, and Microsoft 365 architects responsible for securing and managing cloud or hybrid environments. It is also ideal for IT managers, CISOs, and technical decision-makers who need to establish governance, compliance, and a secure foundation for advanced capabilities such as Copilot and Agents.
CERTIFICATION
After finishing the course, you will be granted a CQURE Certificate of Completion. Please note that after completing the course you will also be eligible for CPE points!
CONTENT
Module 1: Security in Microsoft 365
Hybrid deployment of Entra ID and on premises Active Directory
Active Directory synchronization
Authentication methods and options
Implementing and using Single Sign On
Applying the Zero Trust security model
Secure mobile authentication
Integrating external guests
Managing Microsoft 365 groups
Enabling multi factor authentication
Creating and managing Conditional Access policies
Integrating applications with Entra ID
Enrolling mobile devices and clients in Intune using Microsoft Managed Apps
Module 2: Advanced Security in Microsoft 365
Secure configuration of the Microsoft 365 admin and Entra ID portals
Security concepts for Named Admins
Setting up break glass accounts
Managing external guests in Microsoft Teams
Governance and security
Policies for data sharing and guest permission
Deploying and configuring the Microsoft Defender suite
Defender for Endpoint
Defender for Microsoft 365
Defender for Servers
Working with the Microsoft Purview portal
Data protection and security in accordance with GDPR
Best practices for integrating mobile devices
Microsoft Intune and the Zero Trust approach
Defining compliance and configuration policies
Module 3: Securely Introducing Copilot and Agents in Microsoft 365
Inspiring introduction to Copilot and Agents for Microsoft 365
Optimizing workflows to fully leverage AI
Identifying high impact use cases for your organization
Empowering employees and preparing your helpdesk
Comprehensive technical overview of Copilot and Agents
In depth review of the underlying architecture
Real-world benefits and opportunities with Copilot and Agents for Microsoft 365
Ensuring compliance: data protection & security
Security frameworks, privacy policies, and regulatory fundamentals
Defining roles, personas, and governance models
Govern Copilot and Agents in Microsoft 365
€2.575
Klassikaal
max 16
E-learning CDD-professional (English)
Learn how to safeguard the integrity of the financial sector with the CDD Professional E-learning course. We would be happy to tell you more about it, so read on!
In this e-learning course, you will become familiar with the fundamental principles of CDD, with a primary focus on conducting customer due diligence, identifying risk areas, and implementing anti-money laundering measures.
€399
E-Learning
10 uren
Masterclass: PowerShell for Digital Investigation & Threat Hunting [PST]
CQure Virtual English
di 13 okt. 2026
en 1 andere data
OVERVIEW
This advanced course equips cybersecurity professionals with the skills to detect, investigate, and respond to modern threats using native Windows tools and PowerShell. With a strong focus on real-world attacker behaviors, participants will learn to identify Advanced Persistent Threats (APTs), analyze attack timelines, and uncover hidden or deleted artifacts using forensic techniques.
PowerShell is used throughout the course as both a defensive and investigative tool, supporting artifact collection, process and network analysis, registry inspection, and script-based detection. Participants will explore common attacker techniques such as living-off-the-land binaries (LOLBins), scheduled tasks, and encoded payloads, and learn how to detect and counter them through logging, event analysis, and behavioral detection rules.
Virtual Learning
This interactive training can be taken from any location, your office or home and is delivered by a trainer. This training does not have any delegates in the class with the instructor, since all delegates are virtually connected. Virtual delegates do not travel to this course, Global Knowledge will send you all the information needed before the start of the course and you can test the logins.
OBJECTIVES
Investigate advanced persistent threats (APTs) using PowerShell and native Windows tools.
Perform digital forensics and artifact collection for incident investigations.
Analyze process, network, and registry artifacts to identify malicious activity.
Implement PowerShell logging, detection, and threat hunting techniques.
Conduct Active Directory enumeration and investigate fileless attacks.
Apply real-world threat hunting and incident response techniques through hands-on exercises.
AUDIENCE
This course is designed for security professionals across offensive, defensive, and hybrid roles. Analysts, hunters, SOC teams, and incident responders will learn to enhance investigations with AI-driven workflows. Red and purple teamers will strengthen adversary emulation and detection validation, while engineers and developers gain hands-on experience building AI-powered tools, pipelines, and multi-agent systems. Security leaders and architects will benefit from practical insights into securing AI systems and addressing emerging vulnerabilities.
CERTIFICATION
After completing the course, participants will receive a CQURE Certificate of Completion and will also be eligible for CPE points.
CONTENT
Module 1: APT Attacks & Investigation
Module 2: PowerShell 101 for Blue Teams
Module 3: Understanding Information Gathering and Timelining
Module 4: PowerShell for Digital Forensics & Artifact Collection
Module 5: Process & Network Artifact Collection
Module 6: PowerShell Logging & Detection
Module 7: Threat Hunting with WMI & Scheduled Tasks
Module 8: PowerShell for Enterprise
Module 9: Hands-On Threat Hunting Case Study
Module 10: Active Directory Enumeration with PowerShell
Module 11: Red Teaming Tactics with PowerShell
Module 12: Complete Fileless Attack Analysis Walkthrough
€3.000
Klassikaal
max 16
Masterclass: Red Team Tradecraft and Operations [RTO]
CQure Virtual English
ma 16 nov. 2026
en 1 andere data
OVERVIEW
Red Team Tradecraft and Operations is an intensive 3-day, 21-hour course focused on the professional execution and management of Red Team engagements. Unlike traditional penetration testing courses that focus primarily on how to hack, this course focuses on how to operate, covering strategic planning, infrastructure execution, operational security, collaboration, and reporting throughout the full lifecycle of a Red Team engagement.
Participants will learn how to build and maintain resilient, secure, and automated Red Team infrastructure, define Rules of Engagement, select and configure Command & Control (C2) frameworks, apply operational security (OPSEC), translate threat intelligence into adversary emulation plans, coordinate multi-operator engagements, and produce high-value reports that communicate technical findings in terms of business impact.
Updated Auguts 2026
Virtueel en Klassikaal™
Virtueel en Klassikaal™ is een eenvoudig leerconcept en biedt een flexibele oplossing voor het volgen van een klassikale training. Met Virtueel en Klassikaal™ kunt u zelf beslissen of u een klassikale training virtueel (vanuit huis of kantoor )of fysiek op locatie wilt volgen. De keuze is aan u! Cursisten die virtueel deelnemen aan de training ontvangen voor aanvang van de training alle benodigde informatie om de training te kunnen volgen.
OBJECTIVES
By the end of the course, participants will be able to:
Manage the end-to-end lifecycle of a Red Team operation, including scoping, deconfliction, and legal boundaries.
Define effective Rules of Engagement (RoE) and identify critical assets or “Crown Jewels.”
Translate Cyber Threat Intelligence (CTI) into actionable adversary emulation and simulation plans using MITRE ATT&CK.
Design resilient, tiered Red Team infrastructure, including Team Servers, Redirectors, and Payload Servers.
Deploy disposable Red Team infrastructure using Infrastructure as Code (IaC) and automation.
Configure and manage Command & Control (C2) infrastructure and profiles.
Configure redirectors and use techniques to mask the origin of attacks and blend traffic into normal organizational network traffic.
Implement effective OPSEC workflows and secure team communication.
Maintain accurate logging to support reconstruction of operational events.
Coordinate multi-operator Red Team engagements.
Translate technical findings into business-impact narratives and executive-level reporting.
AUDIENCE
This course is designed for:
- Red Team Leads
- Senior Penetration Testers transitioning to Red Teaming
- Adversary Emulation Specialists
- C2 Infrastructure Engineers
- Security Managers overseeing offensive operations
- Penetration Testers
- Security Analysts
- IT Administrators
- Cybersecurity Professionals
- IT professionals with a technical background who want to develop their skills in cybersecurity penetration testing
CERTIFICATION
Participants receive a CQURE lifelong certification upon successful completion of the course.
NEXT STEP
None
CONTENT
The Red Team Tradecraft and Operations (RTO) program consists of 18 expert-level modules delivered over 3 intensive days, combining strategic planning, infrastructure engineering, operational tradecraft, and reporting methodologies.
This training focuses on the professional execution of Red Team engagements. Students will learn how to design resilient command-and-control infrastructure, manage operational security, translate threat intelligence into adversary emulation plans, coordinate multi-operator engagements, and deliver executive-level reporting that demonstrates real business impact.
Day 1: Engagement Strategy & Infrastructure Engineering
Module 1: The Red Team Framework: Red Teaming vs. Penetration Testing. Defining “Objectives Based” vs. “Scope Based” assessments.
Module 2: Scoping, RoE & Legal: The art of the kick-off meeting. Defining Rules of Engagement (RoE), “Crown Jewels” identification, White Cards, and legal protections.
Module 3: Threat Intelligence (CTI) & Emulation: Translating CTI reports into actionable Adversary Emulation/Simulation Plans using MITRE ATT&CK.
Module 4: Infrastructure Architecture: Designing the Tiered Infrastructure Model (Team Servers, Redirectors, Payload Servers) for non-attribution.
Module 5: Automation (DevSecOps): Hands-on automated deployment of disposable infrastructure. Automating SMTP relays, phishing servers, C2 nodes etc..
Module 6: Traffic Management: Configuring Redirectors (Nginx/Socat) and utilizing CDNs/Domain Fronting to mask the origin of attacks. Using ExternalC2 to blend into the common organization network traffic.
Day 2: Comand, Control & Operational Tradecraft
Module 7: C2 Framework Selection: Comparative analysis of modern frameworks and selection strategy based on operation goals.
Module 8: Traffic Engineering: Customizing traffic signatures (Malleable C2/Profiles) to blend with legitimate network traffic (jitter, sleep, user-agent spoofing). Using application-related external C2 channels.
Module 9: Communication Channels: Deep dive into HTTP/S, DNS, and SMB piping. Understanding “Beaconing” heuristics and detection logic.
Module 10: Team Collaboration: Managing shared sessions, operator logs, and deconfliction servers to avoid “Red-on-Red” issues.
Module 11: Initial Access Strategy: Planning the delivery vector (Physical vs. Phishing vs. Assumed Breach). Tracking payload execution rates and landing success.
Module 12: OPSEC & “Silence”: Managing “Time on Target” and noise levels. Decision-making matrices for when to use active scanning vs. passive enumeration.
Day 3: Execution Management, Analysis & Reporting
Module 13: Persistence Strategy: Long-term access management. Differentiating between “Interactive Access” (high noise) and “Sleepy Agents” (low noise).
Module 14: The “Assume Breach” Execution: Methodologies for internal-only engagements and lateral movement discipline (avoiding event log spikes).
Module 15: Logging & Reconstruction: Aggregating operator logs (ELK/Splunk). Correlating Red Team actions with Blue Team alerts for the debrief.
Module 16: The Red Team Report: Structuring the strategic report. Writing Executive Summaries, visualizing Attack Graphs, and defining Business Impact.
Module 17: Purple Teaming & Remediation: Transitioning from attack to defense. Delivering constructive feedback and verifying fixes.
Module 18: Capstone Workshop: Students design a complete Operation Plan for a fictional client, including Infrastructure design, CTI selection, RoE drafting, and Reporting structure.
€2.575
Klassikaal
max 16
Masterclass: Securing the Cloud [SEC]
CQure Virtual English
ma 12 okt. 2026
en 1 andere data
OVERVIEW
Securing the Cloud is an advanced 5-day, 35-hour course focused on securing Microsoft cloud and hybrid environments. Participants will develop the skills required to monitor, protect, and govern identities, resources, and workloads across Microsoft Entra ID, Azure, and Microsoft 365.
The course combines security best practices from both blue team and red team perspectives with hands-on labs and real-world scenarios. Participants will gain practical experience in threat detection, log analysis, incident response, identity and access management, cloud security, and governance using Microsoft’s cloud security stack, including Defender, Sentinel, and Cloud App Security.
Updated August 2026
OBJECTIVES
By the end of the course, participants will be able to:
Monitor, protect, and govern identities, resources, and workloads across Microsoft Entra ID, Azure, and Microsoft 365.
Detect threats, analyze logs, and respond to security incidents using Microsoft cloud security tools.
Apply security best practices to strengthen identity and access controls.
Secure cloud resources and implement governance at scale.
Investigate security incidents and improve the security posture of cloud and hybrid environments.
Apply both blue team and red team approaches to cloud security.
AUDIENCE
- Security architects, Entra ID administrators, security administrators, and security auditors
- Enterprise administrators, infrastructure architects, security professionals, systems engineers, network administrators, IT professionals, and security consultants
CERTIFICATION
Participants receive a CQURE lifelong certification upon completion of the course.
NEXT STEP
None
CONTENT
This Live Virtual Class consists of 6 Modules in terms of Securing the Cloud. They include essential theory combined with individual practice during the exercises as well as loads of hands-on tools and real-case scenarios.
Module 1: Monitoring Operations in Entra ID
1. Entra ID Operations and Logs
2. Entra ID Roles
3. Identity Protection – Roles, Review access, alerts, Discovery and Insights
4. How to deal with Audit Log
5. Challenging Entra ID settings in Azure and Office from red team perspective
6. Privileged Identity Management – JITA, Discover and Monitor
7. Office Management API – Logs around Office 365
8. Microsoft Azure Policies – getting started, compliance, remediation, assignments, blueprints
9. Labs
Module 2: Microsoft 365 Security
1. Secure Score and Security Center
2. Best Practices for Improving Your
3. Secure Score
4. Azure Defender for Servers
5. Security Benchmark Policy
6. Labs
7. STIG & CIS – cloud security baseline
Module 3: Secure Resources and Identities in Azure
1. Secure identity and access (PIM, Identity Protection)
2. Secure Networking (NSG, Azure Firewall, APIM)
3. Secure Compute
4. Secure Storage
5. Secure Databases
6. Defender for Cloud
7. Labs
Module 4: Governance in Azure
1. Security Baseline
2. Azure Policy
3. Azure Role-Based Access Control (RBAC)
4. Management Groups
5. Resource Graph
6. Tagging in Azure
7. Labs
Module 5: Extended Detection and Response with Sentinel
1. Sentinel 101 – Azure Sentinel Dashboards, Connectors
2. Understanding Normalization in Azure Sentinel
3. Cloud & on-prem architecture
4. Workbooks deep dive – Visualize your security threats and hunts
5. Incidents
6. KQL intro (KQL hands-on lab exercises) and Optimizing Azure Sentinel KQL queries performance
7. Auditing and monitoring your Azure Sentinel workspace
8. Sentinel configuration with Microsoft Cloud stack and MCAS
9. Streamlining your SOC Workflow with Automated Notebooks
10. Customizing Azure Sentinel with Python
11. Best Practices for Converting Detection Rules from Splunk, QRadar, and ArcSight to Azure Sentinel Rules
12. Deep Dive into Azure Sentinel Innovations
13. Investigating Azure Security Center alerts using Azure Sentinel
14. Customizable Anomalies and How to Use Them
15. Introduction to Monitoring GitHub with Azure Sentinel for Security Professionals
16. Hunting in Sentinel
17. Deep Dive on Threat Intelligence
18. End-to-End SOC scenario with Sentinel
Module 6: Microsoft Cloud App Security
1. Intro do MCAS
2. Enabling Secure Remote Work
3. App Discovery and Log Collector Configuration
4. Extending real-time monitoring & controls to any app
5. Connecting 3rd party Applications
6. Automation and integration with Microsoft Flow
7. Conditional Access App Control
8. Threat detection
9. Information Protection
10. Labs: Protect Your Environment Using MCAS
11. DLP in Microsoft stack – how to deploy and monitor using MCAS and Sentinel
€3.500
Klassikaal
max 16
Masterclass: Threat Hunting with AI [TAI]
CQure Virtual English
wo 16 sep. 2026
en 2 andere data
OVERVIEW
Our Threat Hunting with AI Support course is designed for Security Analysts, IT Administrators, Incident Responders and Threat Hunters. During the course participants will learn modern attack techniques, local privilege escalation methods, and identity infrastructure attacks, as well as ways these attacks can be detected and mitigated. This knowledge is enhanced with case studies demonstrating how real-world attacks occur using the methods learned. Additionally, participants will be introduced to solutions that, with AI support, can enhance the threat hunting process. The course concludes by showcasing how threat hunting and threat detection design can be performed using both manual and automated methods.
OBJECTIVES
Understand modern attack techniques and how they are executed and detected
Identify and investigate privilege escalation and identity-based attacks
Understand Windows authentication architecture and common exploitation paths
Apply structured investigation methods using real-world case studies
Use Microsoft Defender for Endpoint (EDR) for threat detection and hunting
Detect and analyze attacks on identity infrastructure
Perform basic network, memory, and disk forensic analysis
Leverage Microsoft Sentinel and Security Copilot in threat detection and investigation
Combine manual and AI-assisted methods to improve threat hunting and response
AUDIENCE
This course is designed for security professionals across offensive, defensive, and hybrid roles. Analysts, hunters, SOC teams, and incident responders will learn to enhance investigations with AI-driven workflows. Red and purple teamers will strengthen adversary emulation and detection validation, while engineers and developers gain hands-on experience building AI-powered tools, pipelines, and multi-agent systems. Security leaders and architects will benefit from practical insights into securing AI systems and addressing emerging vulnerabilities.
CERTIFICATION
After completing the course, participants will receive a CQURE Certificate of Completion and will also be eligible for CPE points.
CONTENT
Module 1: Modern Attack Techniques and Tracing Them
Module 2: Local Privilege Escalation Techniques and Tracing Them
Module 3: Case Study – Investigating In-Place Attacks
Module 4: Windows Authentication Architecture & Cryptography
Module 5: Case Study – Investigating Identity Theft
Module 6: Attacks on Identity Infrastructure and Tracing Them
Module 7: Microsoft 365 Defender for Endpoint (EDR)
Module 8: Security Operations with Microsoft EDR (Defender for Endpoint) – Advanced Threat Hunting with Defender
Module 9: Microsoft Security Copilot
Module 10: Case Study – Detecting a Complex Threat with Microsoft Sentinel and Microsoft Copilot for Security
Module 11: Network Forensics and Monitoring
Module 12: Memory Dumping and Analysis
Module 13: Disk Dumping and Analysis
€2.575
Klassikaal
max 16