Free Live Kickoff

    Write a Detection Rule and Fire It — Live in 60 Minutes

    Join Nahid Farady, PhD (Principal Tech Lead, AI Security & Privacy · Microsoft) for a free live session.

    📅 September 6, 2026⏰ 9:00 AM PDT⏱ 60 minutes🆓 Free to Join
    Nahid Farady, PhD

    Nahid Farady, PhD

    Principal Tech Lead, AI Security & Privacy · Microsoft

    ⭐ 4.9 / 5

    You have detection rules. They're not tuned for how attackers actually move.

    GuardDuty, Sentinel, Security Hub — configured yes, tuned no. In 6 weeks you'll write detection rules that catch IAM role chaining and S3 exfiltration, build a Zero Trust architecture, and ship an IR playbook tested against real attack patterns.

    6 WeeksLive instruction
    3 ProjectsReal deliverables
    30 SeatsPer cohort, capped

    What You'll Learn

    🗺️

    Cloud Attack Surface Map

    Map IAM privilege paths, exposed endpoints, and lateral movement vectors across AWS and Azure — a reusable starting point for every security review.

    🔍

    Detection Engineering in Microsoft Sentinel

    Write custom analytics rules for real attacker TTPs — IAM role chaining, S3 exfiltration, Lambda persistence — and ship a rule library your team deploys.

    🔒

    Zero Trust IAM Architecture

    Design a least-privilege IAM architecture across AWS and Azure with workload identity and a network segmentation plan that limits blast radius.

    📋

    Cloud Incident Response Playbook

    Build an IR playbook against CloudTrail, Azure Activity Logs, and VPC Flow Logs — containment procedures per attack type, tested against real scenarios.

    Who Is This For?

    This course is designed for:

    ☁️

    Cloud Engineers Running Misconfigured Security Tools

    Who have GuardDuty, Sentinel, or Security Hub turned on — but haven't tuned them and don't trust the alerts they're getting.

    🔧

    DevSecOps Engineers Plugging Security Into CI/CD

    Who own the pipeline and need detection and hardening to ship with the product, not bolt on after.

    🛡️

    Security Engineers Moving Into Cloud

    Who know traditional security well but haven't yet built the cloud-native detection and IR muscle their new role demands.

    Course Outline

    6 weeks · 3 sessions per week

    Projects You'll Ship

    Leave with real work to show, not just a certificate.

    01

    Cloud Attack Surface Map

    A comprehensive map of your cloud infrastructure's attack surface, identifying potential vulnerabilities and entry points. This artifact is crucial for ongoing security assessments and can be showcased in your professional portfolio.

    02

    Threat Detection Framework

    A robust framework employing tools like Splunk and Azure Sentinel to detect and analyze threats in real-time. This project demonstrates your ability to implement advanced threat detection systems and is ready for use in live environments.

    03

    Incident Response Playbook

    A detailed playbook outlining procedures for managing cloud security incidents. This reusable artifact is essential for any organization looking to improve their cloud incident response capabilities.

    Your Instructors

    Nahid Farady, PhD

    Nahid Farady, PhD

    Principal Tech Lead, AI Security & Privacy · Microsoft

    ⭐ 4.9 / 5

    Nahid leads AI security, privacy, and responsible AI engineering at Microsoft Copilot, with prior roles at Google Cloud and Capital One CyberML. She holds a PhD from Virginia Tech and brings 10+ years of applied experience in cybersecurity, threat modeling, and ML deployment at scale. She also teaches AI and security as adjunct faculty at UC Berkeley.

    What Students Say

    ⭐⭐⭐⭐⭐

    "The Sentinel detection rule library from Week 2 is now in production. It caught a real IAM role chaining attempt two weeks after the sprint ended."

    Alex Kim

    Alex Kim

    Cloud Security Engineer · Rippling

    ⭐⭐⭐⭐⭐

    "The Zero Trust IAM architecture from Week 3 cut our blast radius analysis from days to hours. We shipped it to staging before the sprint was over."

    Jamie Nguyen

    Jamie Nguyen

    DevSecOps Engineer · Figma

    ⭐⭐⭐⭐⭐

    "We ran the IR playbook in a real incident three weeks after the sprint. The CloudTrail forensics section alone saved us two hours of manual investigation."

    Morgan Lee

    Morgan Lee

    Security Engineer · Notion

    Course Schedule

    All sessions are instructor-led and live. Recordings available within 24 hours.

    SUNDAY

    9:00 AM PDT

    Live Class

    Dive deep into cloud security strategies and tools, with real-world case studies and interactive demos.

    WEDNESDAY

    6:00 PM PDT

    Lab Session

    Apply frameworks to your cloud setup, solve real-world challenges with peer and instructor support.

    THURSDAY

    6:00 PM PDT

    Build & Ship

    Hands-on project work, peer reviews, and feedback sessions to refine your weekly deliverables.

    Frequently Asked Questions

    Related reading

    The JD-backed research behind this course — from Dexity Intel.

    The Cybersecurity + AI Career Path in 2026

    How far do you want to go?

    Start free to experience our offering, choose the program length you would want to commit to.

    You build. Nobody demos at you.

    Every session is follow-along — you build the thing yourself while a practitioner works beside you. That is why the hours look long: they are yours to build in, with an expert on hand to guide you. None of it is a traditional lecture.

    One Saturday, 4 hours, live on Zoom with Nahid Farady
    This is Session 1 of the course — Week 1: Map your AWS and Azure attack surface before someone else does. The real session, not a taster
    Hands-on throughout: you ship your Cloud Attack Surface Map by the end, finished
    A comprehensive map of your cloud infrastructure's attack surface, identifying potential vulnerabilities and entry points.
    Recording, materials and the working file are yours to keep
    Continue to the full course and your $99 comes off — $1,400 for the rest

    In the session, you'll:

    Analyze IAM privilege paths, exposed endpoints, and misconfiguration risk using AWS Security Hub and Microsoft Defender for Cloud.
    Evaluate blast radius for each identified attack vector.
    Build a structured attack surface map your team can act on.

    No payment is taken here. We'll send the payment link by email and confirm by phone.