<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cloud DFIR &#8211; Free &amp; Affordable DFIR, OSINT, &amp; Cybersecurity Training</title>
	<atom:link href="https://training.dfirdiva.com/listing-category/cloud-dfir/feed" rel="self" type="application/rss+xml" />
	<link>https://training.dfirdiva.com</link>
	<description>Free &#38; Affordable DFIR, OSINT, &#38; Cybersecurity Training</description>
	<lastBuildDate>Tue, 02 Sep 2025 00:30:16 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://training.dfirdiva.com/wp-content/uploads/2021/09/cropped-DFIRDivaLogoTwitterMultiBkg-32x32.png</url>
	<title>Cloud DFIR &#8211; Free &amp; Affordable DFIR, OSINT, &amp; Cybersecurity Training</title>
	<link>https://training.dfirdiva.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Cloud Labs (Invictus Incident Response)</title>
		<link>https://training.dfirdiva.com/listing/cloud-labs-invictus-incident-response</link>
		
		<dc:creator><![CDATA[DFIR Diva]]></dc:creator>
		<pubDate>Tue, 02 Sep 2025 00:30:13 +0000</pubDate>
				<guid isPermaLink="false">https://training.dfirdiva.com/?post_type=job_listing&#038;p=3122</guid>

					<description><![CDATA[<p><img width="1200" height="630" src="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png 1200w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-300x158.png 300w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-1024x538.png 1024w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-768x403.png 768w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-400x210.png 400w" sizes="(max-width: 1200px) 100vw, 1200px" /></p>Name &#38; Direct Link: Cloud Labs Platform: Invictus Incident Response Good for Beginners: There are easy labs available Cost: Free &#8211; $58.56/month Proof of Completion: The &#8220;All-In&#8221; subscription offers digital badges Description: Hands-on practice with cloud incident response. Microsoft  365, Azure, Sentinal, AWS and more.]]></description>
										<content:encoded><![CDATA[<p><img width="1200" height="630" src="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" srcset="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png 1200w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-300x158.png 300w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-1024x538.png 1024w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-768x403.png 768w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-400x210.png 400w" sizes="(max-width: 1200px) 100vw, 1200px" /></p><p><strong>Name &amp; Direct Link: <a href="https://cloudlabs.invictus-ir.com/">Cloud Labs</a></strong></p>
<p><strong>Platform</strong>: Invictus Incident Response</p>
<p><strong>Good for Beginners</strong>: There are easy labs available</p>
<p><strong>Cost</strong>: Free &#8211; $58.56/month</p>
<p><strong>Proof of Completion</strong>: The &#8220;All-In&#8221; subscription offers digital badges</p>
<p><strong>Description</strong>: Hands-on practice with cloud incident response. Microsoft  365, Azure, Sentinal, AWS and more.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Digital Forensics &#038; Incident Response in the Cloud Bootcamp (INE)</title>
		<link>https://training.dfirdiva.com/listing/digital-forensics-incident-response-in-the-cloud-bootcamp-ine</link>
		
		<dc:creator><![CDATA[DFIR Diva]]></dc:creator>
		<pubDate>Fri, 16 Aug 2024 02:53:43 +0000</pubDate>
				<guid isPermaLink="false">https://training.dfirdiva.com/?post_type=job_listing&#038;p=2899</guid>

					<description><![CDATA[<p><img width="1200" height="630" src="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" srcset="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png 1200w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-300x158.png 300w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-1024x538.png 1024w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-768x403.png 768w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-400x210.png 400w" sizes="(max-width: 1200px) 100vw, 1200px" /></p>Name &#38; Direct Link: Digital Forensics &#38; Incident Response in the Cloud Bootcamp Platform: INE Cost: This course is part of the INE Premium ($749/year) subscription* Topics: Digital Forensics &#38; Imaging Chain of Custody &#38; Authority Evidence Collection Memory Forensics Logs &#38; Network Analysis Cloud Infrastructure Cloud Incident Response Cloud Playbook Incident Response Lifecycle &#38;&#8230;]]></description>
										<content:encoded><![CDATA[<p><img width="1200" height="630" src="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png 1200w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-300x158.png 300w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-1024x538.png 1024w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-768x403.png 768w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-400x210.png 400w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p><p><strong>Name &amp; Direct Link: <a href="https://my.ine.com/CyberSecurity/courses/e25f7da6/digital-forensics-incident-response-in-the-cloud-bootcamp">Digital Forensics &amp; Incident Response in the Cloud Bootcamp</a></strong></p>
<p><strong>Platform</strong>: INE</p>
<p><strong>Cost:</strong> This course is part of the <a href="https://get.ine.com/plans-dfirdiva">INE Premium ($749/year) subscription*</a></p>
<p><strong>Topics</strong>:</p>
<ul>
<li>Digital Forensics &amp; Imaging</li>
<li>Chain of Custody &amp; Authority</li>
<li>Evidence Collection</li>
<li>Memory Forensics</li>
<li>Logs &amp; Network Analysis</li>
<li>Cloud Infrastructure</li>
<li>Cloud Incident Response</li>
<li>Cloud Playbook</li>
<li>Incident Response Lifecycle &amp; Roles</li>
<li>Threats &#8211; Hunting &amp; Intelligence</li>
</ul>
<hr />
<p>*DFIR Diva is a partner of INE and receives a small percentage of sales made through partner links that go toward keeping the site running.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Introduction to AWS Threat Detection (LinkedIn Learning)</title>
		<link>https://training.dfirdiva.com/listing/introduction-to-aws-threat-detection-linkedin-learning</link>
		
		<dc:creator><![CDATA[DFIR Diva]]></dc:creator>
		<pubDate>Sat, 18 May 2024 04:42:41 +0000</pubDate>
				<guid isPermaLink="false">https://training.dfirdiva.com/?post_type=job_listing&#038;p=2820</guid>

					<description><![CDATA[<p><img width="512" height="512" src="https://training.dfirdiva.com/wp-content/uploads/2024/04/DarkGray.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://training.dfirdiva.com/wp-content/uploads/2024/04/DarkGray.png 512w, https://training.dfirdiva.com/wp-content/uploads/2024/04/DarkGray-300x300.png 300w, https://training.dfirdiva.com/wp-content/uploads/2024/04/DarkGray-150x150.png 150w, https://training.dfirdiva.com/wp-content/uploads/2024/04/DarkGray-200x200.png 200w, https://training.dfirdiva.com/wp-content/uploads/2024/04/DarkGray-400x400.png 400w, https://training.dfirdiva.com/wp-content/uploads/2024/04/DarkGray-100x100.png 100w" sizes="auto, (max-width: 512px) 100vw, 512px" /></p>Name &#38; Direct Link: Introduction to AWS Threat Detection Platform: LinkedIn Learning Instructor: Day Johnson Cost: $34.99 Topics: MITRE Cloud Matrix Log Analysis in AWS CloudTrail Log Analysis Investigating Compute Threats Investigating IAM Threats Investigating Storage Threats Investigating Logging and Monitoring Threats Amazon GuardDuty]]></description>
										<content:encoded><![CDATA[<p><img width="512" height="512" src="https://training.dfirdiva.com/wp-content/uploads/2024/04/DarkGray.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://training.dfirdiva.com/wp-content/uploads/2024/04/DarkGray.png 512w, https://training.dfirdiva.com/wp-content/uploads/2024/04/DarkGray-300x300.png 300w, https://training.dfirdiva.com/wp-content/uploads/2024/04/DarkGray-150x150.png 150w, https://training.dfirdiva.com/wp-content/uploads/2024/04/DarkGray-200x200.png 200w, https://training.dfirdiva.com/wp-content/uploads/2024/04/DarkGray-400x400.png 400w, https://training.dfirdiva.com/wp-content/uploads/2024/04/DarkGray-100x100.png 100w" sizes="auto, (max-width: 512px) 100vw, 512px" /></p><p><strong>Name &amp; Direct Link: <a href="https://www.linkedin.com/learning/introduction-to-aws-threat-detection" data-wplink-edit="true">Introduction to AWS Threat Detection</a></strong></p>
<p><strong>Platform</strong>: LinkedIn Learning</p>
<p><strong>Instructor</strong>: Day Johnson</p>
<p><strong>Cost</strong>: $34.99</p>
<p><strong>Topics</strong>:</p>
<ul>
<li>MITRE Cloud Matrix</li>
<li>Log Analysis in AWS</li>
<li>CloudTrail Log Analysis</li>
<li>Investigating Compute Threats</li>
<li>Investigating IAM Threats</li>
<li>Investigating Storage Threats</li>
<li>Investigating Logging and Monitoring Threats</li>
<li>Amazon GuardDuty</li>
</ul>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AWS Incident Response Workshops</title>
		<link>https://training.dfirdiva.com/listing/aws-incident-response-workshops</link>
		
		<dc:creator><![CDATA[DFIR Diva]]></dc:creator>
		<pubDate>Wed, 15 May 2024 23:00:34 +0000</pubDate>
				<guid isPermaLink="false">https://training.dfirdiva.com/?post_type=job_listing&#038;p=2798</guid>

					<description><![CDATA[<p><img width="1200" height="630" src="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png 1200w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-300x158.png 300w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-1024x538.png 1024w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-768x403.png 768w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-400x210.png 400w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>Name &#38; Direct Link: AWS Incident Response Workshops Platform: AWS Cost: The workshops themselves are free but some of the AWS services used in the hands-on portion can result in charges. Workshops Include: Unauthorized IAM Credential Use Ransomware on S3 Cryptominer Based Security Events SSRF on IMDSv1 AWS CIRT Toolkit for Automating Incident Response Preparedness&#8230;]]></description>
										<content:encoded><![CDATA[<p><img width="1200" height="630" src="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png 1200w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-300x158.png 300w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-1024x538.png 1024w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-768x403.png 768w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-400x210.png 400w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p><p><strong>Name &amp; Direct Link</strong>: <a href="https://www.workshops.aws/categories/Incident%20Response"><strong>AWS Incident Response Workshops</strong></a></p>
<p><strong>Platform</strong>: AWS</p>
<p><strong>Cost</strong>: The workshops themselves are free but some of the AWS services used in the hands-on portion can result in charges.</p>
<p><strong>Workshops Include</strong>:</p>
<ul>
<li>Unauthorized IAM Credential Use</li>
<li>Ransomware on S3</li>
<li>Cryptominer Based Security Events</li>
<li>SSRF on IMDSv1</li>
<li>AWS CIRT Toolkit for Automating Incident Response Preparedness</li>
<li>Automating Incident Response Workshop</li>
<li>SIEM on Amazon OpenSearch Service Workshop</li>
<li>AWS Incident Response Playbooks Workshop</li>
<li>Building an AWS Incident Response Runbook Using Jupyter Notebooks and CloudTrail Lake</li>
</ul>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cloud Forensics Demystified (Ganesh Ramakrishnan &#038; Mansoor Haqanee)</title>
		<link>https://training.dfirdiva.com/listing/cloud-forensics-demystified-ganesh-ramakrishnan-mansoor-haqanee</link>
		
		<dc:creator><![CDATA[DFIR Diva]]></dc:creator>
		<pubDate>Wed, 15 May 2024 21:57:19 +0000</pubDate>
				<guid isPermaLink="false">https://training.dfirdiva.com/?post_type=job_listing&#038;p=2789</guid>

					<description><![CDATA[<p><img width="1200" height="630" src="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png 1200w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-300x158.png 300w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-1024x538.png 1024w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-768x403.png 768w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-400x210.png 400w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>Title: Cloud Forensics Demystified: Decoding Cloud Investigation Complexities for Digital Forensic Professionals Authors: Ganesh Ramakrishnan &#38; Mansoor Haqanee Publisher: Packt Where to Buy (links): Packt Amazon* Topics: Cloud Fundamentals Forensic Readiness: Tools, Techniques, and Preparation for Cloud Forensics DFIR Investigations – Logs in AWS, Azure, and GCP Cloud Productivity Suites (Microsoft 365 and Google Workspace)&#8230;]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignnone size-medium wp-image-2793" src="https://training.dfirdiva.com/wp-content/uploads/2024/05/CloudForensicsDemystified-243x300.jpg" alt="" width="243" height="300" srcset="https://training.dfirdiva.com/wp-content/uploads/2024/05/CloudForensicsDemystified-243x300.jpg 243w, https://training.dfirdiva.com/wp-content/uploads/2024/05/CloudForensicsDemystified-830x1024.jpg 830w, https://training.dfirdiva.com/wp-content/uploads/2024/05/CloudForensicsDemystified-768x947.jpg 768w, https://training.dfirdiva.com/wp-content/uploads/2024/05/CloudForensicsDemystified-1245x1536.jpg 1245w, https://training.dfirdiva.com/wp-content/uploads/2024/05/CloudForensicsDemystified-1661x2048.jpg 1661w, https://training.dfirdiva.com/wp-content/uploads/2024/05/CloudForensicsDemystified-162x200.jpg 162w, https://training.dfirdiva.com/wp-content/uploads/2024/05/CloudForensicsDemystified-400x493.jpg 400w" sizes="auto, (max-width: 243px) 100vw, 243px" /></p>
<p><strong>Title</strong>: Cloud Forensics Demystified: Decoding Cloud Investigation Complexities for Digital Forensic Professionals</p>
<p><strong>Authors</strong>: Ganesh Ramakrishnan &amp; Mansoor Haqanee</p>
<p><strong>Publisher</strong>: Packt</p>
<p><strong>Where to Buy</strong> (links):</p>
<p><a href="https://www.packtpub.com/product/cloud-forensics-demystified/9781800564411">Packt</a></p>
<p><a href="https://amzn.to/3wIYuM0">Amazon</a>*</p>
<p><strong>Topics</strong>:</p>
<ul class=" eplus-wrapper eplus-styles-uid-53dec5">
<li class=" eplus-wrapper">Cloud Fundamentals</li>
<li class=" eplus-wrapper">Forensic Readiness: Tools, Techniques, and Preparation for Cloud Forensics</li>
<li class=" eplus-wrapper">DFIR Investigations – Logs in AWS, Azure, and GCP</li>
<li>Cloud Productivity Suites (Microsoft 365 and Google Workspace)</li>
<li class=" eplus-wrapper">Common Attack Vectors and TTPs</li>
<li class=" eplus-wrapper">Cloud Forensic Analysis – Responding to an Incident in the Cloud</li>
<li>The Digital Forensics and Incident Response Process</li>
<li>Tools and Techniques for Digital Forensic Investigations</li>
<li>Live Forensic Analysis and Threat Hunting</li>
<li>Network Forensics</li>
<li>Malware Investigations</li>
<li>Traditional Forensics vs Cloud Forensics</li>
<li>MITRE ATT&amp;CK Framework</li>
<li class=" eplus-wrapper">Cloud Evidence Acquisition (AWS, Azure, GCP)</li>
<li class=" eplus-wrapper">Analyzing Compromised Containers</li>
<li class=" eplus-wrapper">Analyzing Compromised Cloud Productivity Suites (Microsoft 365 and Google Workspace)</li>
</ul>
<hr />
<p>*DFIR Diva is an affiliate of Amazon and receives a small percentage of sales made through affiliate links that go toward keeping the site running.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Hands-On KQL Courses (Blu Raven)</title>
		<link>https://training.dfirdiva.com/listing/hands-on-kql-courses-blu-raven</link>
		
		<dc:creator><![CDATA[DFIR Diva]]></dc:creator>
		<pubDate>Sat, 09 Mar 2024 04:10:19 +0000</pubDate>
				<guid isPermaLink="false">https://training.dfirdiva.com/?post_type=job_listing&#038;p=2606</guid>

					<description><![CDATA[<p><img width="1200" height="630" src="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png 1200w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-300x158.png 300w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-1024x538.png 1024w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-768x403.png 768w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-400x210.png 400w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>Name &#38; Direct Link: Hands-On KQL Courses Platform: Blu Raven Cost: Free &#8211; $546 Hands-On: Yes (uses a hyper-realistic lab environment) Proof of Completion: Yes &#8211; Certificate of Completion Courses and Topics: Introduction to KQL for Security Analysis (Free &#8211; 50 seats are made available every week) Introduction to Databases and Logging KQL Fundamentals and&#8230;]]></description>
										<content:encoded><![CDATA[<p><img width="1200" height="630" src="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png 1200w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-300x158.png 300w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-1024x538.png 1024w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-768x403.png 768w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-400x210.png 400w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p><p><strong>Name &amp; Direct Link: <a href="https://academy.bluraven.io/">Hands-On KQL Courses</a></strong></p>
<p><strong>Platform</strong>: Blu Raven</p>
<p><strong>Cost</strong>: Free &#8211; $546</p>
<p><strong>Hands-On</strong>: Yes (uses a hyper-realistic lab environment)</p>
<p><strong>Proof of Completion</strong>: Yes &#8211; Certificate of Completion</p>
<p><strong>Courses and Topics</strong>:</p>
<p><strong><a href="https://academy.bluraven.io/intro-to-kql-for-security-analysis">Introduction to KQL for Security Analysis</a></strong> (Free &#8211; 50 seats are made available every week)</p>
<ul>
<li>Introduction to Databases and Logging</li>
<li>KQL Fundamentals and Exploring Data</li>
<li>Searching and Filtering Data</li>
<li>Joining and Combining Datasets</li>
</ul>
<hr />
<p><strong><a href="https://academy.bluraven.io/hands-on-kusto-query-language-kql-for-security-analysts">Hands-On Kusto Query Language (KQL) for Security Analysts</a></strong> ($327)</p>
<ul>
<li>Introduction to Databases and Logging</li>
<li>KQL Fundamentals and Exploring Data</li>
<li>Searching and Filtering Data</li>
<li>Creating and Manipulating Fields</li>
<li>Joining and Combining Datasets</li>
<li>Time Traveling within the Logs</li>
<li>Aggregating Data</li>
<li>Visualizing Data</li>
<li>Time Series Analysis</li>
<li>Using KQL for Triage and Investigations</li>
</ul>
<hr />
<p><a href="https://academy.bluraven.io/hands-on-kql-for-threat-hunting-and-detection-engineering"><strong>Hands-On KQL for Threat Hunting and Detection Engineering</strong></a> ($546)</p>
<ul>
<li>Introduction to Databases and Logging</li>
<li>KQL Fundamentals and Exploring Data</li>
<li>Searching and Filtering Data</li>
<li>Creating and Manipulating Fields</li>
<li>Joining and Combining Datasets</li>
<li>Time Traveling within the Logs</li>
<li>Aggregating Data</li>
<li>Anomaly Detection using KQL</li>
<li>Time Series Analysis</li>
<li>Visualizing Data</li>
</ul>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AWS Security Incident Response Courses (AWS)</title>
		<link>https://training.dfirdiva.com/listing/aws-security-incident-response-courses-aws</link>
		
		<dc:creator><![CDATA[DFIR Diva]]></dc:creator>
		<pubDate>Sun, 10 Dec 2023 12:47:39 +0000</pubDate>
				<guid isPermaLink="false">https://training.dfirdiva.com/?post_type=job_listing&#038;p=2457</guid>

					<description><![CDATA[<p><img width="1200" height="630" src="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png 1200w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-300x158.png 300w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-1024x538.png 1024w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-768x403.png 768w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-400x210.png 400w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>Name &#38; Direct Link: AWS Security Incident Response Courses Platform: AWS Cost: Free Proof of Completion: Certificate Courses: AWS Security Incident Response Overview AWS Security Incident Response &#8211; Cryptomining Use Case AWS Security Incident Response &#8211; Ransomware Use Case AWS Security Incident Response &#8211; Compromised IAM Credentials Use Case]]></description>
										<content:encoded><![CDATA[<p><img width="1200" height="630" src="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png 1200w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-300x158.png 300w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-1024x538.png 1024w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-768x403.png 768w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-400x210.png 400w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p><p><strong>Name &amp; Direct Link: <a href="https://explore.skillbuilder.aws/learn/external-ecommerce;view=none;redirectURL=?ctldoc-catalog-0=se-%22aws%20security%20incident%22">AWS Security Incident Response Courses</a></strong></p>
<p><strong>Platform</strong>: AWS</p>
<p><strong>Cost</strong>: Free</p>
<p><strong>Proof of Completion</strong>: Certificate</p>
<p><strong>Courses</strong>:</p>
<ul>
<li><a href="https://explore.skillbuilder.aws/learn/course/external/view/elearning/17875/aws-security-incident-response-overview">AWS Security Incident Response Overview</a></li>
<li><a href="https://explore.skillbuilder.aws/learn/course/external/view/elearning/17798/aws-security-incident-response-cryptomining-use-case">AWS Security Incident Response &#8211; Cryptomining Use Case</a></li>
<li><a href="https://explore.skillbuilder.aws/learn/course/external/view/elearning/17797/aws-security-incident-response-ransomware-use-case">AWS Security Incident Response &#8211; Ransomware Use Case</a></li>
<li><a href="https://explore.skillbuilder.aws/learn/course/external/view/elearning/17796/aws-security-incident-response-compromised-iam-credentials-use-case">AWS Security Incident Response &#8211; Compromised IAM Credentials Use Case</a></li>
</ul>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cloud Incident Response Framework (Cloud Security Alliance)</title>
		<link>https://training.dfirdiva.com/listing/cloud-incident-response-framework-cloud-security-alliance</link>
		
		<dc:creator><![CDATA[DFIR Diva]]></dc:creator>
		<pubDate>Wed, 25 Oct 2023 03:30:36 +0000</pubDate>
				<guid isPermaLink="false">https://training.dfirdiva.com/?post_type=job_listing&#038;p=2170</guid>

					<description><![CDATA[<p><img width="1200" height="630" src="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png 1200w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-300x158.png 300w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-1024x538.png 1024w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-768x403.png 768w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-400x210.png 400w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>Name &#38; Direct Link: Cloud Incident Response Framework (publication) Platform: Cloud Security Alliance (CSA)]]></description>
										<content:encoded><![CDATA[<p><img width="1200" height="630" src="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png 1200w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-300x158.png 300w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-1024x538.png 1024w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-768x403.png 768w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-400x210.png 400w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p><p><strong>Name &amp; Direct Link: <a href="https://cloudsecurityalliance.org/research/topics/cloud-incident-response/">Cloud Incident Response Framework (publication)</a></strong></p>
<p><strong>Platform</strong>: Cloud Security Alliance (CSA)</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Pwned Labs</title>
		<link>https://training.dfirdiva.com/listing/pwned-labs</link>
		
		<dc:creator><![CDATA[DFIR Diva]]></dc:creator>
		<pubDate>Wed, 25 Oct 2023 02:39:46 +0000</pubDate>
				<guid isPermaLink="false">https://training.dfirdiva.com/?post_type=job_listing&#038;p=2162</guid>

					<description><![CDATA[<p><img width="1200" height="630" src="https://training.dfirdiva.com/wp-content/uploads/2022/11/PurpleTeam.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://training.dfirdiva.com/wp-content/uploads/2022/11/PurpleTeam.png 1200w, https://training.dfirdiva.com/wp-content/uploads/2022/11/PurpleTeam-300x158.png 300w, https://training.dfirdiva.com/wp-content/uploads/2022/11/PurpleTeam-1024x538.png 1024w, https://training.dfirdiva.com/wp-content/uploads/2022/11/PurpleTeam-768x403.png 768w, https://training.dfirdiva.com/wp-content/uploads/2022/11/PurpleTeam-400x210.png 400w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>Name &#38; Direct Link: Pwned Labs Platform: Pwned Labs Cost: Basic &#8211; Free, Pro &#8211; $20/month or $200/year Good For Beginners: Yes &#8211; There are labs labeled as &#8220;Beginner&#8221; Community: There is a Pwned Labs Discord Server Description: Hands-On Security Cloud Labs. There are labs for both blue and red teams. Including DFIR-type labs such&#8230;]]></description>
										<content:encoded><![CDATA[<p><img width="1200" height="630" src="https://training.dfirdiva.com/wp-content/uploads/2022/11/PurpleTeam.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://training.dfirdiva.com/wp-content/uploads/2022/11/PurpleTeam.png 1200w, https://training.dfirdiva.com/wp-content/uploads/2022/11/PurpleTeam-300x158.png 300w, https://training.dfirdiva.com/wp-content/uploads/2022/11/PurpleTeam-1024x538.png 1024w, https://training.dfirdiva.com/wp-content/uploads/2022/11/PurpleTeam-768x403.png 768w, https://training.dfirdiva.com/wp-content/uploads/2022/11/PurpleTeam-400x210.png 400w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p><p><strong>Name &amp; Direct Link</strong>: <a href="https://pwnedlabs.io/"><strong>Pwned Labs</strong></a></p>
<p><strong>Platform:</strong> Pwned Labs</p>
<p><strong>Cost:</strong> Basic &#8211; Free, Pro &#8211; $20/month or $200/year</p>
<p><strong>Good For Beginners</strong>: Yes &#8211; There are labs labeled as &#8220;Beginner&#8221;</p>
<p><strong>Community</strong>: There is a Pwned Labs Discord Server</p>
<p><strong>Description:</strong> Hands-On Security Cloud Labs. There are labs for both blue and red teams. Including DFIR-type labs such as &#8220;Investigate Threats with Amazon Detective&#8221; and &#8220;Breach in the Cloud&#8221;.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cloud Forensics &#038; Incident Response Videos and Resources (Cado Security)</title>
		<link>https://training.dfirdiva.com/listing/cloud-forensics-incident-response-videos-and-resources-cado-security</link>
		
		<dc:creator><![CDATA[DFIR Diva]]></dc:creator>
		<pubDate>Tue, 24 Oct 2023 04:14:33 +0000</pubDate>
				<guid isPermaLink="false">https://training.dfirdiva.com/?post_type=job_listing&#038;p=2154</guid>

					<description><![CDATA[<p><img width="1200" height="630" src="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png 1200w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-300x158.png 300w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-1024x538.png 1024w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-768x403.png 768w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-400x210.png 400w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p>Name &#38; Direct Link: Cloud Forensics &#38; Incident Response Videos Platform: YouTube &#8211; Cado Security Topics Include: EC2 Forensics and Incident Response AWS GuardDuty for Forensics &#38; Incident Response AWS SSM Forensics and Incident Response Google Kubernetes Engine Forensics and Incident Response Kubernetes: Docker Forensics &#38; Incident Response Google Compute Engine Forensics and Incident Response&#8230;]]></description>
										<content:encoded><![CDATA[<p><img width="1200" height="630" src="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR.png 1200w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-300x158.png 300w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-1024x538.png 1024w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-768x403.png 768w, https://training.dfirdiva.com/wp-content/uploads/2021/09/PurpleDFIR-400x210.png 400w" sizes="auto, (max-width: 1200px) 100vw, 1200px" /></p><p><strong>Name &amp; Direct Link</strong>: <a href="https://www.youtube.com/@cadosecurity5380/videos"><strong>Cloud Forensics &amp; Incident Response Videos</strong></a></p>
<p><strong>Platform</strong>: YouTube &#8211; Cado Security</p>
<p><strong>Topics Include</strong>:</p>
<ul>
<li>EC2 Forensics and Incident Response</li>
<li>AWS GuardDuty for Forensics &amp; Incident Response</li>
<li>AWS SSM Forensics and Incident Response</li>
<li>Google Kubernetes Engine Forensics and Incident Response</li>
<li>Kubernetes: Docker Forensics &amp; Incident Response</li>
<li>Google Compute Engine Forensics and Incident Response</li>
<li>ECS Forensics and Incident Response</li>
<li>Azure Forensics and Incident Response</li>
<li>AWS Log Forensics &amp; Incident Response</li>
<li>Cloud Security Fundamentals for Forensics &amp; Incident Response</li>
</ul>
<hr />
<p><strong>Additional Resources</strong>:</p>
<p><strong>There is a free <a href="https://www.cadosecurity.com/cado-community-edition/">Cado Community Edition</a></strong> &#8211; leverages the scale and speed of the cloud to simplify deep-dive investigations.</p>
<p><strong>Cado Security also developed an open source tool</strong>: <a href="https://github.com/cado-security/cloudgrep"><strong>CloudGrep</strong></a> (It currently supports searching log files, optionally compressed with gzip (.gz) or zip (.zip), in AWS S3, Azure Storage or Google Cloud Storage.)</p>
<p>In addition to their <a href="https://www.cadosecurity.com/blog/"><strong>Blog</strong></a>, they have cloud forensics &amp; incident response <a href="https://www.cadosecurity.com/resources/"><strong>Resources</strong></a> on their website such as:</p>
<ul>
<li><a href="https://www.cadosecurity.com/ultimate-guide-to-incident-response-in-azure">Ultimate Guide to Incident Response in Azure</a></li>
<li><a href="https://www.cadosecurity.com/ultimate-guide-to-incident-response-in-aws">Ultimate Guide to Incident Response in AWS</a></li>
<li><a href="https://www.cadosecurity.com/ultimate-guide-to-incident-response-in-gcp">The Ultimate Guide to Incident Response in GCP</a></li>
<li><a href="https://www.cadosecurity.com/the-ultimate-guide-to-docker-and-kubernetes-incident-response">The Ultimate Guide to Docker &amp; Kubernetes Forensics &amp; Incident Response</a></li>
<li><a href="https://www.cadosecurity.com/the-ultimate-guide-to-forensics-of-mining-malware-in-linux-container-and-cloud-environments">The Ultimate Guide to Forensics of Mining Malware in Linux Container and Cloud Environments</a></li>
<li><a href="https://www.cadosecurity.com/microsoft-365-cheat-sheet">Investigating Microsoft 365 Compromises Cheat Sheet</a></li>
<li><a href="https://www.cadosecurity.com/gcp-cheat-sheet">GCP Incident Response Cheat Sheet</a></li>
<li><a href="https://www.cadosecurity.com/aws-ir-cheat-sheet">AWS Incident Response Cheat Sheet</a></li>
<li><a href="https://www.cadosecurity.com/azure-ir-cheat-sheet">Azure Incident Response Cheat Sheet</a></li>
</ul>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
