

Cloud Under Attack: Investigating Azure & Microsoft 365 Intrusions Live
Investigate real intrusions across Azure AD/Entra ID, Exchange, Teams, SharePoint and Copilot, using real telemetry in a live class tenant.
Instructor:
Somil Tyagi, MDR Analyst at Palo Alto Networks Unit42.
Master’s‑educated Cybersecurity professional with Fortune 100 security fusion center experience, specializing in Incident Response, Cloud and Container Security, and automation. Experienced in investigating high‑impact compromises, including APT‑level attacks, with additional expertise in attack emulation, reverse engineering, and digital forensics.
About Event
Your organisation's most valuable data moved into a tenant. Identities, mailboxes, Teams chats, a subscription someone spun up last quarter. Attackers worked that out faster than most SOCs did.
A device code phishing link never touches your EDR. An inbox rule forwarding every invoice to an attacker does not trip a firewall. An external account dropping a malicious URL into a channel your finance team reads daily looks like nothing at all. Not because the telemetry is missing, but because almost nobody has been taught which log to open, or which field to look at.
This workshop closes that gap. You will learn to detect, respond to, and remediate novel attacks within Azure and Microsoft 365 environments, building the skills to defend against threats that bypass traditional security controls. You work in a configured tenant with real telemetry in a SIEM, writing your own KQL queries and running your own analysis, guided by an analyst who ran the attack emulation himself to capture the logs you will investigate.
Who this is for:
L1 and L2 SOC analysts seeing cloud alerts land in the queue who want to know what to do with them
Junior analysts who need a grounding in Azure and Microsoft 365 log sources before the security side makes sense
Detection engineers and threat hunters who need the log structure well enough to write their own queries
Incident responders moving from on-prem investigations into cloud and Microsoft 365 forensics
Requirements: No prior Azure experience needed.
The session starts with the services and log sources, then moves into the security side. If you can read a log and you know what a query is, you are qualified.
What you will be able to do afterwards:
Recognize and investigate trending abuses of authentication protocols in Azure AD/Entra ID, one of the most active attack techniques currently targeting Microsoft tenants
Investigate identity attacks across Azure and Microsoft 365 workloads, including Copilot, Teams, Exchange and other services, covering tactics from initial access and execution through to exfiltration via Exchange and SharePoint
Track the complete incident lifecycle, scoping the intrusion across initial access, enumeration, persistence, privilege escalation, exfiltration and impact, to build a full picture of attacker activity
Emulate real attack scenarios and perform hands-on log analysis: identifying the right logs to collect, interpreting their raw structures, and correlating across multiple sources with KQL queries
Write your own detection queries against Azure and Microsoft 365 telemetry, instead of waiting on out-of-the-box rules
What is included:
Live hands-on instruction from an analyst who ran the attack emulation himself to capture the logs you will investigate and explore novel attack techniques
Access to a configured Azure and Microsoft 365 tenant, no licence or subscription of your own required
Real telemetry in a SIEM, with you writing the queries and running the analysis
Closing Q&A with the instructor
Full session recording for everyone who registers
Certificate of participation with CPE credits
A place in a focused cohort of 40