Hands-on two-day course for SOC analysts and detection engineers. Students build a complete security detection and investigation pipeline on AWS — from a bare EC2 instance through live automated AI-assisted investigations.
Platform: AWS (Amazon Linux 2023 EC2, CloudWatch, Security Hub, GuardDuty)
AI Tooling: CloudWatch AI Operations; AI coding assistants (Amazon Q, GitHub Copilot, or equivalent)
Language: Python 3.x and Bash
See outline.md for full module descriptions, learning objectives, and course overview.
- Basic Python (reading files, writing functions, running scripts from the command line)
- Familiarity with common security concepts (authentication, SSH, privilege escalation, alerts)
- An AWS account with permissions to launch EC2 instances and enable Security Hub and GuardDuty
- No prior AWS experience required — cloud concepts are introduced in Lab 1.1
- glossary.md — Key terms and AWS service definitions used throughout the course