{"title":"Home page","description":null,"products":[{"product_id":"advanced-cloud-incident-response-in-azure-and-microsoft-365-korstiaan-stam-dctfall26","title":"Advanced Cloud Incident Response in Azure and Microsoft 365 - Korstiaan Stam - DCTFall26","description":"\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eName of Training\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e Advanced Cloud Incident Response in Azure and Microsoft 365\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eTrainer(s)\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e Korstiaan Stam\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eDates\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e \u003cmeta charset=\"utf-8\"\u003eOct 1 -2, 2026\u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003cstrong\u003eTime: \u003c\/strong\u003e8:30 am - 5:30 pm\u003c\/span\u003e\u003cspan\u003e\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eVenue\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e \u003cmeta charset=\"utf-8\"\u003eTBD\u003cbr\u003e\u003cmeta charset=\"utf-8\"\u003e\n\u003cstrong\u003eEarly Bird Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$3000 (w\/GST)\u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003c\/span\u003e\u003cstrong\u003eRegular Cost\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e: \u003c\/strong\u003e$3,450 SGD \u003cmeta charset=\"utf-8\"\u003e(\u003cmeta charset=\"utf-8\"\u003ew\/GST) \u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003cstrong\u003eProficiency Exam Add-on:\u003c\/strong\u003e $450 SGD \u003cmeta charset=\"utf-8\"\u003e(\u003cmeta charset=\"utf-8\"\u003ew\/GST)\u003c\/span\u003e\u003cspan\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eShort Summary:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eThis course equips you with the advanced forensic skills to confidently detect, scope, and investigate sophisticated cyber threats across Azure and Microsoft 365 environments. Through immersive hands-on labs and real-world attack simulations, you will master the analysis of cloud log artifacts to lead effective incident response investigations.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eCourse Description: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eThis hands-on two-day training offers a comprehensive guide to incident response in the Microsoft cloud, covering various topics essential for handling threats and attacks. The course starts with an overview of the concepts of the Microsoft cloud that are relevant for incident response. Participants will learn how to scope an incident in the Microsoft cloud and how to leverage it to set up an incident response capability. On the first day you will be immersed in the world of Azure attacks, we cover the different phases of an attack focusing on the evidence an attack leaves and how you can identify attacks based on the available evidence. On the second day we will shift our focus to Microsoft 365. The training covers the different types of evidence available in a Microsoft 365 environment. Participants will gain an understanding of how to acquire data from a Microsoft 365 environment using multiple methods and tools, and how to parse, enrich, and analyze the Microsoft 365 Unified Audit Log (UAL). The best part of the training is that everything you learn you'll apply with hands-on labs in a CTF like environment. Additionally, we have created two full attack scenarios in both Azure \u0026amp; M365 and you're tasked in the CTF to solve as many pieces of the puzzle as you can.\u003cbr\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eCourse Outline: \u003c\/strong\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003eDay 1\u003cbr\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cspan\u003eCourse introduction\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure IR introduction\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure Terminology \u0026amp; Hierarchy\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eEntra ID, Users, Groups \u0026amp; Security Principals\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eEntra ID Roles\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eEntra ID Hybrid setup\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eEntra ID Security (Conditional Access \u0026amp; Identity Protection)\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003e\u003cstrong\u003eExercise 1.1 - Exploring Azure\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure \u0026amp; Entra Audit \u0026amp; Logging\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eKQL for Incident Response\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eKQL Introduction\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eNeed to know KQL commands\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAdvanced KQL\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003e\u003cstrong\u003eExercise 1.2 - KQL Querying\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eGraph API for Incident Response\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eGraph API calls for IR\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure Attack Techniques - Part I\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure Attack Overview\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eReconnaissance: Internal and External\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eInitial Access: Valid accounts, Password Attacks \u0026amp; Malicious apps\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\u003cspan\u003e\u003cstrong\u003eExercise 1.3 - Investigate Recon \u0026amp; Initial Access\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure Attack Techniques - Part II\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eExecution Introduction \u0026amp; Azure RunCommand\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eExecution: Virtual Machine Scripting \u0026amp; Automation accounts\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eExecution: Function app \u0026amp; Cloud Shell\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003ePrivilege Escalation: PIM \u0026amp; Elevated Access Toggle\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003ePrivilege Escalation: Azure AD applications\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003ePersistence: Account Creation \u0026amp; Network Security Group Modification\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003ePersistence: Azure Lighthouse \u0026amp; Delegated Administrators\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003ePersistence: Cross-Tenant Synchronization \u0026amp; Subscription Transfers\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003ePersistence: Federated options\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003e\u003cstrong\u003eExercise 1.4 - Execution, Persistence \u0026amp; Privilege Escalation\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure Attack Techniques - Part III\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eCredential Access: Tokens \u0026amp; Application secrets\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eCredential Access: KeyVault dumping\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eExfiltration\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure Attack tools\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003e\u003cstrong\u003eExercise 1.5 - Credential Access, Exfiltration\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eResponding to Azure attacks\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eIntroduction \u0026amp; NIST model\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eCloud Incident Response: Preparation\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eCloud Incident Response: Investigate \u0026amp; Contain\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eCloud Incident Response: Remediate \u0026amp; Recover\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eToken \u0026amp; Session Revocation\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure Incident Response tools\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cspan\u003e-------------------------- End of day 1---------------------------------------------\u003cbr\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003eDay 2\u003c\/span\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 IR introduction\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 - Forensic artefacts\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 - Course introduction\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eUnified Audit Log: Introduction \u0026amp; Advanced Auditing \u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eUnified Audit Log: Structure\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eUnified Audit Log: Access \u0026amp; Acquisition\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMailItemsAccessed\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eEverything you need to know about the MailItemsAccessed Operation\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003e\u003cstrong\u003eExercise 2.1 - Exploration of the UAL\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 Email Forwarding Rules\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eForensic analysis of inbox rules\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eForensic analysis of transport rules\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eForensic analysis of the Message Trace Log (MTL)\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 Attack Techniques - Part I\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 Attacks Overview\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eInitial Access: Phishing\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eInitial Access: MiTM \u0026amp; AiTM attacks\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 Attack Techniques - Part II\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eExecution: API calls \u0026amp; PowerShell\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003ePersistence \u0026amp; Privilege Escalation: Account manipulation\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003ePersistence \u0026amp; Privilege Escalation: Account Creation \u0026amp; MFA registration\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 Attack Techniques - Part III\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eCollection \u0026amp; Exfiltration: eDiscovery \u0026amp; Content search\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eCollection \u0026amp; Exfiltration: Power Automate abuse\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003e\u003cstrong\u003eExercise 2.2 - Compromise of an email account\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 Attack tools\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAccess Token abuse \u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAccess Token abuse \u0026amp; Family Of Client IDs (FOCI)\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003e\u003cstrong\u003eExercise 2.3 - Extracting \u0026amp; Manipulating tokens (Live Lab)\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 Anti-Forensic techniques\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft 365 IR Tools \u0026amp; Techniques\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft Extractor Suite\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eHawk\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eUntitled Goose Tool\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft Defender for Cloud Apps\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003e\u003cstrong\u003eExercise 2.4- Using the Microsoft Extractor Suite\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eBest practices for remediation and recovery in Microsoft 365\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eRemediation \u0026amp; Recovery - Walkthrough\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\n\u003cstrong\u003eBonus exercises:\u003cbr\u003e\u003c\/strong\u003e\n\u003cul\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\u003cstrong\u003eInvestigating OAuth apps\u003cbr\u003e\u003c\/strong\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\u003cstrong\u003eInvestigation of a malicious Function (Live Lab)\u003cbr\u003e\u003c\/strong\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\u003cspan\u003e\u003cstrong\u003eInvestigation of a suspicious automation account (Live Lab)\u003c\/strong\u003e\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eCTF Time\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eAzure CTF\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli\u003e\u003cspan\u003eMicrosoft CTF\u003cbr\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\n\u003cstrong\u003eBonus exercise:\u003cbr\u003e\u003c\/strong\u003e\n\u003cul\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\u003cstrong\u003eInvestigating OAuth applications\u003cbr\u003e\u003c\/strong\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\u003cstrong\u003eInvestigation of a malicious Function\u003cbr\u003e\u003c\/strong\u003e\u003c\/li\u003e\n\u003cli style=\"font-weight: bold;\"\u003e\u003cstrong\u003eInvestigation of a suspicious Automation Account\u003c\/strong\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cspan\u003e-------------------------- End of day 2---------------------------------------------\u003cstrong\u003e\u003cbr\u003e\u003c\/strong\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eDifficulty Level:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIntermediate\/Advanced\u003c\/span\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIntermediate Definition - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eAdvanced Definition - The student is expected to have significant practical experience with the tools and technologies that the training will focus on.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eSuggested Prerequisites:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cb\u003e\u003c\/b\u003eExperience in the Microsoft cloud will prove very useful to be able to keep up. Experience with PowerShell and\/or KQL is not required but will help you to gain even more from the training. You must also not be afraid of the command-line interface as this will be a hands-on training and not everything will be in the GUI.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat Students Should Bring:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eImportant: You only have to bring your laptop with a browser and we will provide you with access to the cloud tenants and investigation data.\u003cstrong\u003e\u003c\/strong\u003e\u003cspan\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eWhat the Trainer Will Provide:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli dir=\"ltr\"\u003eDigital training materials\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eCloud Access to a training environment\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eLab Access to a pre-configured Microsoft lab environment for the duration of the class\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eTrainer(s) Bio:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eKorstiaan Stam is the Founder and CEO of Invictus Incident Response \u0026amp; former SANS Trainer - FOR509: Cloud Forensics and Incident Response. Korstiaan is a passionate incident responder, preferably in the cloud. He developed and contributed to many open-source tools related to cloud incident response. Korstiaan has gained a lot of knowledge and skills over the years which he is keen to share.  \u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eWay before the cloud became a hot topic, Korstiaan was already researching it from a forensics perspective. “Because I took this approach I have an advantage, because I simply spent more time in the cloud than others. More so, because I have my own IR consultancy company, I spent a lot of time in the cloud investigating malicious behavior, so I don’t just know one cloud platform, but I have knowledge about all of them.” That equips him to help students with the challenge of every cloud working slightly or completely different. “If you understand the main concepts, you can then see that there’s also a similarity among all the clouds. That is why I start with the big picture in my classes and then zoom in on the details. Korstiaan also uses real-life examples from his work to discuss challenges he’s faced with students to relate with their day-to-day work. “To me, teaching not only means sharing my knowledge on a topic, but also applying real-life implications of that knowledge. I always try to combine the theory with the everyday practice so students can see why it’s important to understand certain concepts and how the newly founded knowledge can be applied.”\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eProficiency Exam Option:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eThis course has the option for a proficiency certificate add-on. To earn the proficiency certificate, students will need to participate in the CTF challenge at the end of Day 2 and answer at least 50% of the questions across Microsoft 365 and Azure.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003ePlease reach out to training@defcon.org for any questions related to the proficiency exam and certificate option.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eRegistration Terms and Conditions: \u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTrainings are refundable before Sept 1, 2026, minus a non-refundable processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBetween Sept 2, 2026 and Sept 28, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll trainings are non-refundable after Sept 28, 2026.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTraining tickets may be transferred to another student. Please email us at training@defcon.org for specifics.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIf a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eFailure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eDEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eSeveral breaks will be included throughout the day. Please note that food is not included.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll courses come with a certificate of completion, contingent upon attendance at all course sessions. Some courses offer an option to upgrade to a certificate of proficiency, which requires an additional purchase and sufficient performance on an end-of-course evaluation.\u003c\/span\u003e\u003c\/p\u003e","brand":"Singapore October 2026","offers":[{"title":"Course only - Oct 1-2","offer_id":51478377005196,"sku":null,"price":3000.0,"currency_code":"SGD","in_stock":true},{"title":"Course + Proficiency Exam - Oct 1-2","offer_id":51478377037964,"sku":null,"price":3450.0,"currency_code":"SGD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0750\/9042\/8044\/files\/KorstiaanStam.png?v=1768361711"},{"product_id":"ai-secureops-attacking-defending-ai-applications-agents-abhinav-singh-dctfall26","title":"AI SecureOps: Attacking \u0026 Defending AI Applications \u0026 Agents - Abhinav Singh - DCTFall26","description":"\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eName of Training\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e AI SecureOps: Attacking \u0026amp; Defending AI Applications \u0026amp; Agents\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eTrainer(s)\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e Abhinav Singh\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eDates\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e Oct 1-2, 2026\u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003cstrong\u003eTime: \u003c\/strong\u003e8:30 am - 5:30 pm\u003c\/span\u003e\u003cspan\u003e\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eVenue\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e \u003cmeta charset=\"utf-8\"\u003eTBD\u003c\/span\u003e\u003cspan\u003e\u003cbr\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eEarly Bird Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$2,200 (w\/GST)\u003cbr\u003e\u003cstrong\u003eRegular Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$2,650 SGD \u003cmeta charset=\"utf-8\"\u003e(\u003cmeta charset=\"utf-8\"\u003ew\/GST) \u003cbr\u003e\u003cstrong\u003eProficiency Exam Add-on:\u003c\/strong\u003e $450 SGD \u003cmeta charset=\"utf-8\"\u003e(\u003cmeta charset=\"utf-8\"\u003ew\/GST)\u003c\/span\u003e\u003cbr\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eShort Summary:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eStep into the front lines of securing enterprise AI with an immersive, CTF-style training built around realistic attack-and-defense scenarios for AI applications, agents, and MCP-connected systems. Through hands-on labs, participants will explore how prompt injection, agent abuse, poisoned context, unsafe tool use, and authorization failures can lead to backend compromise, data exposure, and infrastructure impact. The course focuses on the enterprise realities of securing AI apps \u0026amp; agentic systems, covering red and blue teaming, guardrails, monitoring, incident response, and Responsible AI. Designed for security practitioners, builders, and defenders, this training helps attendees understand how modern AI systems fail, how those failures chain into larger enterprise risks, and how to implement practical controls to secure AI deployments at scale.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003eTop 3 Takeaways\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLearn how to identify, exploit, and defend against real-world attacks on AI applications, agents, and tool-connected systems, including prompt injection, jailbreaks, agent abuse, and chained compromise paths.\u003c\/li\u003e\n\u003cli\u003eBuild practical defensive capabilities for enterprise AI, including guardrails, security scanners, monitoring, and response patterns for public, private, and MCP-enabled AI services.\u003c\/li\u003e\n\u003cli\u003eGain hands-on experience using modern AI techniques for security testing, validation, and red\/blue teaming, including judge-LLM workflows, attack automation, and securing agentic AI supply chains.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eCourse Description: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eCan prompt injections lead to complete infrastructure takeovers? Could AI agents, MCP-connected tools, or poisoned external context be abused to compromise backend services? Can data poisoning in AI copilots impact a company’s stock? Can jailbreaks create false crisis alerts in security systems? This immersive, CTF-styled training in GenAI, LLM, agent, and MCP security dives into these pressing questions. Engage in realistic attack-and-defense scenarios focused on real-world threats, from prompt injection and remote code execution to backend compromise, tool abuse, unsafe agent orchestration, and MCP-specific trust and authorization failures. Tackle hands-on challenges with live AI applications to understand vulnerabilities and build robust defenses. Learn how to create a comprehensive security pipeline, master AI red and blue team strategies, secure tool-connected and agentic systems, build resilient guardrails for LLMs, and handle incident response for AI-based threats. You will also explore governance, Responsible AI, and enterprise security patterns for modern AI ecosystems.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBy 2027, Gartner, Inc. predicts that over 80% of enterprises will engage with AI applications, up from less than 5% in 2023. This rapid adoption presents a new challenge for security professionals. This training provides essential AI and LLM security skills through an immersive CTF-styled framework, bringing you from an intermediate to an advanced level. Delve into sophisticated techniques for mitigating AI threats and engineer robust defense mechanisms to address the complex security challenges posed by AI's rapid expansion. You will be provided with access to a live playground with custom-built AI applications replicating real-world attack scenarios covering use-cases defined under the OWASP LLM top 10 framework and mapped with stages defined in MITRE ATLAS. This dense training will navigate you through areas like the red and blue team strategies, create robust LLM defenses, incident response in LLM attacks, implement a Responsible AI (RAI) program, and enforce ethical AI standards across enterprise services, with the focus on improving the entire AI supply chain.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eThis training will also cover the completely new segment of Responsible AI (RAI), ethics, and trustworthiness in AI services. Unlike traditional cybersecurity verticals, these unique challenges such as bias detection, managing risky behaviors, and implementing mechanisms for tracking information are going to be the key challenges for enterprise security teams.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBy the end of this training, you will be able to:\u003c\/span\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli dir=\"ltr\"\u003e\n\u003cspan\u003eExploit vulnerabilities in AI applications to achieve code and command execution, uncovering scenarios such as instruction injection, agent control bypass, remote code execution for infrastructure takeover, and chaining multiple agents for goal hijacking.\u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003c\/span\u003e\n\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eConduct AI red-teaming using adversary simulation, OWASP LLM Top 10, and MITRE ATLAS frameworks, while applying AI security and ethical principles in real-world scenarios.\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eExecute and defend against adversarial attacks, including prompt injection, data poisoning, jailbreaks, agentic attacks, and insecure tool-connected workflows.\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003ePerform advanced AI red and blue teaming through multi-agent auto-prompting attacks, implementing a 3-way autonomous system consisting of attack, defend, and judge models.\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eBuild and deploy enterprise-grade LLM defenses, including custom guardrails for input\/output protection, security benchmarking, penetration testing of LLM agents, and defensive controls for MCP-enabled integrations.\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eUnderstand MCP \u0026amp; agent fundamentals and assess how they expand the attack surface of modern AI systems.\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eEstablish a comprehensive LLM SecOps process to secure the supply chain from adversarial attacks. Create a robust threat model for enterprise applications, including AI systems connected to external tools and data sources through MCP-like architectures.\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eImplement an incident response and risk management plan for enterprises developing or using GenAI services.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cdiv dir=\"ltr\"\u003e\n\u003cdiv class=\"gmail_quote\"\u003e\n\u003cdiv dir=\"ltr\"\u003e\u003cspan id=\"m_4537920884060312m_4557477349097280137m_-2991987330191836870gmail-docs-internal-guid-81f1794d-7fff-aac0-e0e1-98237d64c6cd\"\u003e\u003c\/span\u003e\u003c\/div\u003e\n\u003c\/div\u003e\n\u003c\/div\u003e\n\u003cp\u003e\u003cspan\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eCourse Outline: \u003c\/strong\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e### Introduction \u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eIntroduction to LLM and AI\u003c\/li\u003e\n\u003cli\u003eTerminologies and architecture\u003c\/li\u003e\n\u003cli\u003eTransformers, Attention \u0026amp; their security implications (hallucinations, jailbreaks, etc)\u003c\/li\u003e\n\u003cli\u003eAgents, multi-agents and multi-modal models\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eIntroduction to tool-connected AI systems and MCP as an emerging standard for connecting agents to external tools, data, and workflows\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e### Elements of AI Security (1 lab)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eUnderstanding AI vulnerabilities with case studies on AI security breaches\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eOWASP LLM Top 10 and MITRE mapping of attacks on AI supply chain  \u003c\/li\u003e\n\u003cli\u003eThreat modeling of AI Applications, tool-connection and MCP-enabled architectures, including trust boundaries across hosts, clients, servers, tools, resources, and external systems  \u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e### Adversarial LLM Attacks and Defenses (6 labs)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e(What, Why \u0026amp; how’s)Direct and indirect prompt injection attacks and their subtypes \u003c\/li\u003e\n\u003cli\u003eAdvanced prompt injections through obfuscation and cross-model injections\u003c\/li\u003e\n\u003cli\u003eBreaking system prompts and their trust criteria\u003c\/li\u003e\n\u003cli\u003eIndirect prompt injections through external input sources\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e### Responsible AI \u0026amp; Jailbreaking (6 labs)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eJailbreaking public LLMs covering adversarial AI, offensive security, and CBRN use-cases\u003c\/p\u003e\n\u003c\/li\u003e\n\u003cli\u003e\n\u003cp\u003eResponsible use and governance implications of increasingly autonomous, tool-connected AI systems\u003c\/p\u003e\n\u003c\/li\u003e\n\u003cli\u003eModel alignment, system prompt optimization, and defense\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e### Building Enterprise-grade LLM Defenses (2 labs)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploying LLM security scanner, adding custom rules, prompt block-lists, and guardrails.\u003c\/li\u003e\n\u003cli\u003eWriting custom detection logic, trustworthiness checks, and filters.\u003c\/li\u003e\n\u003cli\u003eBuilding security log monitoring and alerting for models using open-source tools.\u003c\/li\u003e\n\u003cli\u003eLLM security benchmarking and continuous reporting.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e### Red \u0026amp; Blue Teaming of Enterprise AI applications (4 labs)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eBusiness control flow testing for risky responses \u0026amp; misaligned behavior of applications\u003c\/li\u003e\n\u003cli\u003eUsing Colab notebooks for automation of API calls and reporting\u003c\/li\u003e\n\u003cli\u003eVector database and model-weight tracing for root-cause investigation\u003c\/li\u003e\n\u003cli\u003eRainbow teaming through a 3-way LLM implementation: target, attacker, and judge with self-improving attack prompts\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e### MCP Security \u0026amp; Defensive Architecture (1 lab)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eMCP fundamentals \u0026amp; security for agentic systems: protocol basics, trust-boundary changes, key risks like malicious servers and over-broad permissions, plus a browser-based exploit-and-defend lab\u003c\/li\u003e\n\u003cli\u003eDefense patterns for MCP-enabled systems with protection architectures\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e### Attacking \u0026amp; Defending Agentic Systems (5 labs)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eThreat modeling of agentic and multi-agent systems, including planning loops, memory, tool invocation, delegation, trust boundaries, and escalation paths\u003c\/li\u003e\n\u003cli\u003eAttacking LLM agents for task manipulation, risky behavior and PII disclosure in RAG\u003c\/li\u003e\n\u003cli\u003eInjection attacks on AI agents for code and command execution\u003c\/li\u003e\n\u003cli\u003eCompromising backend infrastructure by abusing over-permissioning and tool usage in agentic systems\u003c\/li\u003e\n\u003cli\u003eMulti-agent attacks causing privilege too calls, goal manipulation \u0026amp; chained escalations\u003c\/li\u003e\n\u003cli\u003eDefense patterns for agentic systems, including observability, approval gates, scoped permissions, secure delegation, and runtime tracing for high-risk actions.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e### Building AI SecOps Process\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eSummarizing the learnings into a SecOps workflow\u003c\/li\u003e\n\u003cli\u003eMonitoring trustworthiness, safety and security of enterprise AI applications\u003c\/li\u003e\n\u003cli\u003eImplementing NIST AI Risk Management Framework (RMF) for security monitoring\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eDifficulty Level:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eIntermediate - The student has education, some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eSuggested Prerequisites:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cb\u003e\u003c\/b\u003eComplete the simple pre-training instructions: create a paid OpenAI API key, set up a Google Colab notebook, and read the Introduction document. No local setup is needed. All the training materials and lab access will be provided during the training.\u003cbr\u003e\u003c\/p\u003e\n\u003cp\u003eWho Should Take This Course\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eSecurity professionals who need to understand how modern AI systems fail and how to defend them\u003c\/li\u003e\n\u003cli\u003eRed and blue teamers looking to add AI applications, agents, and tool-connected systems to their offensive and defensive workflows\u003c\/li\u003e\n\u003cli\u003eAI\/LLM developers and engineers who want to build more secure applications, agents, and integrations\u003c\/li\u003e\n\u003cli\u003eSecurity architects, detection engineers, and defenders responsible for securing enterprise AI deployments\u003c\/li\u003e\n\u003cli\u003eAI safety, governance, and risk professionals who need a practical understanding of how technical failures map to real enterprise risk\u003c\/li\u003e\n\u003cli\u003eProduct leaders, founders, and technical decision-makers who want to better understand the attack surface of AI-enabled products and agentic systems\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat Students Should Bring: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cb\u003e\u003c\/b\u003e\u003cspan\u003e\u003c\/span\u003eA laptop with browser access is ideal, preferably a personal laptop without network restricting tools.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eComplete the pre-training setup prior to the class which includes setting up:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli dir=\"ltr\"\u003e\u003cspan\u003eAPI key for OpenAI.\u003c\/span\u003e\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eGoogle Colab account.\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003eComplete the pre-training setup before the first day.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat the Trainer Will Provide:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli dir=\"ltr\"\u003e\u003cspan\u003eOne year access to a live interactive playground with various exercises to practice different attack and defense scenarios for GenAI and LLM applications.\u003c\/span\u003e\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003e\u003cspan\u003e\"AI SecureOps\" Metal coin for CTF players.\u003c\/span\u003e\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003e\u003cspan\u003eComplete course guide containing 200+ pages in PDF format. It will contain step-by-step guidelines for all exercises and labs, and a detailed explanation of concepts discussed during the training.\u003c\/span\u003e\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003e\u003cspan\u003ePDF versions of the slides that will be used during the training.\u003c\/span\u003e\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003e\u003cspan\u003eAccess to the Discord server for continued engagement, support, and development in the field of AI Security \u0026amp; Safety.\u003c\/span\u003e\u003c\/li\u003e\n\u003cli dir=\"ltr\"\u003e\u003cspan\u003eAccess to HuggingFace models, datasets, and transformers.\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eTrainer(s) Bio:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cspan\u003e\u003cstrong\u003eAbhinav Singh\u003c\/strong\u003e is an esteemed cybersecurity leader \u0026amp; researcher with over 15 years of experience across technology leaders and financial institutions, as well as an independent trainer and consultant. Author of \"Metasploit Penetration Testing Cookbook\" and \"Instant Wireshark Starter,\" his contributions span patents, open-source tools, and numerous publications. Recognized in security portals and digital platforms, Abhinav is a sought-after speaker \u0026amp; trainer at international conferences like Black Hat, RSA, DEFCON, BruCon, and many more, where he shares his deep industry insights and innovative approaches in cybersecurity. He also leads multiple AI security groups at CSA, responsible for coming up with cutting-edge white papers and industry reports on the safety and security of AI.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eReview a few examples of Abhinav's previous courses at the links below:\u003c\/span\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cspan\u003e \u003c\/span\u003e\u003cspan\u003e2026:\u003ca href=\"https:\/\/sg.shop.defcon.org\/collections\/singapore-2026\/products\/ai-secureops-defending-ai-applications-and-services-abhinav-singh-dcsg2026\" target=\"_blank\"\u003e DEF CON Singapore,\u003c\/a\u003e\u003ca href=\"https:\/\/training.defcon.org\/collections\/def-con-training-las-vegas-2026\/products\/ai-secureops-attacking-defending-ai-applications-agents-abhinav-singh-dclv2026\" target=\"_blank\"\u003e \u003c\/a\u003e\u003ca href=\"https:\/\/insomnihack.ch\/workshops\/ai-secureops-attacking-defending-ai-applications-agents\/\" target=\"_blank\"\u003eInsomni’hack\u003c\/a\u003e,\u003ca href=\"https:\/\/hackmiami.com\/training-ai-secureops-attacking-defending-genai-applications-and-services.html\" target=\"_blank\"\u003e HackMiami\u003c\/a\u003e,\u003ca href=\"https:\/\/www.x33fcon.com\/#!t\/AbhinavSingh.md\" target=\"_blank\"\u003e x33fcon\u003c\/a\u003e,\u003ca href=\"https:\/\/owasp.glueup.com\/event\/owasp-global-appsec-eu-2026-vienna-austria-162243\/training.html\" target=\"_blank\"\u003e OWASP Global AppSec EU\u003c\/a\u003e\u003c\/span\u003e\n\u003c\/li\u003e\n\u003cli role=\"presentation\"\u003e\n\u003cspan\u003e2025:\u003ca href=\"https:\/\/insomnihack.ch\/workshops\/ai-secureops-attacking-defending-genai-applications-and-services\/\" target=\"_blank\"\u003e Insomni’hack\u003c\/a\u003e, BruCon, Hack Miami, \u003ca href=\"https:\/\/www.rsaconference.com\/experts\/abhinav-singh\" target=\"_blank\"\u003eRSA Conference\u003c\/a\u003e,\u003ca href=\"https:\/\/training.defcon.org\/collections\/def-con-training-las-vegas-2025\/products\/abhinav-singh-ai-attacks-defense-las-vegas-2025\" target=\"_blank\"\u003e DEF CON Vegas\u003c\/a\u003e, Nsec\u003c\/span\u003e\u003cu\u003e\u003cspan\u003e, Lacson, \u003ca href=\"https:\/\/events.humanitix.com\/owaspnz2025-training\"\u003eOWASP Auckland\u003c\/a\u003e\u003c\/span\u003e\u003c\/u\u003e\u003cspan\u003e\u003c\/span\u003e\n\u003c\/li\u003e\n\u003cli role=\"presentation\"\u003e\u003cspan\u003e2024:\u003ca href=\"https:\/\/blackhatmea.com\/trainings-list\/2024\/ai-secureops-genai-and-llm-security-enterprises\" target=\"_blank\"\u003e Black Hat MEA\u003c\/a\u003e,\u003ca href=\"https:\/\/www.rsaconference.com\/Library\/presentation\/USA\/2024\/Blueprint%20for%20Data%20Defense%20in%20the%20Public%20Cloud%20Strategies%20and%20Playbooks\" target=\"_blank\"\u003e RSA San Francisco Workshop\u003c\/a\u003e, Hack Miami, Florida,\u003ca href=\"https:\/\/appsec.org.nz\/conference-2024\/training-ai_secure_ops\" target=\"_blank\"\u003e OWASP New Zealand\u003c\/a\u003e, LASCON 2024,\u003ca href=\"https:\/\/deepsec.net\/archive\/2024.deepsec.net\/speaker.html#WSLOT693\" target=\"_blank\"\u003e DeepSec Austria\u003c\/a\u003e\u003c\/span\u003e\u003c\/li\u003e\n\u003cli role=\"presentation\"\u003e\u003cspan\u003e2023:\u003ca href=\"https:\/\/blackhatmea.com\/trainings-list\/2023\/cloud-security-masterclass-defenders-guide-securing-aws-azure-infrastructure\" target=\"_blank\"\u003e Black Hat\u003c\/a\u003e, DEF CON Las Vegas, OWASP AppSec Days New Zealand,\u003ca href=\"https:\/\/www.rsaconference.com\/Library\/presentation\/USA\/2023\/Defender%20Guide%20to%20Securing%20Data%20in%20Public%20Cloud%20Infrastructures\" target=\"_blank\"\u003e RSA Conference\u003c\/a\u003e, Insomni’hack Geneva,\u003ca href=\"https:\/\/www.infosecworldusa.com\/isw23\/workshops\/\" target=\"_blank\"\u003e InfoSec World\u003c\/a\u003e, BruCon (virtual), BruCon 2023, OWASP LASCON\u003c\/span\u003e\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eProficiency Exam Option:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eThis course has the option for a proficiency certificate add-on. To earn the proficiency certificate, students will have to score at least 1400 out of 2200 on the course capture the flag (CTF). Only students who purchase the proficiency certificate will have their work evaluated by the instructor to certify mastery of the course material.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003ePlease reach out to training@defcon.org for any questions related to the proficiency exam and certificate option.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong style=\"font-family: -apple-system, BlinkMacSystemFont, 'San Francisco', 'Segoe UI', Roboto, 'Helvetica Neue', sans-serif; font-size: 0.875rem;\"\u003eRegistration Terms and Conditions: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTrainings are refundable before Sept 1, 2026, minus a non-refundable processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBetween Sept 2, 2026 and Sept 28, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll trainings are non-refundable after Sept 28, 2026.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTraining tickets may be transferred to another student. Please email us at training@defcon.org for specifics.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIf a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eFailure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eDEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eSeveral breaks will be included throughout the day. Please note that food is not included.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll courses come with a certificate of completion, contingent upon attendance at all course sessions. Some courses offer an option to upgrade to a certificate of proficiency, which requires an additional purchase and sufficient performance on an end-of-course evaluation.\u003c\/span\u003e\u003c\/p\u003e","brand":"Singapore October 2026","offers":[{"title":"Course only - Oct 1-2","offer_id":51478533734540,"sku":null,"price":2200.0,"currency_code":"SGD","in_stock":true},{"title":"Course + Proficiency Exam - Oct 1-2","offer_id":51478533767308,"sku":null,"price":2650.0,"currency_code":"SGD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0750\/9042\/8044\/files\/Abhinav_image_2.png?v=1768361707"},{"product_id":"modern-agentic-ai-engineering-and-security-joseph-mlodzianowski-dctfall26","title":"Modern Agentic AI Engineering and Security - Joseph Mlodzianowski  - DCTFall26","description":"\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eName of Training: \u003c\/b\u003eModern Agentic AI Engineering and Security\u003cbr\u003e\u003cb\u003e\u003c\/b\u003e\u003cb\u003eTrainer(s): \u003c\/b\u003eJoseph Mlodzianowski\u003cbr\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eDates\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e Oct 1-2, 2026\u003c\/span\u003e\u003cbr\u003e\u003cb\u003eVenue:\u003c\/b\u003e TBD\u003cbr\u003e\u003cb\u003eEarly Bird Cost:\u003c\/b\u003e $2500 SGD (w\/GST)\u003cbr\u003e\u003cb\u003eRegular Cost:\u003c\/b\u003e $2,950 SGD (w\/GST)\u003cbr\u003e\u003cspan style=\"font-family: -apple-system, BlinkMacSystemFont, 'San Francisco', 'Segoe UI', Roboto, 'Helvetica Neue', sans-serif; font-size: 0.875rem;\"\u003e\u003cstrong\u003eProficiency Exam Add-on:\u003c\/strong\u003e $450 SGD (w\/GST)\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eShort Summary:\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eThis two-day intensive bootcamp delivers practical, hands-on training tooling in an lab-driven bootcamp that will take a student from beginner to intermediate, with some advanced capabilities.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eCourse Description:\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eThe course is designed to \u003cspan style=\"mso-spacerun: yes;\"\u003e \u003c\/span\u003estarts with an overview of the main two AI coding agents, with a heavy emphasis on OpenAI Codex, and secondary on Claude Code. On the first day you will be immersed in to moving from coding to code to using coding agents to plan, build, verify, troubleshoot and fix simple to more complex issues. Modern AI coding agents can do more than write code: they can remember project context, read instructions, call tools, use app integrations, consult MCP servers, and coordinate specialized sub-agents. This course shows how to put those pieces together without creating an ungoverned automation mess.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003e\u003cspan style=\"font-size: 14.0pt; line-height: 115%;\"\u003eCourse Outline:\u003c\/span\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 1 — The Modern AI Software Engineering Stack\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l4 level1 lfo1; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eHow AI-assisted development has evolved beyond autocomplete\u003c\/li\u003e\n\u003cli style=\"mso-list: l4 level1 lfo1; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eThe model–agent–tool–workflow architecture\u003c\/li\u003e\n\u003cli style=\"mso-list: l4 level1 lfo1; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eCodex interfaces and repository-aware development\u003c\/li\u003e\n\u003cli style=\"mso-list: l4 level1 lfo1; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eRepository instructions and external tool integrations\u003c\/li\u003e\n\u003cli style=\"mso-list: l4 level1 lfo1; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSecurity, Sandboxing, approvals, least privilege, and human review\u003c\/li\u003e\n\u003cli style=\"mso-list: l4 level1 lfo1; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eHow to analyze and safely approach an unfamiliar repository\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eAnalyze, bound, and validate a repository change\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 2 — Installing and Configuring Codex\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l10 level1 lfo2; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eInstallation and runtime considerations\u003c\/li\u003e\n\u003cli style=\"mso-list: l10 level1 lfo2; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eAuthentication and credential boundaries\u003c\/li\u003e\n\u003cli style=\"mso-list: l10 level1 lfo2; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eUser-level, project-levels and security configuration\u003c\/li\u003e\n\u003cli style=\"mso-list: l10 level1 lfo2; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eConfiguration precedence and repository trust\u003c\/li\u003e\n\u003cli style=\"mso-list: l10 level1 lfo2; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eAdvanced Sandbox and approval settings\u003c\/li\u003e\n\u003cli style=\"mso-list: l10 level1 lfo2; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDiagnosing an effective Codex configuration without exposing secrets\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eVerify and explain a safe Codex setup\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 3 — Context Engineering\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l2 level1 lfo3; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eWhy incomplete or excessive context causes failures\u003c\/li\u003e\n\u003cli style=\"mso-list: l2 level1 lfo3; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSources of repository and task context\u003c\/li\u003e\n\u003cli style=\"mso-list: l2 level1 lfo3; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSelecting relevant files, tests, errors, and documentation\u003c\/li\u003e\n\u003cli style=\"mso-list: l2 level1 lfo3; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDefining assumptions, constraints, and exclusions\u003c\/li\u003e\n\u003cli style=\"mso-list: l2 level1 lfo3; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eConstructing a structured context packet\u003c\/li\u003e\n\u003cli style=\"mso-list: l2 level1 lfo3; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eBalancing completeness with context discipline\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eBuild and validate a bounded context packet\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 4 — Mastering AGENTS.md\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l12 level1 lfo4; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eHow durable repository guidance works\u003c\/li\u003e\n\u003cli style=\"mso-list: l12 level1 lfo4; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eInstructions, discovery and precedence\u003c\/li\u003e\n\u003cli style=\"mso-list: l12 level1 lfo4; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eRepository-level and directory-level guidance\u003c\/li\u003e\n\u003cli style=\"mso-list: l12 level1 lfo4; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eWriting concise and actionable engineering instructions\u003c\/li\u003e\n\u003cli style=\"mso-list: l12 level1 lfo4; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSecurity controls for Agents\u003c\/li\u003e\n\u003cli style=\"mso-list: l12 level1 lfo4; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eHandling conflicting, outdated, or oversized guidance\u003c\/li\u003e\n\u003cli style=\"mso-list: l12 level1 lfo4; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSeparating behavioral instructions from enforcement controls\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eAuthor and verify repository and subtree guidance\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 5 — Steering Codex\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l16 level1 lfo5; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eEngineering task postures such as Explore, Plan, Implement, Test, and Review\u003c\/li\u003e\n\u003cli style=\"mso-list: l16 level1 lfo5; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDefining deliverables, constraints, validation, and stopping conditions\u003c\/li\u003e\n\u003cli style=\"mso-list: l16 level1 lfo5; tab-stops: list .5in;\" class=\"MsoNormal\"\u003ePlanning before complex or ambiguous implementation\u003c\/li\u003e\n\u003cli style=\"mso-list: l16 level1 lfo5; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSecurity Considerations and Moving safely between task postures\u003c\/li\u003e\n\u003cli style=\"mso-list: l16 level1 lfo5; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eEscalation and retry boundaries\u003c\/li\u003e\n\u003cli style=\"mso-list: l16 level1 lfo5; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eEvidence-based completion decisions\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eBuild and validate an evidence-gated steering plan\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 6 — Cost-Effective Models and Modes\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l6 level1 lfo6; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eEvaluating work by complexity, ambiguity, and risk\u003c\/li\u003e\n\u003cli style=\"mso-list: l6 level1 lfo6; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSelecting appropriate reasoning and execution approaches\u003c\/li\u003e\n\u003cli style=\"mso-list: l6 level1 lfo6; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eMeasuring latency, retries, context, and review effort\u003c\/li\u003e\n\u003cli style=\"mso-list: l6 level1 lfo6; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eConsidering total engineering cost instead of model cost alone\u003c\/li\u003e\n\u003cli style=\"mso-list: l6 level1 lfo6; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDefining escalation thresholds and budgets\u003c\/li\u003e\n\u003cli style=\"mso-list: l6 level1 lfo6; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eAvoiding unsupported cost-saving claims\u003c\/li\u003e\n\u003cli style=\"mso-list: l6 level1 lfo6; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSecurity models and secure approaches\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eBuild a measurable model-role decision\u003c\/b\u003e\u003cb\u003e \u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 7 — Advanced Codex Development\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l8 level1 lfo7; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eBreaking complex work into dependency-aware tasks\u003c\/li\u003e\n\u003cli style=\"mso-list: l8 level1 lfo7; tab-stops: list .5in;\" class=\"MsoNormal\"\u003ePlanning repository changes before implementation\u003c\/li\u003e\n\u003cli style=\"mso-list: l8 level1 lfo7; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eUsing branches and isolated checkouts appropriately\u003c\/li\u003e\n\u003cli style=\"mso-list: l8 level1 lfo7; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eImplementing changes within bounded scope\u003c\/li\u003e\n\u003cli style=\"mso-list: l8 level1 lfo7; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSecurity and Layered testing and validation\u003c\/li\u003e\n\u003cli style=\"mso-list: l8 level1 lfo7; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eReviewing diffs, addressing findings, and preparing handoffs\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003ePlan, implement, test, review, and hand off a bounded change\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 8 — MCP Servers and Tool Integration\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l15 level1 lfo8; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eMCP host, client, server, and tool architecture\u003c\/li\u003e\n\u003cli style=\"mso-list: l15 level1 lfo8; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eCapability discovery and tool contracts\u003c\/li\u003e\n\u003cli style=\"mso-list: l15 level1 lfo8; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eTransport, lifecycle, schema, and result handling\u003c\/li\u003e\n\u003cli style=\"mso-list: l15 level1 lfo8; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eIdentity, data, side effects, and authorization boundaries\u003c\/li\u003e\n\u003cli style=\"mso-list: l15 level1 lfo8; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eConfiguring and operating MCP integrations\u003c\/li\u003e\n\u003cli style=\"mso-list: l15 level1 lfo8; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eMonitoring, disabling, and safely retiring integrations\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eCore lab: \u003cb\u003eInspect, invoke, constrain, validate, and retire a local MCP tool\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eOptional Lab 8.1 — Five Engineering MCP Servers\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents explore:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l9 level1 lfo9; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eOpenAI documentation integration\u003c\/li\u003e\n\u003cli style=\"mso-list: l9 level1 lfo9; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eVersion-aware library documentation\u003c\/li\u003e\n\u003cli style=\"mso-list: l9 level1 lfo9; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eGitHub repository workflows\u003c\/li\u003e\n\u003cli style=\"mso-list: l9 level1 lfo9; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eBrowser-based engineering workflows\u003c\/li\u003e\n\u003cli style=\"mso-list: l9 level1 lfo9; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDesign-system and Figma workflows\u003c\/li\u003e\n\u003cli style=\"mso-list: l9 level1 lfo9; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eCanaries, monitoring, disablement, and removal\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eDeploy and monitor five engineering MCP servers\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eRecommended Lab 8.2 — Supply-Chain Security\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l0 level1 lfo10; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eServer admission and ownership checks\u003c\/li\u003e\n\u003cli style=\"mso-list: l0 level1 lfo10; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSource and dependency verification\u003c\/li\u003e\n\u003cli style=\"mso-list: l0 level1 lfo10; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eVersion and artifact integrity\u003c\/li\u003e\n\u003cli style=\"mso-list: l0 level1 lfo10; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eThreat modeling before installation\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eThreat-model and evaluate an MCP server before admission\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eSupplemental Lab 8.3 — Identity and Authorization\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l7 level1 lfo11; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eAuthentication versus authorization\u003c\/li\u003e\n\u003cli style=\"mso-list: l7 level1 lfo11; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eLeast-privilege scopes\u003c\/li\u003e\n\u003cli style=\"mso-list: l7 level1 lfo11; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eToken audience and identity separation\u003c\/li\u003e\n\u003cli style=\"mso-list: l7 level1 lfo11; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eTesting permitted and denied behavior\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eDesign and verify MCP identity and authorization boundaries\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eSupplemental Lab 8.4 — Runtime and Secret Boundaries\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l13 level1 lfo12; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eTransport and process isolation\u003c\/li\u003e\n\u003cli style=\"mso-list: l13 level1 lfo12; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eEnvironment and secret handling\u003c\/li\u003e\n\u003cli style=\"mso-list: l13 level1 lfo12; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eFilesystem and network restrictions\u003c\/li\u003e\n\u003cli style=\"mso-list: l13 level1 lfo12; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSecure runtime configuration\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eHarden MCP transport, runtime, and secret boundaries\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eSupplemental Lab 8.5 — Tool and Side-Effect Safety\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l14 level1 lfo13; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eTool schema and contract review\u003c\/li\u003e\n\u003cli style=\"mso-list: l14 level1 lfo13; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eInput and output validation\u003c\/li\u003e\n\u003cli style=\"mso-list: l14 level1 lfo13; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eRead versus write operations\u003c\/li\u003e\n\u003cli style=\"mso-list: l14 level1 lfo13; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eApproval boundaries and dangerous side effects\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eEvaluate tool contracts, content, and side effects\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eSupplemental Lab 8.6 — Monitoring and Incident Response\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l5 level1 lfo14; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eMCP health and security monitoring\u003c\/li\u003e\n\u003cli style=\"mso-list: l5 level1 lfo14; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDetecting unexpected tools or behavior\u003c\/li\u003e\n\u003cli style=\"mso-list: l5 level1 lfo14; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSecurity Controls and Best Practices\u003c\/li\u003e\n\u003cli style=\"mso-list: l5 level1 lfo14; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eAlerting and audit evidence\u003c\/li\u003e\n\u003cli style=\"mso-list: l5 level1 lfo14; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eContainment, recovery, and credential rotation\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eMonitor and respond to an MCP security incident\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 9 — Claude Code as a Complementary Tool\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l11 level1 lfo15; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eComparing engineering tools using evidence\u003c\/li\u003e\n\u003cli style=\"mso-list: l11 level1 lfo15; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSelecting the appropriate tool for a task\u003c\/li\u003e\n\u003cli style=\"mso-list: l11 level1 lfo15; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eClaude Code context and control concepts\u003c\/li\u003e\n\u003cli style=\"mso-list: l11 level1 lfo15; tab-stops: list .5in;\" class=\"MsoNormal\"\u003ePortable repository instructions\u003c\/li\u003e\n\u003cli style=\"mso-list: l11 level1 lfo15; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eAvoiding conflicting simultaneous writers\u003c\/li\u003e\n\u003cli style=\"mso-list: l11 level1 lfo15; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eCreating governed handoffs between tools\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eSelect and govern a complementary-tool workflow\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 10 — AI Development Workflow Engineering\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l1 level1 lfo16; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDesigning an end-to-end AI-assisted development lifecycle\u003c\/li\u003e\n\u003cli style=\"mso-list: l1 level1 lfo16; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDefining states, owners, inputs, outputs, and gates\u003c\/li\u003e\n\u003cli style=\"mso-list: l1 level1 lfo16; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eCreating executable validation and evidence chains\u003c\/li\u003e\n\u003cli style=\"mso-list: l1 level1 lfo16; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eManaging permissions, failures, and escalation\u003c\/li\u003e\n\u003cli style=\"mso-list: l1 level1 lfo16; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eRollback and release controls\u003c\/li\u003e\n\u003cli style=\"mso-list: l1 level1 lfo16; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eWorkflow monitoring, economics, and improvement\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eDesign and validate a governed AI delivery workflow\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 11 — Multi-Agent and Review Workflows\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents learn:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l18 level1 lfo17; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eWhen parallel agents are beneficial\u003c\/li\u003e\n\u003cli style=\"mso-list: l18 level1 lfo17; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eTask independence and dependency graphs\u003c\/li\u003e\n\u003cli style=\"mso-list: l18 level1 lfo17; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eDefining agent roles, context, authority, and budgets\u003c\/li\u003e\n\u003cli style=\"mso-list: l18 level1 lfo17; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eIsolating parallel changes\u003c\/li\u003e\n\u003cli style=\"mso-list: l18 level1 lfo17; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eIdentifying textual and semantic conflicts\u003c\/li\u003e\n\u003cli style=\"mso-list: l18 level1 lfo17; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eIndependent review and finding adjudication\u003c\/li\u003e\n\u003cli style=\"mso-list: l18 level1 lfo17; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSafe integration and stopping\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003eLab: \u003cb\u003eDesign and validate a safe parallel task and review workflow\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eChapter 12 —\u003cspan style=\"mso-spacerun: yes;\"\u003e  \u003c\/span\u003eAI Agentic \u0026amp; Platform Engineering Rollup\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003eStudents apply the entire course through:\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eA bounded enterprise change request\u003c\/li\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eInstruction and context analysis\u003c\/li\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSurface, execution, cost, and tool decisions\u003c\/li\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eMinimal implementation\u003c\/li\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eLayered validation\u003c\/li\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eSecurity and least-authority controls\u003c\/li\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eIndependent review and remediation\u003c\/li\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eRelease, rollback, and residual-risk decisions\u003c\/li\u003e\n\u003cli style=\"mso-list: l3 level1 lfo18; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eA short technical defense\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eAgentic lab:\u003c\/b\u003e Implement, validate, review, and defend an enterprise change\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eOptional Chapter 12.5 — AI Code Engineering Best Practices\u003c\/b\u003e\u003cb\u003e\u003c\/b\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e\u003cb\u003eWhat Students Should Bring: \u003c\/b\u003e\u003c\/p\u003e\n\u003cul type=\"disc\" style=\"margin-top: 0in;\"\u003e\n\u003cli style=\"mso-list: l17 level1 lfo19; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eLaptop with at least 16 GB RAM (32 GB recommended) \u0026amp; 60gb free disk space\u003c\/li\u003e\n\u003cli style=\"mso-list: l17 level1 lfo19; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eOperating system with support and ability to run virtual machines (VMware Workstation, VirtualBox, or similar virtualization platform)\u003c\/li\u003e\n\u003cli style=\"mso-list: l17 level1 lfo19; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eA ChatGPT (Codex)\u003cspan style=\"mso-spacerun: yes;\"\u003e  \u003c\/span\u003e$20\/Month plan and a separate free account plan and\/or Claude Code $20 a month\u003cspan style=\"mso-spacerun: yes;\"\u003e  \u003c\/span\u003eand a separate free limited account plan.\u003c\/li\u003e\n\u003cli style=\"mso-list: l17 level1 lfo19; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eAdministrative privileges on the laptop\u003c\/li\u003e\n\u003cli style=\"mso-list: l17 level1 lfo19; tab-stops: list .5in;\" class=\"MsoNormal\"\u003eA Virtual Machine with Ubuntu 26.04 or newer installed and updated.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eDifficulty Level:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eIntermediate - The student has education, some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eSuggested Prerequisites:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli class=\"MsoNormal\"\u003eStudents should have foundational Coding\/Programing knowledge and beginner exposure to intermediate Codex and Claude Code familiarity.\u003c\/li\u003e\n\u003cli class=\"MsoNormal\"\u003eUnderstanding of Defense in Depth, Security Frameworks like NIST CSF 2.0\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat Students Should Bring: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cb\u003e\u003c\/b\u003e\u003cspan\u003e\u003c\/span\u003eA laptop with browser access is ideal, preferably a personal laptop without network restricting tools.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat the Trainer Will Provide:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003eDetails coming soon.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eTrainer(s) Bio:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan style=\"font-family: -apple-system, BlinkMacSystemFont, 'San Francisco', 'Segoe UI', Roboto, 'Helvetica Neue', sans-serif; font-size: 0.875rem;\"\u003e\u003cstrong\u003eJoseph Mlodzianowski\u003c\/strong\u003e \u003c\/span\u003eis an information security aficionado, author, keynote speaker and adventurer; he started multiple villages at RSA Conference, DEF CON, and BLACK HAT, among others, including founding the original Red Team Village at RSAC and Def Con. Joseph has extensive expertise in cybersecurity infrastructure and architecture with over 25 years leading large teams of Cybersecurity and Network engineers, project managers, and architects in the design, deployment, and monitoring of various ranges of technologies in highly complex and rigorous environments. He designed and deployed a number of multi-million dollar datacenters from inception to completion for the Department of Defense in support of cybersecurity program deployments and critical infrastructure. Joseph is a AI Datacenter Cybersecurity Architect for OpenAI. Previously a Secure Network Data-center Architect at the Department of Defense, and before that a Lead Cybersecurity Data Center Architect at Cisco Systems Federal, for thirteen years building very large datacenters for ML and AI systems, for the Department of Defense. His experience extends beyond Designing, architecting, and deploying nearly two hundred data centers in commercial, private and public sector as highly restrictive environments.  Follow him on X @cedoxx , Facebook and Linkedin.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eProficiency Exam Option:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003eTwo-hour combination of hands-on project build and multiple questions with evidence.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003ePlease reach out to training@defcon.org for any questions related to the proficiency exam and certificate option.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong style=\"font-family: -apple-system, BlinkMacSystemFont, 'San Francisco', 'Segoe UI', Roboto, 'Helvetica Neue', sans-serif; font-size: 0.875rem;\"\u003eRegistration Terms and Conditions: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTrainings are refundable before Sept 1, 2026, minus a non-refundable processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBetween Sept 2, 2026 and Sept 28, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll trainings are non-refundable after Sept 28, 2026.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTraining tickets may be transferred to another student. Please email us at training@defcon.org for specifics.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIf a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eFailure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eDEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eSeveral breaks will be included throughout the day. Please note that food is not included.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll courses come with a certificate of completion, contingent upon attendance at all course sessions. Some courses offer an option to upgrade to a certificate of proficiency, which requires an additional purchase and sufficient performance on an end-of-course evaluation.\u003c\/span\u003e\u003c\/p\u003e","brand":"Singapore October 2026","offers":[{"title":"Course only - Oct 1-2","offer_id":51494589825164,"sku":null,"price":2500.0,"currency_code":"SGD","in_stock":true},{"title":"Course + Proficiency Exam - Oct 1-2","offer_id":51494589857932,"sku":null,"price":2950.0,"currency_code":"SGD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0750\/9042\/8044\/files\/joseph_716e153b-fc6e-4a7a-ab4c-ecdb319a50f5.png?v=1784676533"},{"product_id":"aws-real-world-attack-analysis-threat-detection-in-the-cloud-in-ming-loh-wei-chea-ang-dcsgfall26","title":"AWS Real-World Attack Analysis: AI-Assisted Threat Detection in the Cloud - In Ming Loh \u0026 Wei Chea Ang - DCTFall26","description":"\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eName of Training\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e AWS Real-World Attack Analysis: AI-Assisted Threat Detection in the Cloud\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eTrainer(s)\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e In Ming LOH \u0026amp; Wei Chea ANG\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eDates\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e \u003cmeta charset=\"utf-8\"\u003eOct 1-2, 2026\u003cbr\u003e\u003c\/span\u003e\u003cspan\u003e\u003cstrong\u003eTime: \u003c\/strong\u003e8.30am - 5.30pm\u003c\/span\u003e\u003cspan\u003e\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eVenue\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e:\u003c\/strong\u003e TBD\u003cbr\u003e\u003c\/span\u003e\u003cstrong\u003eEarly Bird Cost\u003c\/strong\u003e\u003cspan\u003e\u003cstrong\u003e: \u003c\/strong\u003e\u003c\/span\u003e\u003cspan\u003e$2,250 (w\/GST)\u003cbr\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eRegular Cost\u003c\/strong\u003e\u003cstrong\u003e: \u003c\/strong\u003e$2,700 (w\/GST)\u003cbr\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eShort Summary:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003eThis comprehensive, hands-on course equips security teams with the practical skills to master AWS security services and CloudTrail analysis, moving beyond theory to effectively detect and respond to modern attack techniques like privilege escalation and data exfiltration. Attendees will leave with a robust security foundation and the proven ability to investigate and defend their AWS infrastructure, directly strengthening their organization's cloud security posture.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eCourse Description: \u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cmeta charset=\"utf-8\"\u003eThis course is designed to equip security teams with the essential knowledge and practical skills needed to safeguard their AWS environments from modern threats. Participants will gain a deep understanding of core AWS security services, common attack vectors, and the capabilities of AWS CloudTrail for effective threat detection and response. Through hands-on labs, students will begin by configuring fundamental AWS services like Identity and Access Management (IAM), Amazon Elastic Compute Cloud (EC2), and AWS CloudTrail, establishing a robust foundation for security monitoring.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eBuilding upon this foundation, participants will engage in various investigation scenarios, analyzing CloudTrail data to identify and investigate various attack techniques demonstrated by the instructor. This practical approach allows students to master the analysis of CloudTrail logs and uncover suspicious activity. They will learn to identify prevalent attack techniques, such as privilege escalation and data exfiltration.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003eThis course empowers security professionals to build a robust security posture and effectively defend their AWS infrastructure against evolving threats.\u003cbr\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003e\u003cmeta charset=\"utf-8\"\u003e \u003cstrong\u003eCourse Outline: \u003c\/strong\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cmeta charset=\"utf-8\"\u003eTopic 1: AWS Fundamentals (Day 1)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eAWS Overview: Introducing the AWS core concept.\u003c\/li\u003e\n\u003cli\u003e\n\u003cmeta charset=\"utf-8\"\u003eHands on Configuration of AWS services such as IAM, EC2, Lambda, S3. This will provide the fundamental knowledge for the attendees before we cover how these services are abused by the threat actor.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003cmeta charset=\"utf-8\"\u003eTopic 2: Introduction to AWS CloudTrail (Day 1)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eCloudTrail Fundamentals: Learn the core concepts and functionalities of AWS CloudTrail.\u003c\/li\u003e\n\u003cli\u003eConfiguring CloudTrail: Master the process of setting up CloudTrail trails to capture relevant events and activities.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eTopic 3: CloudTrail Log Analysis (Day 1\/Day 2)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLog Interpretation: Develop the ability to decipher CloudTrail logs to identify user activities, API calls, and resource changes.\u003c\/li\u003e\n\u003cli\u003eThreat Detection: Learn to recognize indicators of compromise (IoCs), indicators of attack (IoA) and anomalies within CloudTrail logs.\u003c\/li\u003e\n\u003cli\u003eAdvanced Analysis Techniques: Explore methods for extracting actionable intelligence from CloudTrail data.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eTopic 4: Understanding the AWS Threat Landscape (Day 2)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eCommon AWS Attack Vectors: Explore real-world attack scenarios, including unauthorized access and data exfiltration.\u003c\/li\u003e\n\u003cli\u003eThreat Actor Tactics: Analyze the techniques employed by malicious actors to target AWS environments, aligning them with the industry-standard MITRE ATT\u0026amp;CK Framework.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eTopics 5: AWS Attack Detection (Day 2)\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdvanced Threat Hunting with CloudTrail: Analyze attacker methodologies and tactics as captured in CloudTrail logs to understand the techniques used by adversaries, enabling you to proactively identify and counteract potential threats.\u003c\/li\u003e\n\u003cli\u003ePractical Tips for Effective CloudTrail-Based Threat Hunting: Learn proven best practices and actionable strategies to perform robust threat hunting with CloudTrail, ensuring you can efficiently monitor, detect, and respond to evolving cyber risks.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eDifficulty Level:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIntermediate - \u003c\/span\u003e\u003cspan\u003eThe student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eSuggested Prerequisites:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cb\u003e\u003c\/b\u003e\u003cmeta charset=\"utf-8\"\u003eParticipants are not required to have prior AWS knowledge. The training curriculum includes comprehensive coverage of AWS fundamentals, though any existing AWS and SOC experience will be beneficial.\u003cbr\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWhat Students Should Bring:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli dir=\"ltr\"\u003e\n\u003cmeta charset=\"utf-8\"\u003eLaptop\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eWhat the Trainer Will Provide:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cul\u003e\n\u003cli dir=\"ltr\"\u003e\n\u003cmeta charset=\"utf-8\"\u003eOnline lab + Slides\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eTrainer(s) Bio:\u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cmeta charset=\"utf-8\"\u003e\u003cstrong\u003eIn Ming LOH\u003c\/strong\u003e is a principal consultant at a prominent cybersecurity firm, specializing in incident response and technical assessment engagements with a strong emphasis on cloud environments. He has been instrumental in numerous high-profile investigations, involving both nation-state and e-crime threat actors across a wide array of industries.\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eWei Chea ANG \u003c\/strong\u003ecurrently works at a leading SaaS company, empowering enterprises to secure and manage their digital assets. For the past 7 years, he has specialized in cloud security, working with a diverse range of organizations from startups to Fortune 100 companies. His expertise has been shared at prestigious conferences, including HITCon, ISC2 APAC Congress, and FIRST APAC Symposium.\u003cstrong\u003e\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cstrong\u003eRegistration Terms and Conditions: \u003c\/strong\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTrainings are refundable before Sept 1, 2026, minus a non-refundable processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBetween Sept 2, 2026 and Sept 28, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of $350.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll trainings are non-refundable after Sept 28, 2026.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eTraining tickets may be transferred to another student. Please email us at training@defcon.org for specifics.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eIf a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eFailure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eDEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eSeveral breaks will be included throughout the day. Please note that food is not included.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cspan\u003eAll courses come with a certificate of completion, contingent upon attendance at all course sessions. Some courses offer an option to upgrade to a certificate of proficiency, which requires an additional purchase and sufficient performance on an end-of-course evaluation.\u003c\/span\u003e\u003c\/p\u003e","brand":"Singapore October 2026","offers":[{"title":"Course only - Oct 1-2","offer_id":51499658412172,"sku":null,"price":2250.0,"currency_code":"SGD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0750\/9042\/8044\/files\/InMing.jpg?v=1768361718"}],"url":"https:\/\/sg.shop.defcon.org\/collections\/frontpage.oembed","provider":"DEF CON SG","version":"1.0","type":"link"}