Kurssin päätavoitteena on kehittää osallistujasta DevSecOps-osaaja, joka kykenee yhdistämään kehityksen, operoinnin ja tietoturvan yhdeksi tehokkaaksi kokonaisuudeksi. Kurssi opettaa, miten turvallisuus rakennetaan automaattisesti osaksi sovellusten kehitys- ja julkaisuputkea sen sijaan, että tietoturva tarkastettaisiin vasta lopussa.
Kurssin jälkeen osallistujilla on valmius suorittaa GIAC Cloud Security Automation (GCSA) -sertifiointi.
Kurssikielenä on englanti.
Kesto: 5 päivää
Ajankohta: 23.–27.11.2026. Helsinki.
Hinta: 8230 €, sertifikaattivoucher 905 €
Peruutusehto: 45 päivää
Lisätietoja: smnfi.training@elisa.fi
Cloud Native Security and DevSecOps Automation
This training equips security, DevOps, and cloud professionals with the skills to build and secure modern cloud-native environments. Through hands-on labs, participants learn how to integrate security into CI/CD pipelines, secure containers and Kubernetes platforms, manage software supply chain risks, and automate compliance and security controls across cloud infrastructures.
The course is designed to help organizations embed security into every stage of software development, enabling faster and more secure delivery of cloud-native applications while reducing operational and cyber risk. It also prepares participants for the GIAC Cloud Security Automation (GCSA) certification.
For more information:
What SEC540 will teach:
- Understand DevOps principles for secure workflows
- Integrate AI security tools into developer environments and CI/CD pipelines
- Manage secrets and automate infrastructure with IaC
- Harden and monitor containers and Kubernetes workloads
- Secure software supply chain with SBOMs and artifact signing
- Defend microservices using cloud native identity provider and API Gateway services
- Automate compliance with policy guardrails and remediation
- Understand attacker tradecraft to perform proactive compromise assessments
- Upgrade detection capabilities via better understanding of novel attack techniques, focus on critical attack paths, and knowledge of available forensic artifacts
- Develop threat intelligence to track targeted adversaries and prepare for future intrusion events
- Build advanced forensics skills to counter anti-forensics and data hiding from technical subjects for use in both internal and external investigations
Should a breach occur, FOR508 graduates will have the skills to:
- Detect how and when attack happened
- Quickly identify compromised and infected systems
- Perform damage assessments and determine what was read, stolen, or changed
- Contain and remediate incidents
You Will Be Able To:
- Learn and master the tools, techniques, and procedures necessary to effectively hunt, detect, and contain a variety of adversaries and to remediate incidents.
- Detect and hunt unknown live, dormant, and custom malware in memory across multiple Windows systems in an enterprise environment
- Hunt through and perform incident response across hundreds of unique systems simultaneously using PowerShell, Velociraptor, and the SIFT Workstation
- Identify and track malware beaconing outbound to its command and control (C2) channel via memory forensics, registry analysis, and network connection residue.
- Determine how the breach occurred by identifying the root cause, the beachhead systems and initial attack mechanisms.
- Identify living off the land techniques, including malicious use of PowerShell and WMI.
- Target advanced adversary anti-forensics techniques like hidden and time-stomped malware, along with living off the land techniques used to move in the network and maintain an attacker's presence.
- Use memory analysis, incident response, and threat hunting tools in the SIFT Workstation to detect hidden processes, malware, attacker command lines, rootkits, network connections, and more.
- Track user and attacker activity second-by-second on the system you are analyzing through in-depth timeline and super-timeline analysis.
- Recover data cleared using anti-forensics techniques via Volume Shadow Copy/Restore Point analysis.
- Identify lateral movement and pivots within your enterprise across your endpoints, showing how attackers transition from system to system without detection.
- Understand how the attacker can acquire legitimate credentials - including domain administrator rights - even in a locked-down environment.
- Track data movement as attackers collect critical data and shift it to exfiltration collection points.
- Recover data cleared using anti-forensics techniques via Volume Shadow Copy and Restore Point analysis and artifact carving.
- Use collected data to perform effective remediation across the entire enterprise.
Varaa paikkasi koulutukseen
.jpg?fl=progressive&fm=jpg&q=80)
CISSP -tutkintoon tähtäävä valmennus
Valmennus kattaa laajan kirjon kyberturvallisuuden osa-alueita varmistaen monipuolisen asiantuntemuksen. CISSP (Certified Information System Security Professionals) on kansainvälinen ja hyvin tunnettu tietoturvan ammattilaisen sertifikaatti myöntäjänä (ISC)2.

Johdanto kyberuhkien torjuntaan
Kurssilla keskitytään IT-järjestelmien kyber- ja tietoturvauhkiin käytännönläheisesti. Kurssin tarkoituksena on antaa opiskelijalle hyvät tiedot nykyaikaisen kybertietoturvan perusteista.

SANS FOR572 - Advanced Network Forensics: Threat Hunting, Analysis and Incident Response
Kurssilla opitaan tärkeimmät edistyneet taidot ja tiedot, joita tarvitaan verkkoviestinnän ja artefaktien forensiikassa. Oppiminen tapahtuu lukuisten käytännön esimerkkien kautta. Kurssilla keskitytään tietoon, joka on tarpeen viestinnän tutkimisessa ja luokittelussa.
Kurssin jälkeen osallistujilla on mahdollisuus suorittaa GIAC Network Forensic Analyst (GNFA) -sertifikaatti.
