iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The iX workshop Cloud Security Masterclass – Angriff und Verteidigung in AWS is a two-day online course for people who operate AWS environments and want to understand both how attacks develop and how to detect and respond to them. Its curriculum connects identity compromise and privilege escalation with configuration weaknesses, attack paths between local IT and AWS, and security-event analysis using CloudTrail, CloudWatch, and GuardDuty.
What the workshop covers
Heise/iX describes the course as an attacker-and-defender view of AWS security, rather than a session focused only on configuring individual services. The announced subjects include:
- Unauthorized information gathering and initial compromise of AWS identities
- Privilege escalation and attack paths between local IT environments and AWS resources
- Finding and remediating misconfigurations
- Activating and using AWS security capabilities
- Analyzing security events and responding to incidents with CloudTrail, CloudWatch, and GuardDuty
The Heise/iX workshop announcement names Frank Ully as the trainer and describes him as an experienced pentester and Principal Consultant Cybersecurity at Corporate Trust Business Risk & Crisis Management GmbH in Munich.
Who is likely to benefit
The publisher identifies administrators, IT security managers, and security specialists who operate AWS environments as the intended audience. The material is especially relevant to teams that need to connect identity controls, cloud configuration, monitoring, and incident handling instead of treating them as separate tasks.
#1 Best Overall
The announcement does not establish prerequisites, the amount of hands-on lab time, or how much of the course is lecture versus practical exercises. If those details affect your decision, ask the organizer before registering. When assessing this workshop alongside other training, check current course offerings and compare practical lab time, identity and attack-path coverage, detection and logging breadth, incident-response exercises, trainer credentials, delivery format, duration, price, and schedule.
How the AWS services fit together
CloudTrail, CloudWatch, and GuardDuty serve different roles; using one does not make the others interchangeable. AWS’s IAM logging and monitoring guidance describes CloudTrail as recording IAM and STS API calls as events. CloudWatch monitors AWS resources and applications, tracks metrics, supports dashboards and alarms, and can monitor CloudTrail and other log files through CloudWatch Logs. GuardDuty provides security findings that can help identify activity for investigation.
Rank #2
AWS recommends GuardDuty and Security Hub CSPM across accounts and active Regions, along with CloudTrail logging across accounts, for its Security Incident Response service. AWS says those detection services are not prerequisites for activating that service, but without their findings there is less proactive triage information and investigations are more limited; GuardDuty can also be enabled after onboarding. This recommendation is specific to that incident-response context, not a universal configuration rule for every AWS environment. See the AWS incident-response onboarding guidance.
Check coverage across Regions
GuardDuty is regional. AWS Prescriptive Guidance recommends enabling it in all supported Regions, including Regions without active workloads, because findings can still be generated there. Organizations that monitor only the Regions they currently use may therefore leave a visibility gap. Review coverage against your account structure and requirements using AWS Prescriptive Guidance on incident response.
Build an investigation-ready logging foundation
AWS’s Security Incident Response guide identifies CloudTrail logs, VPC Flow Logs, and Route 53 Resolver query logs as a basic logging set for AWS security investigations. Storage and retention choices depend on the team’s query tools, retention requirements, familiarity, and cost. The guide describes S3 as durable storage that can be queried with Athena, while CloudWatch Logs provides built-in querying through Logs Insights. These are options to weigh against your needs, not a single prescribed retention period. The guidance is in the AWS Security Incident Response guide, dated April 7, 2026.
Shared responsibility still applies
AWS distinguishes security of the cloud—the infrastructure AWS operates—from security in the cloud, which includes customer responsibilities. The customer’s specific duties vary with the AWS services used and also depend on data sensitivity, organizational requirements, and applicable laws. Using AWS services does not by itself complete an organization’s security work. AWS explains this model in its CloudTrail security guidance.
Rank #4
Session details and registration
The Heise/iX announcement lists an online session for October 15–16, 2026, from 09:00 to 17:00. It also listed a 10% early-booking discount with a September 17, 2026 deadline. That deadline has passed, so the discount should not be assumed to remain available. Because the announcement is dated, check the publisher’s current event information for registration status, price, and availability.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

