SEC504: Hacker Tools, Techniques, and Incident Handling

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usConnect, learn, and share with other cybersecurity professionals
Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders
Become a member for instant access to our free resources.
Sign UpMission-focused cybersecurity training for government, defense, and education
Explore industry-specific programming and customized training solutions
Sponsor a SANS event or research paper
We're here to help.
Contact UsExpert advice for shoring up your password best practices today on this World Password Day
Passwords (also commonly called credentials) have become one of the primary targets of cyber attackers, especially attackers with more advanced skill sets or those who are attempting to persist long-term in an organization’s environment.
TTPs (Tactics, Techniques and Procedures) is a taxonomy defining the common behaviors of cyber attackers when targeting, hacking into, and persisting within an organization’s environment. A variety of reports, data, and statistics have demonstrated a shift in how threat actor TTPs have changed from a focus on malware to a focus on passwords. Phishing used to be a means to infect a computer; now phishing and social engineering-related attacks have become the means to gain valid passwords.
The reason for this change is it is much harder for security teams to detect an intruder if that intruder is using valid credentials to pivot and traverse through an organization’s systems and data. The term is called ‘living off the land’ and implies a cyber attacker is using the same valid tools and credentials that authorized individuals use, so the cyber attacker's activities blend in and appear to be legitimate.
This is why passwords have become one of the primary targets and why stolen or compromised credentials have become one of the top risks for organizations.
Finally, here are four fantastic OUCH! Security Awareness Newsletters you can share with your workforce on how to securely create and use passwords:
Become an expert in how to best secure your workforce, including using passwords, in the intense three-day SANS MGT433 Managing Human Risk course.
Lance revolutionized cyber defense by founding the Honeynet Project. Over the past 25 years, he has helped 350+ organizations worldwide build resilient security cultures, transforming human risk management into a cornerstone of modern cybersecurity.
Read more about Lance Spitzner