SEC504: Hacker Tools, Techniques, and Incident Handling

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usConnect, learn, and share with other cybersecurity professionals
Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders
Become a member for instant access to our free resources.
Sign UpMission-focused cybersecurity training for government, defense, and education
Explore industry-specific programming and customized training solutions
Sponsor a SANS event or research paper
We're here to help.
Contact UsNEW! Microsoft Azure Lab Environment
SEC540: Cloud Security and DevSecOps Automation has released another major update that will help you in your efforts to build cloud infrastructure with Terraform, deploy resources to the Azure Cloud, and better understand the Container Security Lifecycle. Since the inception of SEC540, the lab environment has had a heavy focus on deploying and securing resources in the AWS Cloud. At the end of every class, I always ask students for feedback about their experience and how we can improve the course. By far, the most common feedback was:
To my past students, we heard you! In the spirit of continuous improvement, the SEC540 author team set a goal in the 2021 update to go multicloud, build full support for deploying the lab environment in Azure, and bring in security tooling for equivalent Azure analysis. This required a tremendous amount of engineering effort, documentation, and support from SANS. We are all proud to announce that SEC540’s lab environment now supports a dual path option for students to choose AWS or Azure as their cloud infrastructure provider!
Microsoft Azure Lab Environment
Students choosing the Azure Lab environment will experience a different toolchain, with a few common tools where possible:
SEC540: Cloud Security and DevSecOps Automation
SEC540.1: DevOps Security Automation
SEC540.2: Cloud Infrastructure Security
SEC540.3: Cloud Security Operations
SEC540.4: Cloud Security as a Service
SEC540.5: Compliance as Code
DevOps is the set of cultural and technical practices that enable teams to deliver value to their stakeholders quickly, securely and reliably. Take SEC540: Cloud Security and DevSecOps Automation and let us teach you how. Read the full course description here.
Eric is a co-founder and principal security engineer at Puma Security focusing on modern static analysis product development and DevSecOps automation. He is co-author and instructor for three SANS Cloud Security courses.
Read more about Eric Johnson