SEC504: Hacker Tools, Techniques, and Incident Handling

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usConnect, learn, and share with other cybersecurity professionals
Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders
Become a member for instant access to our free resources.
Sign UpMission-focused cybersecurity training for government, defense, and education
Explore industry-specific programming and customized training solutions
Sponsor a SANS event or research paper
We're here to help.
Contact UsApply your credits to renew your certifications
Train at your own pace from wherever you are
Course content applicable to people with limited or no cyber security experience
Apply what you learn with hands-on exercises and labs
Gain foundational ICS and OT security knowledge and hands-on experience in this one-day course.
ICS310: ICS Cybersecurity Foundations builds foundational knowledge of ICS systems and explores how automation works across industries. Students analyze real-world cyberattacks to uncover defense strategies and learn five key ICS controls adaptable to any environment.
Tim serves as the Technical Director of ICS and SCADA programs at SANS, and he is responsible for developing, reviewing, and implementing technical components of the SANS ICS and SCADA product offerings.
Read more about Tim ConwayA former U.S. Air Force cyber warfare officer, Robert led the NSA’s first mission targeting threats to industrial infrastructure. Now at Dragos, he spearheads global defense of critical systems, shaping national policy and industry threat response.
Read more about Robert M. LeeJeff is a Subject Matter Expert (SME) for the Global Industrial Cyber Security Professional (GICSP) certification and is an instructor for the ICS612: ICS Cybersecurity In-Depth course.
Read more about Jeffrey ShearerExplore the course syllabus below to view the full range of topics covered in ICS310: ICS Cybersecurity Foundations.
ICS310 is a foundational course for those new to ICS/OT. This section explains who the course is for, how it fits into a broader ICS cybersecurity training program, its development by multiple experts, and its role as a starting point for advanced SANS ICS Security courses.
Section two introduces the basic building blocks of industrial control systems, their purpose, and their key design concepts. We explore how ICS/OT systems connect and depend on each other, emphasizing the need for thoughtful design and reliable operations.
Section three focuses on cybersecurity, exploring challenges faced by offensive and defensive teams in ICS/OT. Students examine security considerations across critical sectors and understand key differences between IT and OT systems, terms, and trends.
Section four uses real-world case studies and events to highlight key lessons for improving operational security. Even if the cases are not from your sector, understanding shared devices, threats, and responses will help defenders focus on actions that truly matter.
Section five introduces common ICS/OT security regulations, guidelines, and standards commonly encountered across systems and sectors worldwide. This section provides a broad overview to build familiarity and serve as a reference point, equipping students with fundamental knowledge that they might later deepen with courses on specific standards.
Section six provides guidance on the SANS Five ICS Cybersecurity Critical Controls to help students prioritize actions in their organizations’ ICS/OT security programs. Modeled after IT controls but tailored for OT, these threat-informed controls focus on practical, proven steps to strengthen ICS/OT cybersecurity.
Get feedback from the world’s best cybersecurity experts and instructors
Choose how you want to learn - online, on demand, or at our live in-person training events
Get access to our range of industry-leading courses and resources