SEC504: Hacker Tools, Techniques, and Incident Handling

Unlock industry insights and hands-on learning with upcoming SANS webcasts and workshops. View archived webcasts here.
Transitioning from a highly technical role to a leadership position in cybersecurity requires a unique blend of skills and values.
This will be an easy, fun and instructive walk through machine learning models, neural networks, all the way to LLMs, trying to see how we can fit and apply each one to our cyber defence challenges.
This workshop supports content from SEC522: Application Security: Securing Web Applications, APIs, and Microservices
Hear the stories from top SANS faculty of how they became the cybersecurity experts they are today and how their stories can be applied to your career journey. Learn how they build their skills to become one of the top practitioners within cybersecurity.
Join Brandon as he discusses widespread issues with cross-cloud integrations, this specific critical vulnerability in Microsoft Defender for Cloud, and how to proactively protect your organization from this class of vulnerabilities.
The maritime industry is the cornerstone of global trade, with approximately 80% of the world’s goods transported by sea. Vessels, whether they are container ships, tankers, or drill ships, are designed to be in service for 25 years or more. This longevity presents unique challenges, especially the need for continuous maintenance and system upgrades, including cybersecurity measures.
SEC547 Mastering Supply Chain Security: A 3-Part Webcast Series. Part 3 supports content and knowledge from SEC547: Defending Product Supply Chains.
As businesses rush to embrace the perceived benefits of AI systems, security professionals must take a more pragmatic view. In this talk, Andy will highlight some of the surprising attack vectors that LLM-powered applications may vulnerable to - and what we can do to help prevent abuse.
Have you heard that SANS has a new Advanced Python Automation class? Are you interested in trying out some of the content? Join us for this workshop where SANS Fellow and course author Mark Baggett will deliver the first hour and a half of content.
In this talk, "Operationalizing a Cyber Security Red Team," we will explore how to effectively build, execute, and continuously improve red team operations to emulate the tactics and strategies of real-world adversaries.
This presentation will equip attendees with the knowledge and tools necessary to identify AI-generated images in their investigative practices.
この講演では、実際の攻撃者の戦術や戦略を模倣したレッドチームを効果的に立ち上げ、実践し、継続的に改善していく方法を共有します。参加者は、レッドチームがどのように仮説に対してアプローチし、セキュリティ防御のギャップを特定し、意思決定を妨げる認知バイアスを克服するかを学びます。MITRE ATT&CKのようなフレームワークを活用し、明確な目的、スコープ、エンゲージメントルールを設定することで、レッドチームは組織のレジリエンスを高める貴重な洞察をもたらすることができます。また、信頼できるエージェントとの連携、業界標準の遵守、エンゲージメントを成功させるための役割分担の重要性についても説明し、最終的には組織の検知、対応、修復能力の向上を支援します。