SEC504: Hacker Tools, Techniques, and Incident Handling

Unlock industry insights and hands-on learning with upcoming SANS webcasts and workshops. View archived webcasts here.
In the talk I will present the current ICS Threat Landscape and recommendations on how to prepare against ICS attacks.
In the 1990s, government agencies, industry groups, and cybersecurity researchers started creating cybersecurity standards, and these standards led to cybersecurity regulations and laws that dictate to organizations what they must do to protect their data.
The financial services industry continues to be a popular attack target, in large part due to the sensitive data and personal information financial institutions safeguard. These institutions are subjected to data scraping, credential stuffing, network intrusion attempts, and more — all while needing to provide fast, reliable service for their end-users and remain compliant with the strictest possible privacy and security regulations.
Organizations are becoming multicloud by choice or by chance. Many of them integrate their multiple clouds with one another to improve Availability, support Disaster Recovery, and leverage the services from each provider that best fits their needs.
Digital Forensics analysis of Apple devices other than iPhones and iPads: current possibilities and limits. Techniques to acquire Apple Watch, Apple TV and Apple HomePod will be discussed, as well as the analysis of extracted data with practical labs.
The ICS threat landscape has changed significantly in the last few years with the discovery of more ICS-specific scalable attack frameworks. In the 2023 SANS ICS/OT Cybersecurity Survey, Certified Instructor Jason Christopher will ask key questions and analyze answers to explore how critical infrastructure defenders across all sectors are constantly adapting to address new challenges and threats in ICS/OT security. Join us for this webcast event as we gather, analyze, and draw out the main takeaways from the 2023 SANS ICS/OT Cybersecurity Survey.
Have you ever wanted to understand how the tools and frameworks you are using during a Red Team engagement work under the hood?
Have you ever wondered about the security of your cloud environment and how to enhance the posture? In this session, we will guide you through the eight fundamental domains of cloud security in today's organizations.
The growth of anti-money laundering regulations and sanctions in today’s world means that organizations need to be able to protect themselves from risk. This webcast will look at open-source resources and techniques that investigators and risk professionals can use to help them in their work.
Love it or loathe it, the fact remains cybersecurity constantly changes. Adversary techniques evolve, and our cyber defenses must likewise.
Part 4 of this series will continue where Part 3 left off with the introduction of functions. For this part we will learn how how create functions that accept pointers as arguments, how to validate pointer arguments, SAL annotations, structures, and linked lists.
What the 2023 MITRE Test Means for YouA role-specific view of what to take awayAs the attack surface expands, and threat actors evolve the sophistication of their attacks, companies continue to explore ways to refine their threat protection and detection capabilities. MITRE Engenuity’s real-world tests examine the behavior of some of the most sophisticated of threats and the potential impact they can have on organizations around the world. Understanding this year’s test and its different phases is an important first step to putting it to good use. Join us for this panel discussion with Symantec’s Distinguished Engineer Mark Kennedy and SANS Analyst Matt Bromiley as they talk about how different members of the security team can use and apply the results of this important assessment. In this session, we will focus on the Security Administrator, the SOC team and the Forensics Analyst and what’s most important about the test to each. You will learn:How the needs of each security role is differentHow the scoring for each phase aligns with their prioritiesWhat each team member can take away from this year’s test.