the most trusted source for computer security training, certification and research


select a course
Global Information Assurance Certification

Wow! It's an incident handler's Christmas morning, tools, tools, tools. Very Applicable!
-Todd Davis, Symantec

SECURITY 504

Hacker Techniques, Exploits & Incident Handling

6 CPE Credits per day

NOTE: Includes access to the Virtual Training Lab


If your organization has an Internet connection or one or two disgruntled employees (and whose doesn't!), your computer systems will get attacked. From the five, ten, or even one hundred daily probes against your Internet infrastructure to the malicious insider slowly creeping through your most vital information assets, attackers are targeting your systems with increasing viciousness and stealth.

By helping you understand attackers' tactics and strategies in detail, giving you hands-on experience in finding vulnerabilities and discovering intrusions, and equipping you with a comprehensive incident handling plan, the in-depth information in this course helps you turn the tables on computer attackers. This course addresses the latest cutting-edge insidious attack vectors and the "oldie-but-goodie" attacks that are still so prevalent, and everything in between. Instead of merely teaching a few hack attack tricks, this course includes a time-tested, step-by-step process for responding to computer incidents; a detailed description of how attackers undermine systems so you can prepare, detect, and respond to them; and a hands-on workshop for discovering holes before the bad guys do. Additionally, the course explores the legal issues associated with responding to computer attacks, including employee monitoring, working with law enforcement, and handling evidence.

This challenging course is particularly well suited to individuals who lead or are a part of an incident handling team. Furthermore, general security practitioners, system administrators, and security architects will benefit by understanding how to design, build, and operate their systems to prevent, detect, and respond to attacks.

It is imperative that you get written permission from the proper authority in your organization before using these tools and techniques on your company's system and also that you advise your network and computer operations teams of your testing.

  • Who Should Attend
    • Members and leaders of incident handling teams
    • System administrators and security personnel
    • Ethical hackers/penetration testers who want to understand the concepts underlying their testing regimen
  • A Sampling of Topics
    • The step-by-step approach used by many computer attackers
    • The latest computer attack vectors and how you can stop them
    • Proactive and reactive defenses for each stage of a computer attack
    • Hands-on workshop addressing scanning for, exploiting, and defending systems
    • Strategies and tools for detecting each type of attack
    • Attacks and defenses for Windows, Unix, switches, routers and other systems
    • Application-level vulnerabilities, attacks, and defenses
    • Developing an incident handling process and preparing a team for battle
    • Legal issues in incident handling
    • Recovering from computer attacks and restoring systems for business
Author Statement

My favorite part of teaching the Hacker Techniques, Exploits, and Incident Handling track is watching students when they finally get it. It's usually a two-stage process. First, students begin to realize how truly malicious some of these attacks are. Some students have a very visceral reaction, occasionally shouting out Oh, shoot! when they see what the bad guys are really up to. But if I stopped the process at that point, I'd be doing a disservice. The second stage is even more fun. Later in the class, students gradually realize that, even though the attacks are really nasty, they can prevent, detect, and respond to them. Using the knowledge they gain in this track, they know they'll be ready when a bad guy launches an attack against their systems. And being ready to thwart the bad guys is what its all about.
- Ed Skoudis

SECURITY 504 :: Hacker Techniques, Exploits and Incident Handling
SANS 2009 Orlando, FL March 02, 2009 - March 09, 2009
SANS Security East 2009 New Orleans, LA May 04, 2009 - May 12, 2009
SANS Cyber Defense Initiative 2008 Washington, DC December 10, 2008 - December 16, 2008
SANS Security West 2009 Las Vegas, NV January 24, 2009 - February 01, 2009
Community SANS Columbus Winter 2008 Columbus, OH December 01, 2008 - December 06, 2008
Community SANS Edmonton 2009 Edmonton , AB February 23, 2009 - February 28, 2009
Community SANS Harrisburg 2009 Harrisburg , PA April 20, 2009 - April 25, 2009
Community SANS Tucson 2008 Tucson, AZ December 08, 2008 - December 13, 2008
SANS London 2008 London, United Kingdom December 01, 2008 - December 09, 2008
SANS Phoenix 2009 Phoenix, AZ March 23, 2009 - March 30, 2009
Mentor Session - Security 504 Denver, CO January 15, 2009 - March 19, 2009
Mentor Session - Security 504 Minneapolis, MN December 02, 2008 - January 17, 2009
SANS Tysons Corner 2009 Tysons Corner, VA April 14, 2009 - April 22, 2009
Mentor Session - Security 504 New York City, NY December 02, 2008 - February 17, 2009
SANS Dublin 2009 Dublin, Ireland March 09, 2009 - March 14, 2009
Community SANS Charleston 2009 Charleston, SC March 16, 2009 - March 21, 2009
Mentor Session - Security 504 Dallas, TX January 13, 2009 - March 17, 2009
SANS Calgary 2009 Calgary, AB April 14, 2009 - April 19, 2009
Mentor Session - Security 504 Murrysville, PA January 27, 2009 - March 31, 2009
Mentor Session - Security 504 Princeton, NJ January 13, 2009 - March 17, 2009
EU Mentor Session - Security 504 Paris, France January 22, 2009 - March 26, 2009
Mentor Session - Security 504 Sydney, Australia January 21, 2009 - March 25, 2009
Mentor Session - Security 504 Garden City, NY January 07, 2009 - March 04, 2009
Community SANS Ft. Lauderdale 2009 Ft. Lauderdale, FL January 19, 2009 - January 24, 2009
Community SANS Montreal Montreal, QC March 09, 2009 - March 14, 2009
Mentor Session - Security 504 Lima, Peru May 02, 2009 - June 06, 2009
Mentor Session - Security 504 San Diego, CA December 09, 2008 - February 24, 2009
Mentor Session - Security 504 Willoughby Hills, OH January 10, 2009 - March 24, 2009
SANS Process Control & SCADA Security Summit 2009 Lake Buena Vista, FL February 01, 2009 - February 09, 2009
Community SANS Ann Arbor 2009 Ann Arbor, MI January 19, 2009 - January 24, 2009
Mentor Session - Security 504 Ottawa, ON February 10, 2009 - April 14, 2009
Mentor Session - Security 401 Phoenix, AZ February 17, 2009 - April 21, 2009
Mentor Session - Security 504 Boise, ID April 21, 2009 - May 21, 2009
Mentor Session - Security 504 Portland, OR March 10, 2009 - May 12, 2009
SANS Secure Europe 2009 - Amsterdam Amsterdam, Netherlands May 11, 2009 - May 23, 2009
SANS@Home - Security 504 - Skoudis/Strand Webcast Classroom Training, VA May 05, 2009 - June 11, 2009
SANS@Home - Security 504 - Skoudis/Strand Webcast Classroom Training, VA November 03, 2009 - December 10, 2009
SANS OnDemand Online Training & Assessments Anytime
SANS SelfStudy Books and .MP3s Only Anytime