select a course
San Diego, CA - May 8 - 14, 2009
Global Information Assurance Certification
I have 14 years experience in IT security, and SANS is by far the best technical security conferences I have attended.
-Tom Davis, Indiana University
Security 517


(Portal Account Required)

For GIAC STAR
If you register for the full course, you may register to seek your STAR .
Online exam issued with 4-month deadline 7-10 days following conference.
Additional information:
STAR Information
GIAC FAQ
Fee Information
For OnDemand Bundles
You can bundle SANS OnDemand online training and assessment package for an additional $99.00 US when registering for the full course. Additional information can be found at the OnDemand Bundles page and the OnDemand FAQ.
Computer attackers continue their relentless march in improving their tools and techniques. The simple scanning of yesteryear has given way to powerful suites of bundled, automated scanning and exploitation tools. Straightforward backdoors have evolved into powerful kernel-mode RootKits, manipulating the very hearts of our systems. Covert channels exfiltrate sensitive information and hash collision attacks are rapidly advancing, with your systems in the cross hairs. In all of these trends, thorough reconnaissance and deep subterfuge dominate the attackers' game.
If we don't keep up with their latest methods, our overall defenses and incident response practices will grow rusty. To help fight back, this action-packed one-day course describes these latest attack trends and what you can do to thwart the bad guys. In addition to detailed descriptions of how the attacks function, you'll get hands-on experience with the tools and their defenses.
This fast-paced, intermediate-to-advanced course is ideal for students who have taken a multi-day hacking course in the past (offered by other training organizations or SANS' own 504 or 560 courses) and are looking to update their understanding and skills. Also, if you are preparing for that final push on your GCIH certification, this session can help you brush up and refresh your knowledge of computer attacks before taking the exam.
- Who Should Attend This Course
- Managers and professionals who have taken a multi-day hacking course seeking to update their understanding and skills
- Professionals preparing for the GCIH or GPEN certification
- Sampling of Topics
- Metasploit modules, including the Meterpreter and Priv – hands on
- New Google search techniques for finding vulnerable systems
- Cross-Site Scripting attacks to steal sensitive information – hands on
- IPS Fingerprinting
- Virtual Machine Detection, the possibility of VM Escape and what it means to you – hands on
- Recent user-mode and kernel-mode RootKits for Windows and UNIX, including Hacker Defender and Nushu
- Hash collisions and their implications with Stripwire and Confoo – hands on
- Late-breaking Nmap features – hands on
- Techniques attackers use to steal a million credit cards and how to stop them
This is critical to any business to protect sensitive data.
-Melissa Black, Lockheed Martin