homepage
Open menu
Contact Sales
Go one level top
  • Train and Certify
    Train and Certify

    Immediately apply the skills and techniques learned in SANS courses, ranges, and summits

    • Overview
    • Courses
      • Overview
      • Full Course List
      • By Focus Areas
        • Cloud Security
        • Cyber Defense
        • Cybersecurity and IT Essentials
        • DFIR
        • Industrial Control Systems
        • Offensive Operations
        • Management, Legal, and Audit
      • By Skill Levels
        • New to Cyber
        • Essentials
        • Advanced
        • Expert
      • Training Formats
        • OnDemand
        • In-Person
        • Live Online
      • Free Course Demos
    • Training Roadmaps
      • Skills Roadmap
      • Focus Area Job Roles
        • Cyber Defense Job Roles
        • Offensive Operations Job Roles
        • DFIR Job Roles
        • Cloud Job Roles
        • ICS Job Roles
        • Leadership Job Roles
      • NICE Framework
        • Security Provisionals
        • Operate and Maintain
        • Oversee and Govern
        • Protect and Defend
        • Analyze
        • Collect and Operate
        • Investigate
        • Industrial Control Systems
      • European Skills Framework
    • GIAC Certifications
    • Training Events & Summits
      • Events Overview
      • In-Person Event Locations
        • Asia
        • Australia & New Zealand
        • Latin America
        • Mainland Europe
        • Middle East & Africa
        • Scandinavia
        • United Kingdom & Ireland
        • United States & Canada
      • Live Online Events List
      • Summits
    • OnDemand
    • Get Started in Cyber
      • Overview
      • Degree and Certificate Programs
      • Scholarships
      • Free Training & Resources
    • Cyber Ranges
  • Enterprise Solutions
    Manage Your Team

    Build a world-class cyber team with our workforce development programs

    • Overview
    • Group Purchasing
    • Build Your Team
      • Assessments
      • Private Training
      • By Industry
        • Health Care
        • Industrial Control Systems Security
        • Military
    • Leadership Training
      • Leadership Courses
      • Executive Cybersecurity Exercises
  • Security Awareness
    Security Awareness

    Increase your staff’s cyber awareness, help them change their behaviors, and reduce your organizational risk

    • Overview
    • Products & Services
      • Security Awareness Training
        • EndUser Training
        • Phishing Platform
      • Specialized
        • Developer Training
        • ICS Engineer Training
        • NERC CIP Training
        • IT Administrator
      • Risk Assessments
        • Knowledge Assessment
        • Culture Assessment
        • Behavioral Risk Assessment
    • OUCH! Newsletter
    • Career Development
      • Overview
      • Training & Courses
      • Professional Credential
    • Blog
    • Partners
    • Reports & Case Studies
  • Resources
    Resources

    Enhance your skills with access to thousands of free resources, 150+ instructor-developed tools, and the latest cybersecurity news and analysis

    • Overview
    • Webcasts
      • Webinars
      • Live Streams
        • Wait Just An Infosec
        • Cybersecurity Leadership
        • SANS Threat Analysis Rundown (STAR)
    • Free Cybersecurity Events
      • Free Events Overview
      • Summits
      • Solutions Forums
      • Community Nights
    • Content
      • Newsletters
        • NewsBites
        • @RISK
        • OUCH! Newsletter
      • Blog
      • Podcasts
        • Blueprint
        • Trust Me, I'm Certified
        • Cloud Ace
        • Wait Just an Infosec
      • Summit Presentations
      • Posters & Cheat Sheets
    • Internet Storm Center
    • Research
      • White Papers
      • Security Policies
    • Tools
    • Focus Areas
      • Cyber Defense
      • Cloud Security
      • Digital Forensics & Incident Response
      • Industrial Control Systems
      • Cyber Security Leadership
      • Offensive Operations
      • Open-Source Intelligence (OSINT)
  • Get Involved
    Get Involved

    Help keep the cyber community one step ahead of threats. Join the SANS community or begin your journey of becoming a SANS Certified Instructor today.

    • Overview
    • Join the Community
    • Work Study
    • Teach for SANS
    • CISO Network
    • Partnerships
    • Sponsorship Opportunities
  • About
    About

    Learn more about how SANS empowers and educates current and future cybersecurity practitioners with knowledge and skills

    • SANS
      • Overview
      • Our Founder
      • Awards
    • Instructors
      • Our Instructors
      • Full Instructor List
    • Mission
      • Our Mission
      • Diversity
      • Scholarships
    • Contact
      • Contact Customer Service
      • Contact Sales
      • Press & Media Enquiries
    • Frequent Asked Questions
    • Customer Reviews
    • Press
    • Careers
  • Contact Sales
  • SANS Sites
    • Australia
    • Brazil
    • France
    • India
    • Japan
    • Middle East & Africa
    • United Kingdom
  • Search
  • Log In
  • Join
    • Account Dashboard
    • Log Out
  1. Home >
  2. Blog >
  3. SANS Top 10 Most Popular Free Resources
SANS_social_88x82.jpg
SANS Institute

SANS Top 10 Most Popular Free Resources

We’ve compiled a list of the most-popular Free Resources created by SANS Faculty and team in 2021. Keep current, elevate your knowledge, and earn CPEs

December 14, 2021

024feb4f-feb8-46dc-b024-17d3484d7ad2.jpg


We’ve compiled a list of the most-popular Free Resources created by SANS Faculty and team in 2021. Keep current, elevate your knowledge, and earn CPEs with the best free resources in cybersecurity.

20f07b40-c854-44b8-a833-b72fd33fe7c6.png


 
Top 10 Webcasts

  1. Ransomware - Do You Pay It Or Not? - Experts debate the costs and ethics surrounding ransomware payments—Ryan Chapman, Matthew Toussain, Jake Williams & James Shank
  2. Out in the Wild: How OSINT Supports Proactive Defense—Jackie Abrams
  3. Pen Testing API Security in the Web & Cloud—Mohammed Aldoub
  4. Unpacking the Hype—What You Can (and Can’t) Do to Prevent/Detect Software Supply Chain Attacks—Jake Williams
  5. Using Marketplaces for Valuable OSINT Data—Jake Creps
  6. What Did Solarwinds Teach Us? Preventing Office 365 and Connected Cloud Attacks—Sundaram Lakshmanan & Matt Hines
  7. Creating Resiliency in Third Party Risk Management—Art Coviello, Robert Herjavec & Nicole Rowe
  8. Contextualizing the MITRE ATT&CK® Framework—Matt Bromiley & Avihai Ben-Yossef
  9. Burp Suite Cheat Sheet & Tips and Tricks—Chris Dale
  10. Cryptography – “The Encryption and Password Hashing Recipe (with a little salt).”—Bryan Simon



6b90eb16-611f-4831-a22b-ff3556d192ca.png


Top 10 Blogs

  1. CIS Controls v8
  2. The Ultimate List of SANS Cheat Sheets
  3. Getting Started in Cybersecurity with a Non-Technical Background
  4. Must-Have Free Resources for Open-Source Intelligence (OSINT)
  5. How you can start learning malware analysis
  6. What you need to know about the SolarWinds Supply Chain Attack
  7. Time for password Expiration to Die
  8. Intro to Report Writing for Digital Forensics
  9. A Step-by-step Intro to using the autopsy forensic browser
  10. Forensics 101 – Acquiring an image with FTK image

CyberTalent-Icons-Personal-Brand-1.png


 Top 10 Open-Source Tools

  1. SIFT Workstation VM Appliance
  2. EZ Tools
  3. Slingshot Community Edition
  4. SOF-ELK®
  5. The Pyramid of Pain
  6. REMnux®
  7. Risk Definitions
  8. NIST CSF+
  9. Human Metrics Matrix
  10. Timeline Explorer

thumb.PNG


    e80f3b6d-b0d7-4495-861a-a6491135adc4.png


    Top 10 Summit Videos 

    1. Keynote: Cobalt Strike Threat Hunting Chad Tilbury, Senior Instructor, SANS Institute
    2. Simplifying and Demystifying Security in the Cloud Jerich Beason, Chief Information Security Officer, Epiq
    3. Keynote: Understanding the Effectiveness of Exploit Mitigations for Purple Teams Stephen Sims, Fellow, SANS Institute, Fellow, SANS Institute
    4. Threat Intel for Everyone: Writing Like A Journalist To Produce Clear, Concise Reports Selena Larson, Cyber Threat Analyst
    5. Landing a Job: Resumes & The Application Process Lesley Carhart, Principal Threat Analyst, Dragos Lesley Carhart, Principal Threat Analyst, Dragos
    6. A River Runs Through IT: What Whitewater Rafting Taught Me About Incident Response Stef Rand, Incident Response Consultant, FireEye/Mandiant
    7. Killing Time (ICS Summit) Tim Conway, Certified Instructor, SANS Institute & Jeff Shearer, Instructor, SANS Institute
    8. Keynote: OSINT Efficiency: Extending & Building Tools Chris Poulter, CEO, OSINT Combine
    9. Kubernetes Goat – Interactive Kubernetes Security Learning Playground Madhu Akula, Security Engineer, Miro
    10. ICS Security Summit 2021 Keynote Anne Neuberger, Deputy Assistant to the President and Deputy National Security Advisor for Cyber and Emerging Technology on the National Security Council

    thumb1.PNG


    SANS Virtual Summits will continue to be FREE to the global community in 2022!
    Be sure to check out the latest Summit listing and get registered, or to opt in to be notified as registration opens for your favorite Summits in 2022.

    e94a59cc-bac4-465d-b384-6ec191aad133.png


    Top 10 Whitepapers

    1. How to Integrate Security into the DevOps Pipeline in AWS—Dave Shackleford
    2. Making Revolutionary Gains in Security on Your Endpoints—John Pescatore
    3. 2021 Ransomware Case Study: Identifying High Priority Security Controls for Public Institutions—Anthony Luna
    4. Data First: Defending Your Organization from Within—Matt Bromiley
    5. Combating Insider Threats with People, Processes, and AI-Based Technology—Heather Mahalik
    6. Maximizing Security Value Through External Attack Surface Management—Jake Williams
    7. Cities of the Future: Smart with Secure Infrastructure—Dean Parsons
    8. Understanding Your Attack Surface—Matt Bromiley
    9. Password Management and Two-Factor Authentication Methods Survey—Chris Dale
    10. End-to-End Security Operations Management in a SOAR Platform—Chris Crowley


    If your 2022 plans include doubling down on your training goals, learning new cybersecurity skills, leveling up in your career, and earning CPEs, make sure to check out sans.org/free for all the latest free resources for the community!

    "The more SANS content I consume, the more I see thoroughness and thoughtfulness that I've not seen in other technical trainings." - Laura F., U of MN

    Share:
    TwitterLinkedInFacebook
    Copy url Url was copied to clipboard
    Subscribe to SANS Newsletters
    Receive curated news, vulnerabilities, & security awareness tips
    United States
    Canada
    United Kingdom
    Spain
    Belgium
    Denmark
    Norway
    Netherlands
    Australia
    India
    Japan
    Singapore
    Afghanistan
    Aland Islands
    Albania
    Algeria
    American Samoa
    Andorra
    Angola
    Anguilla
    Antarctica
    Antigua and Barbuda
    Argentina
    Armenia
    Aruba
    Austria
    Azerbaijan
    Bahamas
    Bahrain
    Bangladesh
    Barbados
    Belarus
    Belize
    Benin
    Bermuda
    Bhutan
    Bolivia
    Bonaire, Sint Eustatius, and Saba
    Bosnia And Herzegovina
    Botswana
    Bouvet Island
    Brazil
    British Indian Ocean Territory
    Brunei Darussalam
    Bulgaria
    Burkina Faso
    Burundi
    Cambodia
    Cameroon
    Cape Verde
    Cayman Islands
    Central African Republic
    Chad
    Chile
    China
    Christmas Island
    Cocos (Keeling) Islands
    Colombia
    Comoros
    Cook Islands
    Costa Rica
    Croatia (Local Name: Hrvatska)
    Curacao
    Cyprus
    Czech Republic
    Democratic Republic of the Congo
    Djibouti
    Dominica
    Dominican Republic
    East Timor
    Ecuador
    Egypt
    El Salvador
    Equatorial Guinea
    Eritrea
    Estonia
    Ethiopia
    Falkland Islands (Malvinas)
    Faroe Islands
    Fiji
    Finland
    France
    French Guiana
    French Polynesia
    French Southern Territories
    Gabon
    Gambia
    Georgia
    Germany
    Ghana
    Gibraltar
    Greece
    Greenland
    Grenada
    Guadeloupe
    Guam
    Guatemala
    Guernsey
    Guinea
    Guinea-Bissau
    Guyana
    Haiti
    Heard And McDonald Islands
    Honduras
    Hong Kong
    Hungary
    Iceland
    Indonesia
    Iraq
    Ireland
    Isle of Man
    Israel
    Italy
    Jamaica
    Jersey
    Jordan
    Kazakhstan
    Kenya
    Kiribati
    Korea, Republic Of
    Kosovo
    Kuwait
    Kyrgyzstan
    Lao People's Democratic Republic
    Latvia
    Lebanon
    Lesotho
    Liberia
    Liechtenstein
    Lithuania
    Luxembourg
    Macau
    Macedonia
    Madagascar
    Malawi
    Malaysia
    Maldives
    Mali
    Malta
    Marshall Islands
    Martinique
    Mauritania
    Mauritius
    Mayotte
    Mexico
    Micronesia, Federated States Of
    Moldova, Republic Of
    Monaco
    Mongolia
    Montenegro
    Montserrat
    Morocco
    Mozambique
    Myanmar
    Namibia
    Nauru
    Nepal
    Netherlands Antilles
    New Caledonia
    New Zealand
    Nicaragua
    Niger
    Nigeria
    Niue
    Norfolk Island
    Northern Mariana Islands
    Oman
    Pakistan
    Palau
    Palestine
    Panama
    Papua New Guinea
    Paraguay
    Peru
    Philippines
    Pitcairn
    Poland
    Portugal
    Puerto Rico
    Qatar
    Reunion
    Romania
    Russian Federation
    Rwanda
    Saint Bartholemy
    Saint Kitts And Nevis
    Saint Lucia
    Saint Martin
    Saint Vincent And The Grenadines
    Samoa
    San Marino
    Sao Tome And Principe
    Saudi Arabia
    Senegal
    Serbia
    Seychelles
    Sierra Leone
    Sint Maarten
    Slovakia
    Slovenia
    Solomon Islands
    South Africa
    South Georgia and the South Sandwich Islands
    South Sudan
    Sri Lanka
    St. Helena
    St. Pierre And Miquelon
    Suriname
    Svalbard And Jan Mayen Islands
    Swaziland
    Sweden
    Switzerland
    Taiwan
    Tajikistan
    Tanzania
    Thailand
    Togo
    Tokelau
    Tonga
    Trinidad And Tobago
    Tunisia
    Turkey
    Turkmenistan
    Turks And Caicos Islands
    Tuvalu
    Uganda
    Ukraine
    United Arab Emirates
    United States Minor Outlying Islands
    Uruguay
    Uzbekistan
    Vanuatu
    Vatican City
    Venezuela
    Vietnam
    Virgin Islands (British)
    Virgin Islands (U.S.)
    Wallis And Futuna Islands
    Western Sahara
    Yemen
    Yugoslavia
    Zambia
    Zimbabwe

    By providing this information, you agree to the processing of your personal data by SANS as described in our Privacy Policy.

    This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

    Recommended Training

    • SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking
    • SEC505: Securing Windows and PowerShell Automation
    • SEC555: SIEM with Tactical Analytics

    Tags:
    • Cybersecurity Insights

    Related Content

    Blog
    Blog: Defending Against Ransomware in ICS
    Cybersecurity Insights, Digital Forensics, Incident Response & Threat Hunting, Industrial Control Systems Security
    August 30, 2023
    Defending Against Ransomware in Industrial Control Systems
    Leveraging ICS612 and the SANS Five Critical Cybersecurity Controls
    Mike_Hoffman_-_Headshot_-_370x370.png
    Mike Hoffman
    read more
    Blog
    Blog_-_The_SEC’s_New_Cybersecurity_Regulations_-_340x340_Thumb.jpg
    Cybersecurity Insights
    July 31, 2023
    Moving Beyond Tech: The SEC’s New Cybersecurity Regulations and the Need for Comprehensive Training
    These new regulations reinforce a crucial tenet that we at SANS have long embraced: Effective cybersecurity starts with skilled people first.
    370x370_john-pescatore.jpg
    John Pescatore
    read more
    Blog
    Cybersecurity Insights
    March 9, 2021
    The Ultimate List of SANS Cheat Sheets
    Need help cutting through the noise? SANS has a massive list of Cheat Sheets available for quick reference.
    SANS_social_88x82.jpg
    SANS Institute
    read more
    • Register to Learn
    • Courses
    • Certifications
    • Degree Programs
    • Cyber Ranges
    • Job Tools
    • Security Policy Project
    • Posters & Cheat Sheets
    • White Papers
    • Focus Areas
    • Cyber Defense
    • Cloud Security
    • Cybersecurity Leadership
    • Digital Forensics
    • Industrial Control Systems
    • Offensive Operations
    Subscribe to SANS Newsletters
    Receive curated news, vulnerabilities, & security awareness tips
    United States
    Canada
    United Kingdom
    Spain
    Belgium
    Denmark
    Norway
    Netherlands
    Australia
    India
    Japan
    Singapore
    Afghanistan
    Aland Islands
    Albania
    Algeria
    American Samoa
    Andorra
    Angola
    Anguilla
    Antarctica
    Antigua and Barbuda
    Argentina
    Armenia
    Aruba
    Austria
    Azerbaijan
    Bahamas
    Bahrain
    Bangladesh
    Barbados
    Belarus
    Belize
    Benin
    Bermuda
    Bhutan
    Bolivia
    Bonaire, Sint Eustatius, and Saba
    Bosnia And Herzegovina
    Botswana
    Bouvet Island
    Brazil
    British Indian Ocean Territory
    Brunei Darussalam
    Bulgaria
    Burkina Faso
    Burundi
    Cambodia
    Cameroon
    Cape Verde
    Cayman Islands
    Central African Republic
    Chad
    Chile
    China
    Christmas Island
    Cocos (Keeling) Islands
    Colombia
    Comoros
    Cook Islands
    Costa Rica
    Croatia (Local Name: Hrvatska)
    Curacao
    Cyprus
    Czech Republic
    Democratic Republic of the Congo
    Djibouti
    Dominica
    Dominican Republic
    East Timor
    Ecuador
    Egypt
    El Salvador
    Equatorial Guinea
    Eritrea
    Estonia
    Ethiopia
    Falkland Islands (Malvinas)
    Faroe Islands
    Fiji
    Finland
    France
    French Guiana
    French Polynesia
    French Southern Territories
    Gabon
    Gambia
    Georgia
    Germany
    Ghana
    Gibraltar
    Greece
    Greenland
    Grenada
    Guadeloupe
    Guam
    Guatemala
    Guernsey
    Guinea
    Guinea-Bissau
    Guyana
    Haiti
    Heard And McDonald Islands
    Honduras
    Hong Kong
    Hungary
    Iceland
    Indonesia
    Iraq
    Ireland
    Isle of Man
    Israel
    Italy
    Jamaica
    Jersey
    Jordan
    Kazakhstan
    Kenya
    Kiribati
    Korea, Republic Of
    Kosovo
    Kuwait
    Kyrgyzstan
    Lao People's Democratic Republic
    Latvia
    Lebanon
    Lesotho
    Liberia
    Liechtenstein
    Lithuania
    Luxembourg
    Macau
    Macedonia
    Madagascar
    Malawi
    Malaysia
    Maldives
    Mali
    Malta
    Marshall Islands
    Martinique
    Mauritania
    Mauritius
    Mayotte
    Mexico
    Micronesia, Federated States Of
    Moldova, Republic Of
    Monaco
    Mongolia
    Montenegro
    Montserrat
    Morocco
    Mozambique
    Myanmar
    Namibia
    Nauru
    Nepal
    Netherlands Antilles
    New Caledonia
    New Zealand
    Nicaragua
    Niger
    Nigeria
    Niue
    Norfolk Island
    Northern Mariana Islands
    Oman
    Pakistan
    Palau
    Palestine
    Panama
    Papua New Guinea
    Paraguay
    Peru
    Philippines
    Pitcairn
    Poland
    Portugal
    Puerto Rico
    Qatar
    Reunion
    Romania
    Russian Federation
    Rwanda
    Saint Bartholemy
    Saint Kitts And Nevis
    Saint Lucia
    Saint Martin
    Saint Vincent And The Grenadines
    Samoa
    San Marino
    Sao Tome And Principe
    Saudi Arabia
    Senegal
    Serbia
    Seychelles
    Sierra Leone
    Sint Maarten
    Slovakia
    Slovenia
    Solomon Islands
    South Africa
    South Georgia and the South Sandwich Islands
    South Sudan
    Sri Lanka
    St. Helena
    St. Pierre And Miquelon
    Suriname
    Svalbard And Jan Mayen Islands
    Swaziland
    Sweden
    Switzerland
    Taiwan
    Tajikistan
    Tanzania
    Thailand
    Togo
    Tokelau
    Tonga
    Trinidad And Tobago
    Tunisia
    Turkey
    Turkmenistan
    Turks And Caicos Islands
    Tuvalu
    Uganda
    Ukraine
    United Arab Emirates
    United States Minor Outlying Islands
    Uruguay
    Uzbekistan
    Vanuatu
    Vatican City
    Venezuela
    Vietnam
    Virgin Islands (British)
    Virgin Islands (U.S.)
    Wallis And Futuna Islands
    Western Sahara
    Yemen
    Yugoslavia
    Zambia
    Zimbabwe

    By providing this information, you agree to the processing of your personal data by SANS as described in our Privacy Policy.

    This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
    • © 2023 SANS™ Institute
    • Privacy Policy
    • Terms and Conditions
    • Do Not Sell/Share My Personal Information
    • Contact
    • Careers
    • Twitter
    • Facebook
    • Youtube
    • LinkedIn