Group Purchasing
Group Purchasing

SEC501 Major Update: Applied Cyber Defense for AI-Accelerated Attacks

Authored byRoss Bergman
Ross Bergman

Artificial intelligence (AI) is changing how quickly an enterprise attack can develop and how much of it can be automated. Google Threat Intelligence Group reported a zero-day it assesses was developed with AI, as well as malware that generates commands from the state of the affected system, and attacks against AI components that exposed AWS keys and GitHub tokens inside build environments. Anthropic has documented an agentic attack in which AI executed commands, exploited vulnerabilities, stole credentials, and made tactical decisions with limited human involvement.

AI-supported attacks add speed and autonomy to an enterprise threat landscape that already includes rapid access transfers, vulnerable edge devices, stolen software as a service (SaaS) sessions, compromised build components, and expanding third-party exposure. Mandiant reported a 22-second median handoff from initial access to a secondary threat group in 2025, while Verizon reported that vulnerability exploitation begins 31% of breaches. That same report found a third party involved in 48% of breaches, up 60% year over year. An intrusion may cross identity platforms, cloud workloads, SaaS applications, endpoints, network devices, build systems, and outside providers before a defender establishes its full scope.

SEC501: Applied Cyber Defense has undergone a major update for this environment. The rebuilt course prepares practitioners to become defenders their organizations can rely upon when an incident moves quickly, when records are incomplete, and when a mistaken action can disrupt critical operations. Students learn to increase confidence as independently sourced records are still arriving, to corroborate the activity and make an evidence-based decision without waiting for certainty the records may never provide.

For a one-page breakdown of every new lab and topic in this update, download the course flyer.

A Major Update Built Around the Defender

SEC501 has been transformed from five technical topic areas into one integrated course built around the defender. A single enterprise investigation now connects visibility, detection, hardening, incident response, and malware analysis.

As the investigation moves through each section, students collect new records, reconsider the confidence these records justify, and decide whether the response should change. They separate what a record shows from the explanation they infer and the decision they make. Confidence increases when independently sourced records corroborate the same activity. Students document missing or conflicting records before choosing a response action.

I have spent nearly four decades moving between hands-on technical work and leadership roles, and the hardest incidents crossed systems, teams, and providers. I designed SEC501 around the decisions defenders make while additional records are arriving. Students establish what the records support, document the uncertainty that remains, and choose an action they can justify to technical teams, leadership, and the people affected by it. - Ross Bergman

One Persistent Investigation Connects the Course

SEC501 opens with gateway failovers, voice-quality complaints, a privileged logon outside a change window, and DNS activity involving an unfamiliar domain. These observations may or may not be related, and no single one supports a confident conclusion.

Students revisit these observations as independently sourced records appear throughout the five technical sections. Some observations become part of supported incidents, while others remain separate or unresolved. By the end, each decision is matched to the available records, and unresolved questions are documented.

Network, endpoint, identity, cloud, and device records each provide a different view of the activity. Students decide whether these records describe one incident, separate incidents, or ordinary activity and whether the available records justify escalation, containment, or continued investigation.

Visibility and Detection Reframed Around the Records

Sections 1 and 2 now organize network infrastructure, centralized logging, packet analysis, security analytics, and detection technologies around the records a defender can retrieve during an investigation. Students determine which records each system creates, and whether the organization receives and retains them, before relying on them to establish a timeline, account, system, or action.

Students compare local device records with centralized logs, introduce a controlled time discrepancy, and examine DNS history, sinkholes, and decoys. A new Suricata lab connects alerts to packets, while other exercises use tcpdump, Wireshark, Zeek, and a security information and event management (SIEM) platform to follow activity from packets to alerts.

Coverage includes endpoint detection and response (EDR), network detection and response (NDR), extended detection and response (XDR), managed detection and response (MDR), SIEM, packet capture, and managed security service providers (MSSPs). The comparison focuses on which activity each method can record, where gaps remain, and who can retrieve or act on the data. Students also trace an incident into a build pipeline or an MSSP relationship and determine what records that provider is contractually obligated to hand over.

An Entirely New Section for Hardening Like a Defender

Section 3, Hardening Like a Defender, is the largest addition in this major update. Students begin with observed exposure and follow it through validation, correction, and records showing whether a control produced the intended result.

Students discover services that respond, compare exposure with inventory and business function, trace reachability between systems, and test segmentation. Identity protection extends beyond user passwords to OAuth grants, service accounts, AI agents, and cloud roles. When one of those identities belongs to an AI agent, students treat its changes as an investigation target, not an assumption, and check whether the change was authorized before accepting it as routine automation. Students connect each discovered exposure or configuration difference to an intended control and use the resulting records to verify whether the change worked.

New hands-on exercises use Hayabusa to analyze Windows event timelines after controlled exploitation, and Real Intelligence Threat Analytics (RITA) to examine command-and-control behavior in Zeek records. Ansible then lets students preview, apply, repeat, and verify an approved change across Windows and Linux systems.

Incident Response and Malware Analysis Connected to the Evidence

Section 4 now organizes incident response and forensics around decisions made while records are incomplete. Students establish scope, recover and interpret artifacts, narrow a ransomware encryption window and reconstruct its timeline, and choose proportionate containment and recovery actions while documenting who has authority to act. A new AI-assisted handoff exercise requires each material claim to be checked against the artifact it cites before the handoff can influence the next response decision.

Section 5 continues the course's established malware-analysis progression through automated analysis, static properties, controlled behavior, and code review. The ransomware investigation scoped in Section 4 continues here, connecting file-level findings back to the incident thread introduced in Section 1. Students use malware findings to refine earlier detection, scoping, hardening, response, and recovery decisions while keeping each conclusion tied to what the file and affected host can show.

Hands-On Practice Across the Course

SEC501 includes 26 hands-on labs supported by the SEC501 Electronic Workbook. Students generate records, test controls, and make decisions with the results. The exercises move through network devices, packet and event analysis, hardening, incident response, ransomware, and malware analysis as one connected practice.

The course concludes with a capstone of independent challenges drawing on every technical skill practiced throughout SEC501. Working individually or with a team, students recover exact answers from the available artifacts and decide which challenge is worth the next block of their time, the same judgment call they've been making since Section 1.

Why This Major SEC501 Update Is a Serious Training Investment

SEC501 is the entry point to the Cyber Defense curriculum for practitioners ready to connect technical work across systems, teams, and service providers. It serves security analysts moving into incident handling, security engineers, network and system administrators, digital forensics and incident response practitioners, and technical leads responsible for response decisions.

For management, the investment gives practitioners repeated practice establishing scope before broad containment, connecting a technical finding to business impact, testing whether a control produced the expected result, and explaining why escalation or another response action is justified. Students must tie each conclusion to the records they inspected, document missing records, and identify who is authorized to collect, contain, recover, or notify.

For technologists, SEC501 provides the breadth to follow an intrusion across network, endpoint, identity, cloud, build, and provider records while retaining enough technical depth to open the original records and test the controls involved. SEC501 also prepares students to pursue the GIAC Certified Enterprise Defender (GCED) certification. GCED validates the broad technical knowledge required to defend an enterprise environment and lets practitioners signal that capability to employers.

Become the Defender Your Enterprise Can Rely On

When the next enterprise incident arrives, time will be short, mistakes will be costly, and complete certainty may remain unavailable. My coauthor, Dave Shackleford, and I rebuilt SEC501 so students can become the defenders their organizations rely upon during a difficult incident. They will be ready to find the records, judge the confidence these records justify, choose a proportionate action, and explain the decision to technical teams and leadership.

Explore SEC501: Applied Cyber Defense and review upcoming course dates, or download the course flyer for a one-page breakdown of everything new in this update.