Group Purchasing
Group Purchasing

SEC555: Detection Engineering and SIEM Analytics

SEC555Cyber Defense
  • 5 Days (Instructor-Led)
  • 30 Hours (Self-Paced)
Course authored by:
Nick Mitropoulos
Nick Mitropoulos
SEC555: SIEM with Tactical Analytics
Course authored by:
Nick Mitropoulos
Nick Mitropoulos
  • GIAC Certified Detection Analyst (GCDA)
  • 30 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 18 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Gain hands-on skills in Detection Engineering and SIEM, learning the processes for understanding logs, enhancing existing logging solutions, and creating detection content that fits your needs.

Course Overview

SEC555: Detection Engineering and SIEM Analytics is a hands-on detection engineering training course that teaches students how to design proactive detection strategies and effectively manage SIEM platforms. Through real-world labs and in-depth analysis, participants learn to interpret logs, craft high-quality detection rules, and uncover hidden threats in both cloud and on-premises environments. Whether you're new to detection engineering or looking to sharpen your skills, this course prepares you to extract meaningful insights from complex data and build a more responsive, intelligence-driven Security Operations Center (SOC). It also serves as a valuable preparation path for the GCDA certification (GIAC Certified Detection Analyst), which validates advanced capabilities in detection engineering and data-driven defense.

Download the Detection Engineering poster for a visual walkthrough of the Detection Engineering Life Cycle in action.

Master the Art of Cyber Defense with Detection Engineering and SIEM Analytics

In a world where cyber threats grow more sophisticated by the day, organizations need skilled defenders who can stay one step ahead. This course is your gateway to mastering Detection Engineering—the craft of designing proactive defenses—and SIEM, the core of modern threat detection and response. Whether you're a Security Analyst looking to upskill or a Detection Analyst looking to upskill, you'll gain the hands-on expertise to detect and investigate attacks. SEC555 is designed to provide students with training, methods, and processes for enhancing existing logging solutions and promote creation of healthy detection rules to enable proactive monitoring. The course is closely aligned with the skills tested in the GCDA certification, making it ideal for professionals seeking to validate and advance their expertise in this space.

Uncover the Secrets Hidden in the Logs

This course dives deep into the "when, what, and why" behind logs, teaching you how to craft precise detection rules, fine-tune SIEM configurations, and analyze real-world scenarios to expose hidden threats, in both on-premises and cloud environments. You'll master the art of building automated alerts, leveraging data analytics, and understanding adversarial tactics to defend against sophisticated attacks. Security operations today aren’t facing a "Big Data" problem, but a "Data Analysis" conundrum, and this course equips you to extract actionable insights from vast amounts of data.

Through hands-on learning, you'll demystify SIEM architecture and its integration into a fully operational Security Operations Center (SOC). You'll explore how to tailor and manage SIEM platforms effectively, enriching enterprise log data to uncover critical intelligence for crafting powerful detections.

Hands-On Detection Engineering Training

The hands-on portion of SEC555 is uniquely tailored to give the students a problem-solving perspective by investigating logs from real incidents, using both on-premises and cloud-based tools. In addition, students will get an opportunity to use tools for automating detection lab deployment, recording incidents and use cases and perform use testing.

Syllabus Summary

  • Section 1: Detection Engineering and SIEM Architecture
  • Section 2: Network and Endpoint Analytics
  • Section 3: Asset Discovery, Baselines and UEBA
  • Section 4: Cloud Logging and Monitoring
  • Section 5: Alerting and Detection Engineering Pipelines

Author Statement

Working in security for over two decades, you begin to see the core challenge Security Operations teams are facing: it's not just about tools or processes—it's about mindset. The reactive nature of our industry keeps us a step behind adversaries, focusing too heavily on post-intrusion actions. The truth is simple: While prevention is ideal, detection is essential. SEC555 is designed to transform how you approach detection by teaching you to build a foundation for optimizing your logging and SIEM capabilities. By doing so, you'll shift from reactive firefighting to proactive threat visibility, enabling you to detect and respond to threats before they escalate. It’s about turning the tables and taking control of your environment early, rather than scrambling to implement use cases after an attack has already occurred.

This course is crafted to empower security professionals to not only master the technical intricacies of SIEM tools and detection frameworks but also to understand their broader business implications. By focusing on practical, hands-on learning, participants will gain actionable skills to identify, investigate, and mitigate threats effectively while aligning their efforts with organizational objectives.

From log analysis to leveraging frameworks like MITRE ATT&CK, this course integrates industry best practices and real-world scenarios to ensure relevance in today’s dynamic threat landscape. Whether you’re a seasoned SOC analyst, a security architect, or a threat hunter, this course equips you with the knowledge and tools to design scalable, efficient, and impactful detection systems. My hope is that every participant leaves not only with enhanced technical expertise but also with a deeper appreciation of how their role contributes to safeguarding their organization in an ever-evolving digital world.

-Nick Mitropoulos

What You’ll Learn

  • Build and configure your own detection lab environment
  • Write detection rules to identify adversary behaviors
  • Optimize SIEM architecture for better performance and visibility
  • Perform adversary emulation and analyze related log activity
  • Evaluate security controls using real log data
  • Manage and filter high-volume data from diverse sources
  • Gain expertise in SIEM tools (on-prem and cloud), MITRE ATT&CK mapping, SOAR integration, and detection tracking

Business Takeaways

  • Identify and mitigate threats in near real-time to reduce business risk
  • Evaluate vendors effectively to select the right security partners
  • Prioritize threats based on asset importance and business impact
  • Build a reliable asset database to monitor critical systems
  • Align detection engineering with operational goals
  • Improve alert precision to reduce fatigue and boost efficiency
  • Support collaboration across IT, security, and compliance teams using detection insights

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC555: Detection Engineering and SIEM Analytics.

Section 1Detection Engineering and SIEM Architecture

Section one builds a strong foundation in Detection Engineering and SIEM, covering core concepts, best practices, and modern logging techniques. It prepares students to analyze logs effectively and create agile, scalable detection systems for today’s threat landscape.

Topics covered

  • SIEM Introduction
  • Detection Engineering Life Cycle and SIEM Planning
  • Creating a Detection Lab
  • Log Collection and Enrichment
  • Log Aggregation, Parsing, and Analysis

Labs

  • DeTTECT and Data Source Gap Analysis
  • Luring the Attacker with a Honeypot
  • Introduction to SIEM Components
  • Detecting SSH Brute Force Attacks and Using Wazuh MCP

Overview

Logging and analysis are the foundation of modern cyber defense, enabling both rapid response to threats and proactive identification of adversarial activities. When implemented effectively, they serve as the backbone of agile detection, providing deep visibility into the environment and empowering security teams to stay ahead of attackers. Over the years, logging tools and analysis techniques have evolved significantly, offering enhanced capabilities that are critical for modern detection strategies. This section dives into effective tools and cutting-edge techniques for making sense of logs and elevating traditional logging approaches to meet today’s complex security challenges.

Day one sets the stage by equipping all participants with a solid understanding of Detection Engineering and SIEM fundamentals. It establishes a strong baseline, ensuring students are prepared to engage with advanced concepts throughout the course. Additionally, this foundational day focuses on creating a detection lab and providing an overview of SIEM best practices, laying the groundwork for building efficient and effective detection systems that align with industry-leading methodologies.

Full Lab Details

  • SIEM Introduction
    • Industry statistics and challenges
    • Why we need a SIEM
    • Log volume and EPS considerations
  • Detection Engineering Life Cycle & SIEM Planning
    • What are the goals of Detection Engineering
    • MITRE DeTTECT
    • Detection Engineering Life Cycle
  • Choosing an MSSP
    • Creating a Detection Lab
    • Detection lab on premises vs on the cloud
    • Vulnerable machines and required tools
    • Adding Honeypots
    • Automating Deployment of cloud labs
  • Case Management
    • Adding alert data in incident management tools
    • Examples of incident management and case recording tools
  • Log Collection and Enrichment
    • Agent vs agentless vs script log collection
    • What data should be used for enrichment
  • Log Aggregation, Parsing, and Analysis
    • Log aggregation
    • Data queueing
    • Using a message broker
    • Searching and alerting on ingested data

Section 2Network and Endpoint Analytics

This section covers how to collect and enrich logs from key protocols like DNS, SMTP, and HTTP/HTTPS. It also dives into endpoint logs for detecting malicious activity on Windows and Linux systems. Lastly, host-based firewalls and login events are also explored.

Topics covered

  • Network Analysis
  • Endpoint Analysis

Labs

  • Investigating DNS Logs
  • Investigating HTTP Logs
  • Investigating Windows Logs
  • Using auditd

Overview

The majority of network communication relies on a handful of key protocols, yet many organizations overlook the value of collecting and analyzing this data. We'll explore methods for gathering logs from services like DNS, SMTP and HTTP/HTTPS servers.

We will also explore endpoint logs, since they are a goldmine for detecting attacks, offering unparalleled visibility into post-compromise activities. When leveraged effectively, they can outshine other sources of detection. We will focus on the critical "why" and "how" of system log collection. You'll have an opportunity to explore various strategies designed to simplify the collection, filtering, and handling of the vast amount of data generated by servers and workstations.

Full Topic Details

  • Network Analysis
    • SMTP
      • Identify suspicious patterns on inbound/outbound emails
      • Fuzzy matching likely phishing domains
    • DNS
      • Finding new domains being accessed
      • Gathering additional information, such as domain age
      • Finding randomly named domains
      • Identifying reconnaissance
      • Finding DNS C2 channels
      • Detecting fast flux and DGA
    • HTTP/HTTPS
      • Use large datasets to find attacks
      • Identify automated activity vs user activity
      • Filter approved web clients vs unauthorized ones
      • Find HTTP C2 channels
      • Identify suspicious certificates
  • Endpoint Analysis
    • Windows Logs
      • Understanding structure and format
      • Methods of collection
      • Advanced audit policy
      • Adding additional logging (i.e. Sysmon)
    • Linux Logs
      • Common log files
      • Syslog and rsyslog
      • Auditd
    • Host-based firewalls and Login Events
      • Windows vs Linux firewalls
      • Windows vs Linux logins

Section 3Baselines and UEBA

This section focuses on methods for maintaining accurate asset inventories and identifying unauthorized devices. Students will learn to combine data sources for a clear network view and gain hands-on experience with baselining and anomaly detection to spot threats like C2 activity or suspicious behavior.

Topics covered

  • Asset Discovery
  • Application Monitoring and Scripting
  • Traffic Monitoring
  • User Monitoring and Baselining

Labs

  • Using inventory data for threat hunting
  • Identifying malicious PowerShell execution
  • Cobalt Strike beaconing detection
  • Detecting Linux credential attacks

Overview

“Know thyself” is a cornerstone of effective defense, yet one of the hardest strategies to achieve. Take, for example, something as seemingly simple as maintaining a complete inventory of all assets in your organization and identifying unauthorized devices on your network. While straightforward in theory, this task becomes daunting in today’s dynamic and ever-evolving networks.

This section tackles this challenge head-on, focusing on techniques to maintain an accurate list of assets, while distinguishing authorized from unauthorized devices. You’ll learn how to identify key data sources that provide high-fidelity information and combine multiple streams of data to create a comprehensive and actionable master inventory.

Beyond inventory, we’ll expand into other aspects of “knowing thyself.” You’ll gain hands-on experience with network and system baselining, learning to monitor network flows and detect anomalies like command-and-control (C2) beaconing or unusual user activity.

Full Lab Details

  • Active and Passive Asset Discovery
    • Vulnerability scanners
    • Network Access Control
    • DHCP
    • NetFlow
    • Connection monitoring
  • Application Monitoring and Scripting
    • Controlling what applications run
    • Software monitoring
    • Long tail analysis
    • PowerShell logging
  • Traffic Monitoring
    • NetFlow vs sFlow
    • Flow direction matters
    • Transfer sizes
    • Use of tagging
  • UEBA
    • Anomaly analysis
    • Establish user activity patterns
    • Create organizational baselines

Section 4Cloud Logging and Monitoring

This section focuses on building strong cloud visibility across platforms like AWS and Azure. Students will explore key log types, learn to detect attacker activity, and optimize configurations to close monitoring gaps—ensuring effective defense and rapid response in cloud environments.

Topics covered

  • Azure Cloud Logging
  • Microsoft Defender Suite and Copilot for Security
  • Microsoft Sentinel and KQL
  • AWS Cloud Logging

Labs

  • Logging Unauthorized Access to Sensitive Data
  • Defender for Cloud
  • Sentinel and KQL
  • Creating an AWS Lab
  • Configuring and Testing CloudWatch

Overview

As organizations increasingly migrate to the cloud, achieving comprehensive visibility across platforms has never been more critical. This section emphasizes the importance of cross-vendor expertise in configuring robust cloud monitoring to protect your environment. You’ll explore the various log types available, with a focus on those that can be leveraged to strengthen defenses and streamline incident response.

Through hands-on guidance, you’ll become familiar with the key logging tools in Microsoft Azure and AWS. You’ll also analyze how attackers attempt to bypass cloud security measures, uncovering the traces they leave in logs. Finally, you’ll learn how to optimize log configurations to ensure you capture critical events, leaving no gaps in your cloud monitoring strategy. This knowledge is essential to operationalize defenses and maintain a strong security posture in today’s cloud-driven world.

Full Lab Details

  • Azure Cloud Logging Identify Azure log sources Work with EntraID logs (activity, resource, sign-in and audit logs) NSG Flow log extraction Azure Monitor DCR (Data Collection Rules) and AMA (Azure Monitoring Agent)
  • Defender Suite and Copilot for Security
    • Defender for Cloud
      • Provisioning methods
      • Logic App configuration
      • Alert creation
    • Defender for Endpoint
      • Settings Overview
      • Troubleshooting
      • Using the Graph Security API
      • Using Graph Explorer
    • Defender XDR and Copilot Introduction
  • Microsoft Sentinel and KQL
    • Sentinel functions and architecture
    • Sentinel tables of interest
    • ASIM and normalization
    • Sentinel playbooks
    • KQL language and useful operators
  • AWS Cloud Logging
    • AWS log types and services
      • CloudTrail
      • CloudWatch
      • GuardDuty
      • Flow Log extraction

Section 5In-Depth Alerting, Post-Mortem Analysis, and Capstone Exercise

This section highlights how to centralize and correlate logs from diverse sources to enhance context and prioritization. It also covers building an automated detection engineering pipeline to streamline operations and speed up the creation of effective detections.

Topics covered

  • SIEM Alerting and Analysis
  • Post-mortem Analysis
  • Detection Engineering Pipelines
  • Defend-the-Flag Challenge

Labs

  • Sigma Operation
  • Using VirusTotal for Malware Detection and Removal

Overview

This section emphasizes the power of integrating security logs from multiple sources for centralized analysis. You’ll learn methods to combine and correlate data streams, adding valuable context that enables analysts to prioritize effectively. In addition, you will understand the importance of establishing and creating an automated detection engineering pipeline to streamline your operations and reduce delays when creating new detections.

Full Lab Details

  • SIEM Alerting and Analysis Define custom alerts
    • Fine tune alert thresholds
    • Work with Sigma
    • Investigating alerts
    • Case management
  • Post-mortem analysis and Detection Engineering Pipelines
    • Re-analyze network traffic
    • Identify malicious domains and IPs
    • Look for beaconing activity
    • Traditional vs automated detection engineering
    • CI/CD detection automation workflow
    • DaC (Detection as Code)
    • Using LLMs for assisted detection engineering
  • Defend-the-Flag Challenge - Hands-on Experience
    • The course culminates in a team-based design, detect, and defend the flag competition
    • Your team will progress through multiple levels and missions designed to ensure mastery of the modern cyber defense techniques promoted all week long. From building a logging architecture, augmenting logs, analyzing network logs and system logs, and developing dashboards to find attacks, this challenging exercise will reinforce key principles in a fun, hands-on, team-based challenge.

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class.
  • CRITICAL: Apple systems using the M1/M2 processor line cannot perform the necessary virtualization functionality and therefore cannot in any way be used for this course.
  • BIOS settings must be set to enable virtualization technology, such as "Intel-VTx" or "AMD-V" extensions. Be absolutely certain you can access your BIOS if it is password protected, in case changes are necessary.
  • 16GB of RAM or more is required.
  • 160GB of free storage space or more is required.
  • At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration And Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 10.15.x or newer.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Local Administrator Access is required. (Yes, this is absolutely required. Don't let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from accomplishing the labs.
  • Any filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls should be disabled or you must have the administrative privileges to disable it.
  • Download and install VMware Workstation Pro 16.2.X+ or VMware Player 16.2.X+ (for Windows 10 hosts), VMware Workstation Pro 17.0.0+ or VMware Player 17.0.0+ (for Windows 11 hosts), or VMWare Fusion Pro 12.2+ or VMware Fusion Player 11.5+ (for macOS hosts) prior to class beginning. If you do not own a licensed copy of VMware Workstation Pro or VMware Fusion Pro, you can download a free 30-day trial copy from VMware. VMware will send you a time-limited serial number if you register for the trial at their website. Also note that VMware Workstation Player offers fewer features than VMware Workstation Pro. For those with Windows host systems, Workstation Pro is recommended for a more seamless student experience.
  • On Windows hosts, VMware products might not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are contained in the setup documentation that accompanies your course materials.
  • Download and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts). These tools are also included in your downloaded course materials.

Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

If you have additional questions about the laptop specifications, please contact customer service.

SEC555 training is recommended for a diverse range of individuals, including:

  • Detection Engineer
  • Detection Analyst
  • Security Analyst
  • Security Engineer
  • Threat Hunter
  • Incident Handler/Responder
  • Security Architect
  • Security Monitoring Specialist
  • Cyber Threat Investigator
  • Penetration Tester

The GIAC Certified Detection Analyst (GCDA) certification validates a practitioners understanding of how to collect, analyze, and tactically use modern network, endpoint, and cloud data sources to detect malicious or unauthorized activity.

  • SIEM Fundamentals
  • Service Profiling, Advanced Endpoint Analytics, Baselining and User Behavior Monitoring
  • Cloud Logging Solutions in AWS and Azure, SIEM Solutions in Azure
  • Tactical SIEM Detection and Post-Mortem Analysis

More Certification Details

  • Printed and electronic courseware
  • Online Electronic Workbook for all lab exercises
  • ISO files with virtual machines necessary for executing the labs:
    • Windows Server 2022 VM
    • Slingshot VM
    • Ubuntu 24.04 VM

A basic understanding of:

  • TCP/IP
  • Logging methods and techniques
  • Overall operating system fundamentals

Nice-to-haves:

  • Logging systems experience (both network and host)
  • Command-line activity familiarization
  • Detection engineering and/or SIEM tool exposure

The SEC555 course is a part of the “Advanced Cyber Defense” Learning Path, which aims to train security professionals for platform-focused network monitoring. The SEC555 course is a part of the “Advanced Cyber Defense” Learning Path, which aims to train security professionals for platform-focused network monitoring.

Depending on your current or desired future role, one of these courses is a great next step in your cybersecurity journey:

Security Analyst/Intrusion Detection:

Security Engineer:

Cloud Security Analyst:

SOC Leadership

Detection engineering and SIEM analytics are key pillars of modern cybersecurity.

Detection engineering is the practice of proactively designing, implementing, and refining security measures to identify threats before they cause damage. It includes creating precise detection rules, optimizing how log data is collected and analyzed, and building systems that enhance visibility into potential attacks.

SIEM (Security Information and Event Management) analytics involves collecting, correlating, and analyzing log data from various sources to detect unusual patterns and support real-time threat response.

Together, these practices empower security teams to move from reactive to proactive defense. They allow organizations to uncover hidden threats, improve response times, and reduce business risk. In today’s fast-evolving threat landscape, detection engineering and SIEM analytics are essential for staying ahead of adversaries and protecting critical assets. Their integration is what enables the development of resilient, scalable, and intelligent security operations.

SEC555: Detection Engineering and SIEM Analytics can significantly benefit your cybersecurity career by enhancing your ability to identify and respond to security threats. It will deepen your understanding of how to configure and optimize SIEM systems to detect suspicious activities, ensuring that you can efficiently monitor and manage security incidents in real-time. The course will also teach you how to develop custom detection rules, correlate events, and analyze large volumes of security data.

Mastering these skills can help you play a pivotal role in an organization's security operations, proactively preventing breaches. It can also open up opportunities in threat hunting, incident response, and security operations centers (SOCs). With the growing importance of threat detection in cybersecurity, this expertise will make you a more valuable asset in securing modern IT environments.

Relevant Job Roles

Network Operations (OPM 441)

NICE: Implementation and Operation

Responsible for planning, implementing, and operating network services and systems, including hardware and virtual environments.

Explore learning path

Vulnerability Assessment

SCyWF: Protection And Defense

This role tests IT systems and networks and assesses their threats and vulnerabilities. Find the SANS courses that map to the Vulnerability Assessment SCyWF Work Role.

Explore learning path

Intrusion Detection/SOC Analysts

Digital Forensics and Incident Response

Analyze network and endpoint data to swiftly detect threats, conduct forensic investigations, and proactively hunt adversaries across diverse platforms including cloud, mobile, and enterprise systems.

Explore learning path

Blue Teamer - All Around Defender

Cyber Defense

This job, which may have varying titles depending on the organization, is often characterized by the breadth of tasks and knowledge required. The all-around defender and Blue Teamer is the person who may be a primary security contact for a small organization, and must deal with engineering and architecture, incident triage and response, security tool administration and more.

Explore learning path

Intrusion Detection / (SOC) Analyst

Cyber Defense

Security Operations Center (SOC) analysts work alongside security engineers and SOC managers to implement prevention, detection, monitoring, and active response. Working closely with incident response teams, a SOC analyst will address security issues when detected, quickly and effectively. With an eye for detail and anomalies, these analysts see things most others miss.

Explore learning path

Penetration Tester

European Cybersecurity Skills Framework

Assess the effectiveness of security controls, reveals and utilise cybersecurity vulnerabilities, assessing their criticality if exploited by threat actors.

Explore learning path

Cybersecurity Analyst/Engineer

Cyber Defense

As this is one of the highest-paid jobs in the field, the skills required to master the responsibilities involved are advanced. You must be highly competent in threat detection, threat analysis, and threat protection. This is a vital role in preserving the security and integrity of an organization’s data.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 11

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources