Group Purchasing
Group Purchasing

SEC673: Advanced Information Security Automation with Python

SEC673Cyber Defense
  • 6 Days (Instructor-Led)
  • 36 Hours (Self-Paced)
Course authored by:
Mark Baggett
Mark Baggett
SEC673: Advanced Information Security Automation with Python
Course authored by:
Mark Baggett
Mark Baggett
  • 36 CPEs

    Apply your credits to renew your certifications

  • Self-paced

    Train at your own pace from wherever you are

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 27 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Dive into advanced Python coding techniques from top open-source security tools and empower yourself to build secure, scalable solutions across a wide range of high-demand fields.

Course Overview

SEC673 is designed for those who want to use Python for cybersecurity. It teaches advanced skills to build scalable, efficient, and maintainable cybersecurity tools. Students will explore programming techniques used in top open-source security projects, covering topics like multi-threading, logging, unit testing, decorators, and object-oriented coding. Through hands-on labs and the pyWars server, students will refine their skills by solving real-world challenges while learning best practices for secure and optimized Python development.

Enhanced Python Security Automation: Building Scalable and Reliable Tools

In today's rapidly evolving digital landscape, information security professionals face increasingly complex challenges. Threats are more sophisticated, attack surfaces are expanding, and the volume of data requiring protection is exploding. Those who lack the ability to code are finding themselves ill-equipped to navigate this intricate terrain. Manual processes, outdated tools, and a reliance on others for development are no longer sufficient. To effectively secure systems and data, coding proficiency, especially in a versatile language like Python, has become essential. Without it, even seasoned security professionals are not prepared to embrace the full scope of modern cybersecurity challenges.

This skills gap is precisely what we address. Our advanced Python for Cybersecurity program empowers experienced security professionals to enhance their expertise and take control of their security posture. This isn't just about learning a new language; it's about gaining the ability to build, automate, and adapt—essential skills for staying ahead of the curve in an increasingly sophisticated threat landscape.

Our approach centers on practical, hands-on experience. Through dedicated labs and our enhanced pyWars platform, you'll immerse yourself in the techniques used by leading open-source security projects. You won't just study theoretical concepts; you'll apply them in real-world scenarios, developing projects like the SPF100 and building a portfolio of demonstrable skills.

This immersive experience covers crucial areas:

  • Package Development: Learn to create reusable modules that streamline security tasks and promote collaboration within advanced security teams.
  • Custom Object Creation: Tailor solutions to your specific, complex needs by creating custom objects that represent the unique elements of your advanced security environment.
  • Multi-Processing Optimization: Maximize the efficiency of your security tools by leveraging multi-processing to handle complex tasks and massive datasets.
  • Secure Coding Practices: Embed security into the very foundation of your code, minimizing vulnerabilities and building robust defenses from the ground up.
  • Python's versatility makes it invaluable across the spectrum of advanced cybersecurity functions:
  • Threat Detection and Analysis: Develop automated systems to identify and analyze potential threats in real-time, leveraging Python's powerful data processing capabilities for sophisticated threat analysis.
  • Vulnerability Scanning and Penetration Testing: Build custom tools to probe systems for weaknesses, simulating real-world attacks to proactively identify and patch vulnerabilities in complex enterprise environments.
  • Incident Response and Forensics: Automate the collection of evidence, analyze logs, and accelerate incident response with Python scripts, minimizing the impact of security breaches in critical systems.
  • Malware Analysis: Gain the skills to dissect malicious code, understand its behavior, and develop effective countermeasures, enhancing your ability to defend against evolving malware threats.
  • Security Automation: Automate repetitive tasks, freeing up valuable time and resources to focus on more strategic security initiatives and advanced threat hunting.

The World Economic Forum's list of fastest-growing jobs between now and 2030 underscores the importance of these skills, with 8 of the 15 positions requiring or significantly benefiting from Python proficiency. This highlights not only the demand for coding skills in cybersecurity but also the broader applicability of Python across industries.

Our program is designed for experienced professionals looking to enhance their skillset and stay at the forefront of the cybersecurity field. The emphasis on hands-on labs ensures that you not only learn Python but master it in the context of real-world security challenges. You'll leave with the practical experience and confidence to tackle the ever-evolving landscape of cyber threats. Don't be left behind in the face of increasing complexity. Embrace the power of Python and equip yourself with the skills needed to secure the digital future.

This course is designed for those who have completed SEC573 (Automating Information Security with Python) or possess a foundational understanding of Python programming. SEC673 dives into advanced concepts, exploring coding techniques used in prominent open-source security tools and applying them to your own Python cybersecurity projects.

Learn from the best. Over the week, you'll enhance your project, SPF100, to match the development ease and maintainability of top-tier cybersecurity projects. Discover how to structure your code and leverage advanced programming principles for faster, more efficient, and easily maintainable applications.

This course teaches you to develop custom classes for information security applications, covering:

  • Distributing and updating your tools effortlessly: Learn to package your code for easy installation using Package Installer for Python (PIP).
  • Accelerated development with custom data structures: Build specialized data structures optimized for your specific needs.
  • Simplified code using advanced Python features: Leverage decorators, generators, and context managers to write cleaner and more efficient code.
  • Boosting performance with concurrency: Master multi-threading and multi-processing to make your programs run faster.
  • Preventing cascading errors with unit testing: Implement unit tests to catch issues early and ensure small changes don't lead to major problems.
  • Effective logging for debugging: Learn proper log generation and handling to quickly identify and resolve errors.
  • Automation for increased efficiency: Automate tasks and interactions to free up time for more critical work.
  • Identify and mitigate common Python vulnerabilities: Learn to recognize and address security weaknesses often found in Python code.

Like SEC573, this course emphasizes hands-on labs using the enhanced pyWars server. This unique environment not only checks your code for correctness but also evaluates your problem-solving approach, guiding you towards writing maintainable code by enforcing the use of advanced features. Complex challenges are broken down into manageable segments, allowing you to focus on mastering new skills without feeling overwhelmed.

SEC673 is ideal for those who understand basic Python and can create simple security tools but are ready to enhance their productivity and build better, more robust applications.

Author Statement

"I've been overwhelmed by the popularity of the SEC573 course and the excitement about it. The most common feedback I get is 'We want MORE pyWars!' SEC673 is the answer to that call. And here's a bonus: What if while you are having all of that fun playing pyWars I could teach you to make applications run faster with multi-processing and multi-threading? What if you learned object-oriented coding, unit testing, how to have properly configured logging in your applications, and more? Well, that would be an awesome course.

The pyWars server has all-new capabilities that go beyond measuring whether or not you got the correct answer. Now it can assess the quality of the programs you are writing. I can feed you partially completed applications and have you complete the code to satisfy the learning objectives. You will go from writing simple modules and single file scripts to writing more complex and better organized Python packages. If you are ready to take your coding skills to the next level, come check out SEC673."

- Mark Baggett

What You’ll Learn

  • Design PIP-installable security packages
  • Create custom objects for security applications
  • Implement multi-threading for enhanced performance
  • Develop comprehensive logging and testing systems
  • Build automated CLI security tool interfaces
  • Deploy efficient error handling mechanisms

Business Takeaways

  • Improve efficiency by producing faster, more maintainable code
  • Optimize performance with multi-threading and better data structure
  • Strengthen security practices with secure coding
  • Automate workflows and reduce manual work
  • Align with top industry best practices
  • Improve software reliability with enhanced logging and error handling
  • Develop in-house expertise, boosting retention and innovation

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC673: Advanced Information Security Automation with Python.

Section 1Python Package Essentials

Dive into advanced Python development practices through hands-on experience with pyWars. Learn professional package development techniques, from creating deployable packages to managing complex import structures and implementing comprehensive unit testing.

Topics covered

  • Virtual Environment
  • Using an IDE
  • Unit Testing
  • Building Packages

Labs

  • Build a complete PIP-installable security package
  • Implement unit tests for security functions
  • Configure virtual environments for development
  • Resolve complex import dependencies

Overview

The first course section jumps straight into pyWars. SEC573 alumni will quickly learn the new features and how they will be used in SEC673, while veteran coders who come straight to this course will be introduced to this amazing learning platform. You'll learn how developers use unit tests to evaluate their programs during the development process and prevent small changes in core function from having cascading affects in your applications. We'll deep dive into the Python package structure, and you'll learn how setup.py can be used to build a deployable package and how to handle common structural errors such as circular references.

Full Topic Details

  • Virtual Environment
  • Using an IDE
  • Unit Testing
  • Building Packages
  • PIP Installable Package
  • Understanding Package Imports
  • Absolute vs. Relative Imports
  • Circular References

Section 2Python Objects

Develop the Security Professionals Friend 100 (SPF100) project while learning advanced object-oriented programming concepts. Create specialized data structures for cybersecurity applications and learn to extend built-in Python objects for security-specific functionality.

Topics covered

  • Argument Packing
  • Objects
  • Inheritance Super
  • Inheriting and Extending Built-in Objects

Labs

  • Create custom security data structures
  • Extend built-in Python objects
  • Implement inheritance in security tools
  • Build flexible argument handling systems

Overview

This course section will teach you to develop custom Python objects and data structures to support the needs of modern cybersecurity projects. We will build a model cybersecurity project called the Security Professionals Friend 100 (SPF100) that incorporates features found in popular cybersecurity packages such as Scapy and Volatility. You'll see how the right data structure can make your applications much easier to use and speed the development process. The section starts with a discussion on argument packing, unpacking, and how to pass arguments on to other functions. That discussion will set you up for success when we move into the principles of object-oriented coding and object inheritance, followed by a comprehensive discussion on object classes, scope, and inheritance that focuses on the real-world application of objects in modern Python projects. You'll learn to take advantage of existing data structure and extend build in object types like lists, integers, and dictionaries. Imagine having a data structure perfectly suited for your application, and then building it! Your code will be much cleaner and easier to support. You will learn how the magic dunder methods work and when to modify them in your programs. Finally, you'll learn how to use slicing in your own data types so you can pull the data you want from them.

Full Topic Details

  • Argument Packing
  • Objects
  • Inheritance Super
  • Inheriting and Extending Built-in Objects
  • The Magic Dunders
  • Slicing

Section 3Python Objects (continued)

Enhance SPF100 with advanced object manipulation techniques. Learn secure attribute handling, custom object behaviors, and advanced error management while implementing network packet processing capabilities.

Topics covered

  • Attribute Access
  • Executable Attributes
  • Name Mangling
  • Attribute Privacy

Labs

  • Develop secure attribute access controls
  • Implement custom object iterators
  • Create network packet processors
  • Build advanced exception handlers

Overview

In this section we continue adding new features to SPF100 that make Python objects more versatile. You'll learn how to customize the behavior of objects when accessing their attributes, and how to resolve attribute naming conflicts by using name mangling. We will discuss attribute privacy, the security pitfalls associated with any developer trying to protect object attributes, and how to exploit them. This section will provide you with a firm understanding of how to perform error handling in your projects. We'll complete the session by adding custom iterators to our project that can process network packets in interesting ways.

Full Topic Details

  • Attribute Access
  • Executable Attributes
  • Name Mangling
  • Attribute Privacy
  • Object Comparison Operations
  • Advanced Exception Handling
  • Object Iteration
  • Object Instantiation

Section 4Advanced Concepts

Address real-world cybersecurity challenges through practical programming solutions. Learn critical skills in timestamp processing, concurrent operations, and secure serialization while implementing industry-standard security tool features.

Topics covered

  • Dataclasses and NamedTuples
  • Timestamps and Time Zones
  • Concurrency

Labs

  • Build multi-threaded security scanners
  • Implement secure serialization systems
  • Create timezone-aware security tools
  • Develop context managers for security apps

Overview

Knowing how to code is only part of the battle. When it comes to solving real-world cybersecurity problems, a bit more is required. Show us an information security professional who doesn't hate working with timestamps and time zones and we'll show you an information security professional who has never had to deal with timestamps and time zones. In this course section you will learn how to properly process and handle timestamps and solve problems that require knowledge of multiple time zones. You will learn how and when to use multi-processing and multi-threading to spread out the load and handle large amounts of data. We will continue to build on SPF100 and leverage Python features such as context managers in order to make the package as user-friendly as it is in other popular cybersecurity projects.

Full Topic Details

  • Dataclasses and NamedTuples
  • Timestamps and Time Zones
  • Concurrency
  • Multi-threading
  • Multi-processing
  • Serialization Attack and Mitigation
  • Context Managers

Section 5Advanced Concepts (continued)

Learn advanced automation techniques for security tools while focusing on proper logging and security vulnerability prevention. Implement powerful code modifications using decorators and explore Python-specific security concerns.

Topics covered

  • CLI Tool Automation
  • Logging
  • Decorators
  • Python Attacks

Labs

  • Automate interactive security tools
  • Implement comprehensive logging systems
  • Create security-focused decorators
  • Identify and prevent Python vulnerabilities

Overview

This course section will examine some of the most common struggles developers face when designing cyber tools. We will discuss how to automate command line tools that require interaction. This goes far beyond just running the program and capturing the output. We will talk about the ability to fully automate and interact with any command line. Next, we will add the ability to generate logs. You'll learn how to control the logs for other modules and configure applications so that you are alerted when critical events take place. We'll show you how you can use decorators to quickly add functionality to existing code with minimal changes to those programs. You will learn how to develop your own powerful decorators to improve any code base. We'll wrap up our discussion with a look at more security vulnerabilities that affect the Python interpreter and commonly used functions.

Section 6Capture-the-Flag Challenge

Apply advanced Python security programming skills in a series of real-world challenges. Demonstrate proficiency in custom object development, decorator implementation, and other advanced concepts through hands-on security scenarios.

Labs

  • Exploit vulnerable systems
  • Develop custom security objects
  • Create specialized security decorators
  • Build comprehensive security tools

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class.
  • CRITICAL: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot in any way be used for this course.
  • BIOS settings must be set to enable virtualization technology, such as "Intel-VTx" or "AMD-V" extensions. Be absolutely certain you can access your BIOS if it is password protected, in case changes are necessary.
  • 8GB of RAM or more is required.
  • 15GB of free storage space or more is required.
  • At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration And Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 10.15.x or newer.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Local Administrator Access is required. (Yes, this is absolutely required. Don't let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • You should ensure that antivirus or endpoint protection software is disabled, fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system and these products can prevent you from accomplishing the labs.
  • Any filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls should be disabled or you must have the administrative privileges to disable it.
  • Download and install VMware Workstation Pro 16.2.X+ or VMware Player 16.2.X+ (for Windows 10 hosts), VMware Workstation Pro 17.0.0+ or VMware Player 17.0.0+ (for Windows 11 hosts), or VMWare Fusion Pro 12.2+ or VMware Fusion Player 11.5+ (for macOS hosts) prior to class beginning. If you do not own a licensed copy of VMware Workstation Pro or VMware Fusion Pro, you can download a free 30-day trial copy from VMware. VMware will send you a time-limited serial number if you register for the trial at their website. Also note that VMware Workstation Player offers fewer features than VMware Workstation Pro. For those with Windows host systems, Workstation Pro is recommended for a more seamless student experience.
  • On Windows hosts, VMware products might not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are contained in the setup documentation that accompanies your course materials.
  • Download and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts). These tools are also included in your downloaded course materials.

Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.

If you have additional questions about the laptop specifications, please contact customer service.

SEC673 training is recommended for a diverse range of individuals, including:

  • Security professionals who know how to code in Python and are ready to take their coding skills to the next level
  • Tool developers who want to be able to publish installable and easy-to-use Python packages
  • Network defenders who want to be able to extend the capability of popular Python packages to create new detection capabilities
  • Security professionals who need their tools to run faster by adding multi-processing and multi-threading capabilities

  • A USB containing a virtual machine filled with sample code and working examples
  • MP3 audio files of the complete course lecture

This course teaches advanced Python coding skills. You are not required to have taken SEC573: Automating Information Security with Python, but there will be an assumption that you understand all of the skills taught in the class. Those skills include using built-in data types, for loops, while loops, Bytes, UTF-8, File IO, regular expressions, Scapy, and basic exception handling as well as writing functions and developing a single file module.

SEC673 is part of the Cyber Defense curriculum. It’s an Advanced defense course focused on arming you with the skills to harder specific defenses. Other Advanced Defense courses include SEC595, which covers Applied Data Science, and SEC566, which covers the CIS Controls.

Python is one of the most widely used programming languages in cybersecurity due to its simplicity, flexibility, and extensive libraries. It enables security professionals to automate tasks, analyze data, develop security tools, and even exploit vulnerabilities in ethical hacking scenarios.

Python is essential for cybersecurity for a number of reasons:

  • Automation – Speeds up tasks like log analysis, network scanning, and malware detection.
  • Penetration Testing – Helps ethical hackers develop custom scripts for exploits.
  • Forensic Analysis – Extracts and analyzes data from logs, memory, and disk images.
  • Threat Intelligence – Collects and processes security threat data.
  • Reverse Engineering – Decompiles and analyzes malware behavior.

SEC673: Advanced Information Security Automation with Python is designed for cybersecurity professionals looking to enhance their skills in security automation, threat analysis, and offensive security. Here’s how this course can benefit your career:

  • Automate Security Tasks – Save time, reduce errors, and improve efficiency.
  • Enhance Offensive Security – Build custom penetration testing and red teaming tools.
  • Strengthen Threat Detection – Automate malware analysis, log review, and threat hunting.
  • Boost Career Prospects – Python automation skills are in high demand.
  • Advance to Senior Roles – Gain expertise for roles like Security Engineer and Threat Hunter.

Relevant Job Roles

Data Analysis (OPM 422)

NICE: Implementation and Operation

Responsible for analyzing data from multiple disparate sources to provide cybersecurity and privacy insight. Designs and implements custom algorithms, workflow processes, and layouts for complex, enterprise-scale data sets used for modeling, data mining, and research purposes.

Explore learning path

Technology Research and Development (OPM 661)

NICE: Design and Development

Responsible for conducting software and systems engineering and software systems research to develop new capabilities with fully integrated cybersecurity. Conducts comprehensive technology research to evaluate potential vulnerabilities in cyberspace systems.

Explore learning path

Malware Analyst

Digital Forensics and Incident Response

Malware analysts face attackers’ capabilities head-on, ensuring the fastest and most effective response to and containment of a cyber-attack. You look deep inside malicious software to understand the nature of the threat – how it got in, what flaw it exploited, and what it has done, is trying to do, or has the potential to achieve.

Explore learning path

Digital Forensic Analyst Training, Salary, and Career Path

Digital Forensics and Incident Response

This expert applies digital forensic skills to a plethora of media that encompass an investigation. The practice of being a digital forensic examiner requires several skill sets, including evidence collection, computer, smartphone, cloud, and network forensics, and an investigative mindset. These experts analyze compromised systems or digital media involved in an investigation that can be used to determine what really happened. Digital media contain footprints that physical forensic data and the crime scene may not include.

Explore learning path

Digital Forensics (OPM 212)

NICE: Protection and Defense

Responsible for analyzing digital evidence from computer security incidents to derive useful information in support of system and network vulnerability mitigation.

Explore learning path

Military Operations / Law Enforcement Agents

Digital Forensics and Incident Response

Execute digital forensic operations under demanding conditions, rapidly extracting critical intelligence from diverse devices. Leverage advanced threat hunting and malware analysis skills to neutralize sophisticated cyber adversaries.

Explore learning path

Media Exploitation Analyst

Digital Forensics and Incident Response

This expert applies digital forensic skills to a plethora of media that encompasses an investigation. If investigating computer crime excites you, and you want to make a career of recovering file systems that have been hacked, damaged or used in a crime, this may be the path for you. In this position, you will assist in the forensic examinations of computers and media from a variety of sources, in view of developing forensically sound evidence.

Explore learning path

Intrusion Detection/SOC Analysts

Digital Forensics and Incident Response

Analyze network and endpoint data to swiftly detect threats, conduct forensic investigations, and proactively hunt adversaries across diverse platforms including cloud, mobile, and enterprise systems.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
Showing 1 of 1

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources