Group Purchasing
Group Purchasing
MAJOR UPDATES

SEC501: Applied Cyber Defense

SEC501Cyber Defense
  • 6 Days (Instructor-Led)
  • 38 Hours (Self-Paced)
Course authored by:
Ross BergmanDave Shackleford
Ross Bergman & Dave Shackleford
SEC501: Advanced Security Essentials - Enterprise Defender
Course authored by:
Ross BergmanDave Shackleford
Ross Bergman & Dave Shackleford
  • GIAC Certified Enterprise Defender (GCED)
  • 38 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 26 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Attackers move across cloud platforms, SaaS providers, and AI agents faster than logging can keep up. Learn to scope, contain, and act using incomplete evidence.

Course Overview

One enterprise investigation connects visibility, detection, hardening, incident response, and malware analysis. More than 25 integrated labs require you to follow suspicious activity through records held by systems and providers. You use these records to establish scope, test controls, and decide whether escalation, containment, or recovery is justified.

What You’ll Learn

  • Correlate records held by different systems, teams, and service providers.
  • Recover the sequence of suspicious activity from network and host records.
  • Build and test detections against the traffic they are expected to identify.
  • Validate which exposed services can extend access before assigning remediation priority.
  • Establish scope before containment disrupts systems or accounts outside it.
  • Use malware behavior and program logic to improve detection, scoping, and recovery.
  • Check AI-assisted analysis and agent actions against primary records.

Business Takeaways

  • Reduce the cost of premature escalation by requiring corroborating records.
  • Limit disruption by matching containment to the systems and accounts in scope.
  • Give responders timely access to records held by providers and authority to act.
  • Require tested corrections when controls fail to record or restrict activity.
  • Identify missing records and short retention periods before they delay an investigation.
  • Remove persistence and compromised access before systems return to service.
  • Limit risk from automated actions by verifying authority and the resulting system change.

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC501: Applied Cyber Defense.

Section 1Seeing Like a Defender

A persistent anomaly begins with records of network availability, privileged access, and DNS activity that do not establish a common cause. Compare what network devices generate with what receiving systems retain, then test how device time, administrative access, network trust, and decoy activity affect a later investigation.

Topics covered

  • Persistent anomaly and enterprise records
  • Network device baselines and audit evidence
  • Syslog, time integrity, and record retention
  • Authentication, authorization, and accounting (AAA)
  • Domain Name System decoys and active defense

Labs

  • Establish a defensible baseline and measure the effect of each change
  • Determine whether timestamp differences make records unsafe to correlate
  • Compare local and centralized records of administrative access
  • Verify that untrusted network peers are rejected and recorded
  • Create low-noise signals that support targeted investigation

Section 2Detecting Like a Defender

Trace an alert to the packet, protocol record, flow data, or host event that produced it. Reconstruct suspicious activity, test detection logic against captured traffic, and determine whether the combined records justify escalation or a change in incident scope.

Topics covered

  • Security operations and alert triage
  • Packet analysis and network forensics
  • Zeek, flow data, and network visibility
  • Suricata detection development
  • SIEM correlation and security analytics

Labs

  • Isolate the traffic needed to test an alert
  • Reassemble suspicious network activity and recover transferred files
  • Test whether a detection identifies the behavior it targets
  • Correlate authentication and flow records before changing incident scope

Section 3Hardening Like a Defender

Find the systems and services that respond now, compare them with the inventory, and validate which exposures can extend access. Test how credentials and command-and-control channels cross expected boundaries, then verify a controlled configuration change against each managed system.

Topics covered

  • Asset, service, and identity discovery
  • Vulnerability assessment and exploit validation
  • Credential exposure and remote administrative access
  • Command and control, segmentation, and reachability
  • Configuration drift and controlled automation

Labs

  • Reconcile the asset inventory with services that respond on the network
  • Validate whether a scanner finding provides usable access
  • Determine whether exposed credentials extend administrative access
  • Test whether network records expose command-and-control activity
  • Preview a controlled change and verify it on each managed system

Section 4Responding Like a Defender

Incident response begins before every record is available and often before scope is established. Recover host artifacts, test the claims in a handoff, reconstruct ransomware activity, and decide which systems or accounts require collection, containment, or recovery.

Topics covered

  • Incident response thresholds and authority
  • Filesystem recovery and Windows artifacts
  • AI-assisted handoff review
  • Timeline analysis and incident scoping
  • Containment, eradication, and recovery

Labs

  • • Recover deleted files and preserve the records that explain their origin
  • Use Windows artifacts to connect prior activity with a user or system
  • Check every handoff claim against the artifact it cites
  • Narrow the ransomware window and reconstruct the sequence of activity
  • Use network records to identify systems requiring further examination

Section 5Understanding Malware Like a Defender

Connect a suspicious file with the incident around it. Use file properties, host changes, network requests, and program logic to refine detection and scope, identify failed controls, and make containment and recovery decisions that the available records support across the enterprise.

Topics covered

  • Malware triage and static properties analysis
  • Host behavior and persistence
  • Network dependencies and controlled interaction
  • Code review and manual reversing
  • Enterprise detection and response implications

Labs

  • Develop detection leads before running a suspicious file
  • Identify the host changes that distinguish execution from download
  • Test how network responses change the specimen's behavior
  • Confirm encryption and file-selection logic through code review

Section 6Operating Like a Defender

The final Applied Cyber Defense capstone draws on all five technical sections through independent challenges. Working individually or with a team, you must recover exact answers from the available artifacts and decide which challenge warrants the next block of time.

Things You Need To Know

Relevant Job Roles

Protection

SCyWF: Protection And Defense

This role uses cybersecurity tools to protect information, systems and networks from cyber threats. Find the SANS courses that map to the Protection SCyWF Work Role.

Explore learning path

Vulnerability Assessment Analyst (DCWF 541)

DoD 8140: Cybersecurity

Assesses systems and networks to ensure compliance with policies and identify vulnerabilities in support of secure and resilient operations.

Explore learning path

Network Operations (OPM 441)

NICE: Implementation and Operation

Responsible for planning, implementing, and operating network services and systems, including hardware and virtual environments.

Explore learning path

Network Operations Specialist (DCWF 441)

DoD 8140: Cyber IT

Implements and maintains network services, including hardware and virtual systems, ensuring operational support for infrastructure platforms.

Explore learning path

Defense

SCyWF: Protection And Defense

This role uses monitoring and analysis tools to identify and analyze events and to detect incidents. Find the SANS courses that map to the Defense SCyWF Work Role.

Explore learning path

Cybersecurity Instruction (OPM 712)

NICE: Oversight and Governance

Responsible for developing and conducting cybersecurity awareness, training, or education.

Explore learning path

Information Security (SCTY)

Skills Framework for the Information Age

Implementation and oversight of security measures to protect organisational data, systems, and operations. Responsibilities include risk assessments, policy enforcement, and compliance with regulatory standards.

Explore learning path

Security Operations (SCAD)

Skills Framework for the Information Age

Monitoring and response to security incidents in live environments. Analysts detect anomalies, triage alerts, and coordinate defensive actions to maintain organisational security posture.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $8,780 USD*Prices exclude applicable local taxesBuy now for access on Aug 31. Use code Presale10 for 10% off course price!
    Registration Options
  • Location & instructor

    SANS Virginia Beach 2026

    Virginia Beach, VA, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Live Online Europe October 2026

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €8,230 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Dallas 2026

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
Showing 4 of 4

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources