Group Purchasing
Group Purchasing
AI-FOCUSED

SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

SEC595Cyber Defense, Artificial Intelligence
  • 6 Days (Instructor-Led)
  • 36 Hours (Self-Paced)
Course authored by:
David Hoelzer
David Hoelzer
SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals
Course authored by:
David Hoelzer
David Hoelzer
  • GIAC Machine Learning Engineer (GMLE)
  • 36 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 30 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Acquire practical data science and machine learning skills to build custom AI-driven security solutions that transform your organization's threat detection capabilities.

Course Overview

Harness practical data science and machine learning in cybersecurity. This course transforms complex AI concepts into accessible tools through hands-on labs comprising over 70% of class time. Designed specifically to focus on machine learning in cybersecurity, the course prepares students to apply AI techniques to real-world security problems—making it a powerful option for those pursuing the GMLE certification (GIAC Machine Learning Engineer for Cybersecurity).

Participants solve actual security challenges using statistical models, probabilistic tools, and neural networks rather than engaging in theoretical discussions. You will develop skills to extract, analyze, and visualize security data, construct predictive models for threat detection, and implement anomaly detection systems.

The curriculum achieves an optimal balance between essential theory and practical application, requiring only intermediate Python skills and basic mathematics knowledge. Security professionals gain immediately applicable techniques for enhancing security operations, incident response, and threat hunting through targeted AI implementation.

Data-Driven Cybersecurity: Practical AI for Security Operations

Data Science, Artificial Intelligence, and Machine Learning aren't just the current buzzwords, they are fast becoming one of the primary tools in our information security arsenal. The problem is that, unless you have a degree in mathematics or data science, you're likely at the mercy of the vendors. This course completely demystifies machine learning and data science. More than 70% of the time in class is spent solving machine learning and data science problems hands-on rather than just talking about them. You will leave the class not only understanding how these tools and techniques work, but understanding how to think about your data, making it into something that you can apply machine learning and AI techniques to.

Unlike other courses in this space, this course is squarely centered on solving information security problems - in other words, applied rather than theoretical. Where other courses tend to be at the extremes, teaching almost all theory or solving trivial problems that don't translate into the real world, this course strikes a balance. While this course will cover necessary mathematics, we cover only the theory and fundamentals you absolutely must know, and only so as to allow you to understand and apply the machine learning tools and techniques effectively. We show you how the math works but don't expect you to do it. The course progressively introduces and applies various statistic, probabilistic, or mathematic tools (in their applied form), allowing you to leave with the ability to use those tools and to be able to troubleshoot your results since you have developed strong intuitions about the underlying mathematics. The hands-on projects covered were selected to provide you a broad base from which to build your own machine learning solutions. If you want or need to know how AI tools like ChatGPT really work so that you can intelligently discuss their potential uses in your organization, in addition to knowing how to build effective solutions to solve real cybersecurity problems using machine learning and AI today, this is the class you need to take. Check out the extensive course description below for a detailed run down of course content and don't miss the free demo available by clicking the "Course Demo" button above!

NOTE: All the concepts in this course are discussed using Python examples. You should have an intermediate understanding of the Python language! There is no need to be a Python expert. If you have successfully written at least a handful of Python scripts, your Python knowledge is likely sufficient. We will review key Python data structures in class in the first section of the course. If you need assistance determining if your Python knowledge is sufficient, please contact us for more information.

This course is for cybersecurity professionals who are seeking to add machine learning, data science, and artificial intelligence skills to their repertoire. This course is also very useful for individuals with a data science background who are seeking to understand how to use cybersecurity data in meaningful ways for threat hunting, anomaly detection, and monitoring. Intermediate Python fluency is important. Pre-calculus mathematics skills are important but not required.

Major Topics Covered Include

  • Data acquisition from SQL, NoSQL document stores, web scraping, and other common sources
  • Data exploration and visualization
  • Descriptive statistics
  • Inferential statistics and probability
  • Bayesian inference
  • Unsupervised learning and clustering
  • Deep learning neural networks
  • Autoencoders
  • Anomaly detection with neural networks
  • Loss functions
  • Convolutional networks
  • Embedding layers
  • Practical containerized deployment

Hands-On Machine Learning Training

The hands-on portion of SEC595 and especially suited to the student with a data science background who are seeking to understand how to use cybersecurity data in meaningful ways for threat hunting, anomaly detection, and monitoring. The course includes 30 hands-on labs and over 70% of the class is spent solving machine learning and data science problems hands-on.

  • Section 1: Python Refresher; Accessing, Manipulating, and Retrieving SQL Data; Accessing, Manipulating, and Retrieving NoSQL data: MongoDB; Webscraping for data acquisition
  • Section 2: Statistics Fundamentals: Medians and Means; Statistics Fundamentals: Variance, Deviations, and Robust Measures; Applications of Statistics to Data Identification; Probability and Bayes; Threat Hunting through Signals Analysis
  • Section 3: K-Means/KNN; Elbow Functions and PCA; DBSCAN for Clustering; Support Vector Classifiers; Support Vector Machines; Decision Trees; Random Forests
  • Section 4: Regression Analysis; First DNN; Ham vs. Spam via Deep Learning; Gradient Descent and Back Propagation; Realtime Application Protocol Identification with Deep Learning
  • Section 5: Predictive Malware Identification - Finding Zero Days with Deep Learning; Ham vs. Spam, CNN Style; Multi-class text classifications via CNNs; Signature Free Anomaly Detection in Logs using Autoencoders; Real-time Network Application Anomaly Detection with Ensemble Neural Networks
  • Section 6: CAPTCHA Solver POC; Solving CAPTCHAs with Functional Models; Solving CAPTCHAs Efficiently with Mixture of Experts DNNs

Syllabus Summary

  • Section 1: Data Acquisition, Cleaning, and Manipulation
  • Section 2: Data Exploration and Statistics
  • Section 3: Essentials of Machine Learning: Trees, Forests, & K-Means
  • Section 4: Essentials of Machine Learning: Deep Learning
  • Section 5: Essentials of Machine Learning: Autoencoders
  • Section 6: Essentials of Machine Learning: Functional Models and Deployment

Author Statement

"AI and Machine Learning are everywhere. How do the vendor solutions work? Is this really black magic? I wrote this course to fill an enormous knowledge gap in our field. I believe that if you are going to use a tool, you should understand how that tool works. If you don't, you don't really know what the results mean or why you are getting them. This course provides you with a crash course in statistics, mathematics, Python, and machine learning, taking you from zero to...I'm reluctant to promise 'Hero...' Let's say competent-person-who-can-solve-real-problems-today!"

- David Hoelzer

What You'll Learn

  • Design custom machine learning solutions for security data
  • Implement AI-based anomaly detection and threat hunting
  • Build neural networks for security classification tasks
  • Create effective data visualizations for security insights
  • Develop Python automation for security data analysis

Business Takeaways

  • Reduce alert fatigue and false positives in security operations
  • Enhance threat detection with predictive AI capabilities
  • Automate routine security tasks through machine learning
  • Identify previously undetectable security anomalies
  • Optimize security resource allocation with data insights
  • Improve incident response time through intelligent analysis
  • Strengthen security posture with proactive AI detection

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals.

Section 1Data Acquisition, Cleaning, and Manipulation

On day one we focus on essential Python skills for data acquisition and manipulation in security contexts. Students will learn methods for retrieving data from SQL databases, NoSQL document stores, and web sources. This foundation enables effective data collection for subsequent analysis and machine learning applications in security operations.

Topics covered

  • Python refresher for data science applications
  • SQL database access and data extraction
  • NoSQL document stores and MongoDB integration
  • Web scraping for security intelligence
  • Data cleaning and preparation techniques

Labs

  • Building data pipelines from security databases
  • Extracting indicators from unstructured sources
  • Implementing web scraping for threat intelligence
  • Creating data transformation workflows
  • Automating data collection processes

Overview

This section introduces some of the terminology in the data science and machine learning fields, in addition to introducing a number of the technologies that are used as data sources. Since the first step in any data science or machine learning project is to acquire data, the balance of the day is focused on hands-on exercises to prepare the student for these tasks.

The first necessary skill is the use of Python, our chosen language for this course. The only course prerequisite is an intermediate understanding of Python. If you've successfully written a few Python scripts, you are probably knowledgeable enough to get started! We will cover lists, arrays, tuples, dictionaries, comprehensions and then begin introducing the NumPy variants.

Following the Python refresher the course provides some theory followed immediately by hands-on exercises to give you just enough knowledge of SQL, MongoDB, and web scraping to get real work done.

Section 2Data Exploration and Statistics

Section two covers the statistical foundations necessary for effective security data analysis. Students learn to apply statistical measures to security datasets, interpret probability distributions, and use Bayesian inference for security decision-making. These skills form the basis for understanding anomaly detection and predictive security analytics.

Topics covered

  • Descriptive statistics for security metrics
  • Inferential statistics and hypothesis testing
  • Probability distributions in security data
  • Bayesian inference for threat assessment
  • Statistical anomaly detection methods

Labs

  • Analyzing security event frequency distributions
  • Applying statistical tests to detect outliers
  • Building probabilistic models for alert triage
  • Implementing Bayesian analysis for threat scoring
  • Developing statistical baselines for normal behavior

Overview

This section begins with the fundamentals of statistics that matter for data science and machine learning. Following this introduction and hands-on exercises that provide practical uses for these techniques against real-world data, the course transitions to probability theory.

Probability theory is an extensive field of its own. Following the introduction of some fundamentals, the course works directly toward deriving Bayes theorem. Building on this introduction, students then engage in a hands-on lab that builds a useful Bayesian analysis tool, upon which students will improve later in the course.

The remainder of this section is translating the statistical knowledge gained into the field of signals analysis. After a discussion concerning the derivation and applications of the Fourier series, the Fast Fourier Transformation, and the Discrete Fourier Transformation, students use these tools in a real-world threat hunting activity.

Section 3Essentials of Machine Learning: Trees, Forests, & K-Means

This introduction to machine learning techniques focuses specifically on security use cases. Students explore supervised and unsupervised learning approaches for threat detection, classification, and anomaly identification. The section progresses from basic clustering methods to advanced classification algorithms; all applied to security datasets.

Topics covered

  • Unsupervised learning for anomaly detection
  • Support Vector Machines for classification
  • K-Means and KNN clustering techniques
  • Dimensionality reduction with PCA
  • Feature selection for security data

Labs

  • Building anomaly detection for network traffic
  • Classifying malicious vs. benign behavior
  • Implementing clustering for threat hunting
  • Applying dimensionality reduction to log data
  • Designing feature extraction pipelines

Overview

The remaining 18+ contact hours of this course are spent learning about and immediately applying various machine learning models. After each topic is introduced and discussed, students engage in lengthy hands-on labs to develop an intuitive understanding and apply the technique to real problems.

The section begins with various clustering approaches and unsupervised machine learning. The exploration begins with Support Vector Classifiers, kernel functions, and Support Vector Machines. Following this discussion and exercises, we continue the clustering theme by considering the K-Means and KNN approaches. After working through examples in just two or three dimensions, we turn our attention to methods for determining the ideal number of clusters. With this done, we finally explore high-dimensional applications and dimensionality reduction through Principal Component Analysis. The DBSCAN algorithm is covered in some depth, with application made to threat hunting and efficient SOC analysis of large-scale data.

The balance of this section is spent discussing Tree-based classifiers. After a hands-on activity and discussion of the limitations of Decision Trees, we expand into Random Forests and explore hands-on how these provide better inferences in most cases.

Full Lab Details

  • K-Means / KNN
  • Elbow Functions and PCA
  • DNSCAN for Clustering
  • Support Vector Classifiers
  • Support Vector Machines
  • Decision Trees
  • Random Forests
  • Boosted Trees

Full Topic Details

  • Support Vector Classifiers
  • Support Vector Machines
  • Kernel Functions
  • Primary Component Analysis
  • DBSCAN
  • K-Means
  • KNN
  • Elbow Functions
  • Decision Trees
  • Random Forests
  • Anomaly Detection

Section 4Essentials of Machine Learning: Deep Learning

Our exploration into deep learning methods addresses advanced security challenges. Participants discover ways to design, train, and evaluate neural networks for security applications including malware detection, phishing identification, and behavioral analysis. We also cover network architectures optimized for security data types and formats.

Topics covered

  • Neural network fundamentals for security
  • Deep learning for malware detection
  • Convolutional networks for pattern recognition
  • Autoencoders for anomaly detection
  • Embedding layers for categorical security data

Labs

  • Building neural networks for threat classification
  • Implementing autoencoders for outlier detection
  • Training convolutional networks for malware analysis
  • Developing embedding models for user behavior
  • Creating deep learning pipelines for security data

Overview

The entire focus of this section is on the theory, development, and use of supervised learning approaches in the field of information security. Building on the mathematics and statistics covered in section 2, this section begins with linear regressions and ends with the application of deep learning neural networks to multi-class classification problems involving real-time network data.

The material is focused on using supervised machine learning and mathematics to create predictive models. The initial discussion and exercises center around forecasting and trends analysis for anomaly detection. Following this, the majority of the material focuses on classification problems.

Building on the Bayes approach used in section two, this section introduces deep learning neural networks and fully connected dense networks through the development of a far more accurate phishing detection network. Following this, the course explores visualization and measurement of neural network training performance, in addition to discussing overfitting, overtraining, and how to identify (and avoid!) them.

The next portion of this section turns to categorical problems, during which students will build a real-time network protocol classification system. More importantly, students will implement anomaly detection in this classification system, a task typically reserved for unsupervised approaches.

Section 5Essentials of Machine Learning: Autoencoders

This section focuses on convolutional networks and autoencoder architectures. The first half concentrates on CNNs for text classification and zero-day malware detection, while the second half examines autoencoder fundamentals, latent representations, and reconstruction loss functions for signature-free anomaly detection in logs and network traffic.

Topics covered

  • Convolutional neural networks
  • Embedding layers
  • CNN text applications
  • Autoencoder architecture
  • Reconstruction loss measurement

Labs

  • Predictive malware identification
  • CNN-based message filtering
  • Multi-class text classification
  • Log anomaly detection
  • Real-time network anomaly detection

Overview

This section of the course is dedicated to expanding students' knowledge of deep learning solutions. The first half of the section is focused entirely on convolutional networks (CNNs). The class explores the application of CNNs to text classification problems, but also to predictive identification of zero-day malware.

The second half of this section of the course focuses on autoencoders. The class examines what autoencoders do, why they work, how to select a latent representation, and how reconstruction loss functions work. This knowledge is then applied to creating an automatic log anomaly detection solution that does not use any signatures or human intervention to identify anomalies. Building on this, students work on the building blocks for a large-scale ensemble autoencoder for detecting network threats.

Section 6Essentials of Machine Learning: Functional Models and Deployment

This section focuses on practical implementation of complex neural networks using TensorFlow's functional API. We also cover effective synthetic data generation, data augmentation, genetic hyperparameter optimization, and deployment strategies including standalone solutions for time-critical applications and containerized approaches using Docker/Kubernetes.

Topics covered

  • CNN regression applications
  • Functional network architecture
  • Multi-input/multi-output neural networks
  • Machine learning problem framing
  • Genetic algorithms andmodel deployment

Labs

  • CAPTCHA solving proof-of-concept
  • Functional API implementation
  • Split model architecture

Overview

The final section of this course continues discussing Convolutional Neural Networks and the application of CNNs and fully connected networks for solving regression problems. The major focus of this section is on the creation of a deep neural network using TensorFlow's functional pattern, allowing you to build networks with complex structures, multiple inputs, and multiple outputs. The main task used to learn about these techniques will be using neural networks for both testing the quality of and solving CAPTCHAs. Whether you are on a red, blue, or purple team, you will learn how to think through and use machine learning to solve what amounts to a computer vision problem and to solve it at greater than 95% accuracy! Along the way you will also learn the key concepts behind the creation of representative synthetic data, how to build synthetic data with generators, and how things can go wrongly. You will also learn how to make use of data augmentation layers.

Following this project, the class covers the use of genetic techniques for hyperparameter optimization. Students are provided with a starting point for genetic optimization for use on their own after class.

The final discussion and demonstration in the course covers practical deployment approaches, including stand-alone deployments for real time critical applications and, for less time critical applications, the more common containerized approaches that can be used with Docker, Rancher, or Kubernetes.

Things You Need To Know

Important! Bring your own system configured according to these instructions!

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.

It is critical that you back-up your system before class. it is also strongly advised that you do not bring a system storing any sensitive data. Your system should meet these requirements:

  • Modern 64-bit processor (ARM/AMD/Intel) running Linux (Ubuntu or similar recommended, Linux kernel version 6 or higher), Windows 10 or later, or MacOS 11.x or later
  • A minimum of 16GB RAM
  • 80GB Free Hard Drive Space
  • Your computer must either have Docker, Rancher, or Podman installed, or your user account must have the necessary rights to install one of these software packages

Your course media will be delivered via download. The media file for class is large, more than 50GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Waiting until the night before the class starts to begin your download has a high probability of failure.

SANS has begun providing printed materials in PDF form. Additionally, certain classes are using an electronic workbook in addition to the PDFs. The number of classes using eWorkbooks will grow quickly. In this new environment, we have found that a second monitor and/or a tablet device can be useful by keeping the class materials visible while the instructor is presenting or while you are working on lab exercises.

If you have additional questions about the laptop specifications, please contact customer service.

SEC595 training is recommended for a diverse range of individuals, including:

  • Infosec professionals who want to understand machine learning
  • Professionals desiring to apply data science principles to real-world problems
  • Anyone who has tried to learn the basics but can't figure out how to translate your problem into something that can be solved with machine learning
  • Blue team and SOC members looking to identify anomalies and perform custom threat hunting

The GIAC Machine Learning Engineer (GMLE) certification validates a practitioner’s knowledge of practical data science, statistics, probability, and machine learning. GMLE certification holders have demonstrated that they are qualified to solve real-world cyber security problems using Machine Learning.

  • Anomaly detection and optimization
  • Convolutional neural networks
  • Data acquisition
  • Data exploration and visualization
  • Data manipulation and analysis
  • Deep learning neural networks
  • Inferential statistics and probability
  • Loss functions
  • Probability and inference
  • Python scripting
  • Supervised and unsupervised learning

More Certification Details

  • Jupyter notebooks of all labs and complete solutions
  • Sample data for real-world cybersecurity problems

Intermediate Python programming skills are essential for this course. While not required, basic knowledge of statistics and mathematics at a pre-calculus level will be beneficial. Students should have a foundational understanding of cybersecurity concepts and be familiar with common security tools and data sources. No prior experience with machine learning or data science is necessary.

The learning path begins with cybersecurity fundamentals (SEC401), progresses to detection and monitoring (SEC450), then to advanced monitoring (SEC503/504), culminating in SEC595 for applied data science and machine learning. This progression builds comprehensive skills from security foundations to advanced AI-driven analytics.

Machine learning in cybersecurity enables systems to automatically identify patterns, detect anomalies, and predict threats without explicit programming. This data-driven approach enhances detection capabilities beyond traditional rule-based systems by continuously learning from new data and adapting to evolving threats.  

It involves the development of algorithms that can analyze and make predictions or decisions based on data. This technology is fundamental in creating applications that adapt and become more accurate over time, revolutionizing industries by automating complex tasks and unlocking new insights from data.

This course provides immediately applicable AI and data science skills that are increasingly essential in cybersecurity roles. You'll gain expertise in developing custom machine learning solutions for security challenges, enhancing your value to employers seeking professionals who can implement advanced detection and response capabilities.

Relevant Job Roles

Data Analysis (OPM 422)

NICE: Implementation and Operation

Responsible for analyzing data from multiple disparate sources to provide cybersecurity and privacy insight. Designs and implements custom algorithms, workflow processes, and layouts for complex, enterprise-scale data sets used for modeling, data mining, and research purposes.

Explore learning path

Cybersecurity Research & Development

SCyWF: Cybersecurity Architecture, Research And Development

This role conducts conducts cybersecurity research and development. Find the SANS courses that map to the Cybersecurity Research & Development SCyWF Work Role.

Explore learning path

Data Science (DATS)

Skills Framework for the Information Age

Application of statistical analysis, machine learning, and data engineering to identify trends, forecast outcomes, and inform strategic and operational decisions through structured insights.

Explore learning path

Artificial Intelligence and Data Ethics (AIDE)

Skills Framework for the Information Age

Responsible design, development, and governance of AI and data-driven systems. Ethical principles are embedded into algorithms, models, and automated decision-making to ensure fairness, transparency, and accountability.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 20

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources