SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Kick off your SANSFIRE 2025 experience at the Welcome Reception. Be a part of this kickoff event and join the industry’s most powerful gathering of cybersecurity professionals. Share stories, make connections, and learn how to make the most out of your training this week in Washington, DC. Beverages (adult and otherwise) and bites will be served. Hope to see you there!
I've been a heavy user of AI since the beginning, but the way that I use AI has recently shifted. In this fast-paced, fun talk, we'll cover the top ways that I've improved my efficiency and productivity by changing the way I interact with AI so far in 2025.
Like it or not, AI is here to stay, so why not embrace it and the capabilities offered. This talk will showcase how to use two different models to design a custom C2 framework from scratch. Privacy concerns will also be addressed during the talk and will highlight how to maintain control of sensitive company information, or just information you don't want a model to have. Attendees will understand how to feed a model various prompts to get what is desired as well as how to begin the implementation of what's given back to you from your prompt's response. Those is a dev-like role should attend this talk, but it is also open to anyone who might be curious about the process.
Join us for a special "Community Night" at SANSFIRE 2025. This gathering is open to all cybersecurity professionals and designed to foster connections across the entire spectrum of our community — from newcomers to seasoned experts.
For security operations, distractions can be dangerous. A “denial of service” against a defender often leads to missed alerts and compromise. The tool must never be the focus but the results the tool provides should determine the value of the tool. AI tools are currently in the “new and cool” phase of the hype cycle. There is no week without a major new AI development. As a result, defenders tend to spend a lot of time trialing new tools and little time properly integrating them into security operations. During this presentation, we interview several defenders to learn what turned out to be just a distraction, or what tools turned out to be a game changer for operations once properly integrated.
Join us for an exclusive evening of connection and inspiration at SANSFIRE 2025 Women’s Connect, hosted in partnership with Women in CyberSecurity (WiCyS). This special gathering is open to SANS students and members of the local cybersecurity community — from CISOs to early-career practitioners.
Speakers: Internet Storm Center Handlers, Guy Bruneau and Jesse La Grew
Become part of the largest, oldest, and most open sensor network on the internet. Learn how to build, configure, and operate your very own honeypot. We will provide up to twenty honeypots free on a first-come basis. You are also welcome to bring your own Raspberry Pi, n100, or similar system (or cloud account).
This is a hands-on session and requires some familiarity with Linux. Once deployed, the three honeypots submitting data most consistently for the first three months will have a yet-to-be-announced prize.
Buckle up for a lively ride through the wild world of cybersecurity! Sure, today’s tech landscape is all about AI, quantum computing, and other fancy buzzwords that make your head spin but guess what? None of that cutting-edge stuff means squat if you’re ignoring the good old basics. In this upbeat, interactive session, we’ll dive into why the tried-and-true fundamentals (think password hygiene, patch management, and access controls) are the secret sauce to surviving and thriving in the age of ever-evolving cyber threats. Prepare for real-life “oops” moments, plenty of laughs, and hands-on tips you can actually use. This is not your buttoned-up, corporate snooze-fest: you’ll leave inspired, empowered, and ready to fortify your digital defenses with good vibes and rock-solid basics. Let’s have some fun getting back to what really matters!
Registration: All students who register for a 4-6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About Core NetWars: The most comprehensive of the NetWars ranges, this ultimate multi-disciplinary cyber range powers up the most diverse cyber skills. This range is ideal for advancing your cybersecurity prowess in today's dynamic threat landscape. The winning team and the top five solo players from every Core NetWars tournament throughout the year are offered a chance to compete in the annual SANS Core NetWars Tournament of Champions.
Speaker: Deborah Kariuki, Graduate Program Director, MAE-UMBC
The persistent framing of users as the “weakest link” in cybersecurity has long shaped how risks and responsibilities are distributed in digital systems. However, in the age of artificial intelligence (AI), this narrative demands reexamination. As AI increasingly mediates critical decisions, from authentication to threat detection, the question of “who or what” constitutes the weakest link becomes more complex.
Registration: All students who register for a 4-6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About Cyber Defense NetWars: Focused on preventing, analyzing, and defending against complex real-world attack scenarios, including brute-force attacks and ransomware campaigns.
In this demo of hardware hacking, we'll introduce PulseView - the 'Wireshark of hardware hacking' - and demonstrate a technique to unlock a keypad safe. Our method? A Side-Channel Timing Attack, which relies on the timing discrepancies in the user interface.
Using an affordable logic analyzer (priced under $15), we'll capture microsecond changes in response times tied to incorrect passcodes. By leveraging this side-channel data, we will carefully decipher the true passcode of the safe. Unique Approach: Traditional hacking often focuses on software vulnerabilities to exfiltrate sensitive data.
Registration: All students who register for a 4-6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About Core NetWars: The most comprehensive of the NetWars ranges, this ultimate multi-disciplinary cyber range powers up the most diverse cyber skills. This range is ideal for advancing your cybersecurity prowess in today's dynamic threat landscape. The winning team and the top five solo players from every Core NetWars tournament throughout the year are offered a chance to compete in the annual SANS Core NetWars Tournament of Champions.
Registration: All students who register for a 4-6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About Cyber Defense NetWars: Focused on preventing, analyzing, and defending against complex real-world attack scenarios, including brute-force attacks and ransomware campaigns.