Group Purchasing
Group Purchasing

SEC501 Live Online February

  • Mon, Feb 8 - Sat, Feb 13, 2027
  • 1 Course
  • English
Virtual (ET)
SEC501: Advanced Security Essentials - Enterprise Defender
  • 6-Day Course: February 8 – 13, 2027

    Earn 38 CPEs.

  • GIAC Certified Enterprise Defender
  • Intermediate Skill Level

    Course material is geared for cybersecurity professionals with hands-on experience.

  • 26 Hands-On Labs

    Apply what you learn with hands-on exercises and labs.

SEC501: Applied Cyber Defense - Live Online

The hardest part of enterprise defense is rarely the analysis. It is deciding what to do when the record you need sits with a SaaS provider, an MSSP, or a cloud platform, and it will not arrive before you have to act.

SEC501 trains that decision over six days of live, virtual instruction, built around a single persistent anomaly you follow all week. Each section adds evidence and none of it hands you a tidy conclusion. The recurring question is the one the job actually asks: does this justify escalation, containment, or collecting more, and what is still missing when you make the call?

During the week, you'll work through:

  • 25+ integrated hands-on labs
  • A Capture the Flag capstone with independent challenges
  • Packet analysis, network reconstruction, and Suricata rule testing
  • Asset discovery, vulnerability validation, and credential exposure exercises
  • Deleted-file recovery, Windows artifact analysis, and ransomware timeline work
  • Static, host behavior, network behavior, and manual code analysis of a malware specimen

Verifying AI-Assisted Analysis

SEC501 treats AI-assisted analysis and agent actions as evidence to be verified, not accepted. You compare automated interpretations against primary records, confirm what authority an agent was granted, and identify which system change it actually made. 38 CPE credits, aligned to the GIAC Certified Enterprise Defender (GCED) certification.

Who Should Take This Course?

Experienced technologists whose defensive work crosses systems and teams: SOC analysts moving into incident handling, security engineers responsible for detection and hardening, network and system administrators taking on defense duties, DFIR practitioners, and CSIRT members. SEC401-level knowledge or equivalent experience is the right starting point.

Download the Course Syllabus or Letter to Justify this Training to Your Manager

To learn more about SEC501, business takeaways, laptop requirements and more, please visit the course page.

Courses

Looking for Group Purchasing? Contact Sales

Featured Speaker

Ross Bergman
Ross Bergman

Ross Bergman

SANS Principal Instructor Ross Bergman brings nearly four decades of hands-on and leadership experience. SANS Senior Instructor Dave Shackleford has advised hundreds of organizations on cloud, network, and security architecture.

Read more about Ross Bergman

Three Reasons to Train Virtually

  • Ultimate Convenience

    Eliminate the hassle of daily commutes and wasted travel time. You’ll have everything you need right from your home.

  • Personalization

    Hands-on learning with the opportunity to ask questions and receive instant feedback from world-renowned experts. Afterward, reinforce your skills with 4-months of access to daily course lecture archives.

  • Hands-On Labs

    Learn cutting-edge cybersecurity knowledge with hands-on labs that provide you with techniques you can immediately use in your organization.

Woman at Laptop