Group Purchasing
Group Purchasing
MAJOR UPDATES

SEC501: Applied Cyber Defense

SEC501Cyber Defense
  • 6 Days (Instructor-Led)
  • 38 Hours (Self-Paced)
Course authored by:
Ross BergmanDave Shackleford
Ross Bergman & Dave Shackleford
SEC501: Advanced Security Essentials - Enterprise Defender
Course authored by:
Ross BergmanDave Shackleford
Ross Bergman & Dave Shackleford
  • GIAC Certified Enterprise Defender (GCED)
  • 38 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 26 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Attackers move across cloud platforms, SaaS providers, and AI agents faster than logging can keep up. Learn to scope, contain, and act using incomplete evidence.

Course Overview

One enterprise investigation connects visibility, detection, hardening, incident response, and malware analysis. More than 25 integrated labs require you to follow suspicious activity through records held by systems and providers. You use these records to establish scope, test controls, and decide whether escalation, containment, or recovery is justified.

Defend the Enterprise When the Records Are Incomplete

Cyber defenders must investigate and act across systems and services they do not fully control. A compromised software update can enter through an approved process, while stolen credentials can cross platforms before an investigation establishes scope. AI agents can make authorized changes faster than teams can review the resulting records. SEC501 develops the technical judgment to determine what these records support before escalation or containment creates unnecessary cost or disruption.

SEC501 begins with a persistent anomaly involving network availability, privileged access, and DNS activity. Additional records may narrow the possible explanations without establishing a single cause. You must decide whether they justify escalation, containment, or collection from another system.

You revisit the persistent anomaly by comparing network and identity records with alerts retained elsewhere in the enterprise. Hardening changes, recovered host artifacts, and malware behavior may change which systems or accounts require action.

More than 25 integrated labs require you to decide what the records support. You will trace an alert or exposed service to the record behind it and test a control against observed behavior. You must then decide whether the record justifies escalation, containment, or corrective action. Document any record that remains missing when the decision is made.

Records needed to establish scope may reside with a SaaS provider, cloud management platform, or MSSP. AI systems and agents may also produce analysis or change a system under delegated authority. You will identify which record is missing, verify the authority granted, and compare the automated analysis or system change with records from the affected system before using either to make an incident decision.

Management gains cyber defenders who reduce the cost of premature escalation, match containment to the systems and accounts in scope, and require a tested correction when a control fails. The same investigation reveals whether contracts, retention periods, or access rights will keep a required record from responders during the next incident.

SEC501 prepares practitioners with SEC401-level knowledge or equivalent experience to investigate activity across systems before deeper specialization in the Cyber Defense curriculum.

Author Statement

“Cyber defenders rarely receive every record at the moment a decision is required. I have spent my career moving between hands-on technical work and leadership roles where records were held by different systems, teams, and providers, and where an unnecessary response action could disrupt the business it was intended to protect. I designed SEC501 around this reality. The persistent anomaly connects the five technical sections, requiring you to examine what the enterprise recorded, determine which explanations remain supportable, and decide whether the records justify escalation, containment, or further collection. SEC501 develops the breadth needed to follow suspicious activity across the enterprise and the judgment to act before every record is available.”

– Ross Bergman

What You’ll Learn

  • Correlate records held by different systems, teams, and service providers.
  • Recover the sequence of suspicious activity from network and host records.
  • Build and test detections against the traffic they are expected to identify.
  • Validate which exposed services can extend access before assigning remediation priority.
  • Establish scope before containment disrupts systems or accounts outside it.
  • Use malware behavior and program logic to improve detection, scoping, and recovery.
  • Check AI-assisted analysis and agent actions against primary records.

Business Takeaways

  • Reduce the cost of premature escalation by requiring corroborating records.
  • Limit disruption by matching containment to the systems and accounts in scope.
  • Give responders timely access to records held by providers and authority to act.
  • Require tested corrections when controls fail to record or restrict activity.
  • Identify missing records and short retention periods before they delay an investigation.
  • Remove persistence and compromised access before systems return to service.
  • Limit risk from automated actions by verifying authority and the resulting system change.

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC501: Applied Cyber Defense.

Section 1Seeing Like a Defender

A persistent anomaly begins with records of network availability, privileged access, and DNS activity that do not establish a common cause. Compare what network devices generate with what receiving systems retain, then test how device time, administrative access, network trust, and decoy activity affect a later investigation.

Topics covered

  • Persistent anomaly and enterprise records
  • Network device baselines and audit evidence
  • Syslog, time integrity, and record retention
  • Authentication, authorization, and accounting (AAA)
  • Domain Name System decoys and active defense

Labs

  • Establish a defensible baseline and measure the effect of each change
  • Determine whether timestamp differences make records unsafe to correlate
  • Compare local and centralized records of administrative access
  • Verify that untrusted network peers are rejected and recorded
  • Create low-noise signals that support targeted investigation

Overview

Privileged activity may be recorded by a network device, authentication service, and Syslog server at different times and with different detail. The defender must establish what each system generated and retained before placing the records on one timeline.

Network devices provide a concrete model for records and controls distributed throughout an enterprise. A provider-managed service, build process, or AI agent can also change a system under approved authority. Records from the affected system must be compared with the approval and workflow records before the change is attributed to the approved workflow or agent.

Full Lab Details

  • Configuration Baseline and Audit. Compare the current device configuration with a recognized benchmark, prioritize the exposure that warrants correction, and retain the baseline needed to measure later changes.
  • Record Delivery and Time Integrity. Trace one event from the device to the receiving system and determine whether timestamp differences make the records unsafe to correlate during an incident.
  • Administrative Access Records. Compare the records kept locally with centralized authentication and accounting. Determine which account received access, what the device retained, and which details would be missing during an investigation.
  • Gateway Trust and Availability. Demonstrate how an untrusted peer can influence gateway selection, then verify that authentication prevents the same change and produces records for an availability investigation.
  • Routing Trust. Disrupt a routing relationship with unauthenticated traffic, then verify that authenticated peers reject the traffic without creating a false route change.
  • Low-Noise Connection Alerts. Convert connections to unused services into alerts that justify targeted review without adding routine service traffic to the queue.
  • DNS Control and Investigation. Compare current and historical DNS records, test a sinkhole decision, and generate a decoy lookup that identifies the system requiring review.
  • Hardening Evidence. Re-audit the configuration to verify which findings were corrected, which exceptions remain, and whether the final configuration contains each approved correction.

Full Topic Details

  • Persistent Anomaly and Enterprise Records. Network availability, privileged access, and DNS records begin the investigation that continues across all five sections.
  • Configuration Baselines and Audit Evidence. Published benchmarks, saved configurations, approved exceptions, and change records establish the state a defender expects to find on the network device.
  • Logging and Time Integrity. Network device and Syslog records expose what was generated, received, normalized, and retained for later comparison.
  • Administrative Access and AAA. Local device logs, RADIUS records, and command accounting describe different parts of administrative access.
  • Network Trust. HSRP and OSPF show how unauthenticated peers can influence availability and how authentication changes both behavior and the records produced.
  • Active Defense. Honeyports, DNS sinkholes, and decoy records create low-noise events for comparison with routine traffic.
  • Software Supply Chain and Automated Change. Compare package, build, workflow, and endpoint records when an approved process or AI agent produces the change found on an affected system.
  • Hardening and Final Audit. Compare the final configuration with the opening baseline, then document each correction and approved exception.

Section 2Detecting Like a Defender

Trace an alert to the packet, protocol record, flow data, or host event that produced it. Reconstruct suspicious activity, test detection logic against captured traffic, and determine whether the combined records justify escalation or a change in incident scope.

Topics covered

  • Security operations and alert triage
  • Packet analysis and network forensics
  • Zeek, flow data, and network visibility
  • Suricata detection development
  • SIEM correlation and security analytics

Labs

  • Isolate the traffic needed to test an alert
  • Reassemble suspicious network activity and recover transferred files
  • Test whether a detection identifies the behavior it targets
  • Correlate authentication and flow records before changing incident scope

Overview

An alert may remain available after the packet or host record that produced it is no longer retained. A dashboard may expose only the fields selected by another team or provider. The defender must establish what the enterprise retained before using the alert to widen scope or escalate.

An MSSP may hold the alert while the customer retains the packet, authentication event, or host record needed to interpret it. The responder must know who can retrieve each record and who can escalate or contain the activity.

Full Lab Details

  • Packet Evidence. Isolate the traffic relevant to an investigation and use the captured header fields to document what the record supports before expanding scope.
  • Reconstructing Network Activity. Reassemble conversations, recover transferred content, and convert packets into searchable records that expose the activity sequence, systems, and services for further investigation.
  • Testing Detection Logic. Compare each alert with the packet that produced it, then build and test a local rule against observed behavior before relying on it for escalation.
  • Correlating Enterprise Records. Compare authentication events with network flow during the same period to determine whether the combined activity changes incident scope.

Full Topic Details

  • Security Operations and Alert Triage. Identify who owns the alert, inspect the source record, and determine whether the responder has authority to escalate or act.
  • Network Visibility Architecture. Examine how sensor placement, encryption, edge devices, and provider access determine which traffic records exist.
  • Packet Analysis with tcpdump. Use header fields and readable filters to isolate the traffic needed for review.
  • Wireshark and Network Forensics. Reassemble conversations, inspect protocol behavior, and extract transferred objects from packet captures.
  • Zeek and Flow Analysis. Turn packet captures into searchable protocol logs and compare them with flow records that cover a larger environment.
  • Suricata Detection. Inspect alert records, match them to packet fields, and build a local rule from observed traffic.
  • Testing Detection Logic. Start with behavior the enterprise records, then verify that the rule identifies the intended traffic under expected conditions.
  • Managed Detection and AI-Assisted Triage. Identify which records reach the MSSP or AI-assisted workflow, which remain with the customer or provider, and who has authority to act.
  • SIEM Analytics. Correlate Syslog and flow records across time and endpoints to assess whether an alert changes incident scope.

Section 3Hardening Like a Defender

Find the systems and services that respond now, compare them with the inventory, and validate which exposures can extend access. Test how credentials and command-and-control channels cross expected boundaries, then verify a controlled configuration change against each managed system.

Topics covered

  • Asset, service, and identity discovery
  • Vulnerability assessment and exploit validation
  • Credential exposure and remote administrative access
  • Command and control, segmentation, and reachability
  • Configuration drift and controlled automation

Labs

  • Reconcile the asset inventory with services that respond on the network
  • Validate whether a scanner finding provides usable access
  • Determine whether exposed credentials extend administrative access
  • Test whether network records expose command-and-control activity
  • Preview a controlled change and verify it on each managed system

Overview

Hardening begins with the systems and services that answer today, including those missing from the inventory or reachable through an exposed credential. A scanner result becomes a corrective priority after reachability, usable access, and business function have been validated.

Controlled automation closes the section with one low-impact change. Records from the preview, each target, and the repeated run show whether the approved change was applied consistently without altering systems that already matched the requested state.

Full Lab Details

  • Asset and Service Discovery. Reconcile documented assets with the services that answer on the network, then identify which unexpected services require validation and corrective action.
  • Vulnerability Validation. Determine whether a scanner finding provides usable access, inspect the records created on the target, and separate confirmed exposure from AI-assisted interpretation before assigning remediation priority.
  • Identity Exposure. Determine whether captured credential material can be recovered and reused for administrative access, then identify the accounts and systems that require further review or containment.
  • Command-and-Control Visibility. Generate controlled command activity, then determine whether the network records identify the channel and affected host well enough to support detection and scoping.
  • Controlled Configuration Change. Preview and verify one low-impact change on Windows and Linux targets, then determine whether a second run changes a system that already matches the requested state.

Full Topic Details

  • Asset Discovery and Inventory. Compare documented assets with the systems and services that respond when they are checked from the network.
  • Enterprise Exposure. Extend discovery beyond network addresses to cloud-hosted workloads, SaaS applications, application programming interfaces (APIs), and identities used by automation.
  • Vulnerability Assessment. Use scanner findings, service details, reachability, and business function to decide which exposure requires validation and correction.
  • Exploit Validation and Host Records. Validate an exposure under controlled conditions and inspect the Windows records created by the resulting access.
  • Identity Exposure. Examine challenge-response capture, password reuse, and remote administrative access as separate ways credentials can extend an intrusion.
  • Non-Human Identities and AI Agents. Assess service accounts, tokens, integrations, and agent identities that may exist outside routine ownership and access reviews.
  • Command and Control. Compare host and network records created by two command-and-control frameworks to determine whether either channel would be detected and scoped.
  • Segmentation and Reachability. Assess which systems, services, and management planes an exposed service or credential can reach.
  • Configuration Drift and Controlled Automation. Preview one low-impact change, apply it to approved targets, repeat it, and verify the resulting files on each system.

Section 4Responding Like a Defender

Incident response begins before every record is available and often before scope is established. Recover host artifacts, test the claims in a handoff, reconstruct ransomware activity, and decide which systems or accounts require collection, containment, or recovery.

Topics covered

  • Incident response thresholds and authority
  • Filesystem recovery and Windows artifacts
  • AI-assisted handoff review
  • Timeline analysis and incident scoping
  • Containment, eradication, and recovery

Labs

  • • Recover deleted files and preserve the records that explain their origin
  • Use Windows artifacts to connect prior activity with a user or system
  • Check every handoff claim against the artifact it cites
  • Narrow the ransomware window and reconstruct the sequence of activity
  • Use network records to identify systems requiring further examination

Overview

Response decisions begin while scope is developing. A SaaS audit log, cloud management record, or MSSP-held alert may be required before a responder can identify the affected account or contain a system. The organization must correct any contractual, access, retention, or authority gap that could keep the needed record from responders during the next investigation.

Recovered files and Windows artifacts can narrow the ransomware window or connect activity to a user or system. The defender must document missing execution records and inaccessible provider logs because either gap could affect containment or recovery.

Full Lab Details

  • Deleted-File Recovery. Compare what Windows displays with underlying filesystem records, recover deleted content, and determine which claims the recovery method supports about a file's name, location, and prior state.
  • Windows Activity and Persistence. Use host artifacts to connect prior activity with a user or system, identify a persistence entry, and determine which execution records remain missing.
  • Incident Handoff Review. Check each claim against the artifact it cites, remove excessive claims, and document which statements remain supportable or require additional records.
  • Ransomware Timeline. Narrow the infection window, reconstruct the sequence surrounding visible encryption, and document delivery or execution as unresolved when the timeline does not record them.
  • Ransomware Network Scope. Compare network and historical DNS records with one affected host to identify systems requiring further examination without treating shared infrastructure as shared compromise.

Full Topic Details

  • Response Thresholds and Authority. Decide whether the available records justify an incident declaration, collection from additional systems, containment, or leadership escalation, and identify who has authority to act.
  • Artifact Collection and Integrity. Preserve the source and collection details needed to explain where an artifact came from and whether a response action may change it.
  • Windows Artifact Interpretation. Use the Red Poster to locate registry, event, filesystem, and cache artifacts tied to earlier user or system activity.
  • AI-Assisted Handoffs. Check each claim in a draft handoff against the artifact it cites before the note becomes part of the incident record.
  • Incident Scoping. Select network, host, identity, and provider records according to the system or account the response may affect.
  • Containment. Match isolation, credential changes, and other response actions to the systems and accounts placed in scope by the available records.
  • Eradication and Recovery. Remove identified persistence and compromised access before an affected system or service returns to operation.
  • Provider and MSSP Access. Correct contracts, retention periods, access rights, and escalation procedures that keep audit records from responders during an investigation.

Section 5Understanding Malware Like a Defender

Connect a suspicious file with the incident around it. Use file properties, host changes, network requests, and program logic to refine detection and scope, identify failed controls, and make containment and recovery decisions that the available records support across the enterprise.

Topics covered

  • Malware triage and static properties analysis
  • Host behavior and persistence
  • Network dependencies and controlled interaction
  • Code review and manual reversing
  • Enterprise detection and response implications

Labs

  • Develop detection leads before running a suspicious file
  • Identify the host changes that distinguish execution from download
  • Test how network responses change the specimen's behavior
  • Confirm encryption and file-selection logic through code review

Overview

Malware remains central to ransomware, espionage, credential theft, and destructive attacks. Analyzing a specimen can expose behavior that the enterprise failed to record or restrict and provide artifacts for identifying affected systems.

Each analysis stage adds details about the file and its behavior that can change which systems require review and which controls require correction. Enterprise records remain necessary to establish the specimen's role in the wider incident.

Full Lab Details

  • Static Properties Analysis. Examine file properties without running the specimen, then determine which identifiers can support immediate triage and which suggested behaviors require later testing.
  • Host Behavior Analysis. Observe processes, copied files, registry changes, and persistence created during execution, then use these artifacts to distinguish affected systems from systems that only received the file.
  • Network Behavior Analysis. Provide controlled network services and alter a response to identify dependencies, confirm observable requests, and determine which network records can support detection or containment.
  • Manual Code Reversing. Review deobfuscated program logic to confirm file selection, encryption, and network behavior left unresolved by earlier analysis, then apply these details to detection and recovery.

Full Topic Details

  • Malware in Enterprise Incidents. Connect a suspicious file with the host and network records needed to assess its role in an active investigation.
  • Malware Triage. Select an analysis stage according to the question being asked, the time available, and the risk of running the specimen.
  • Static Properties Analysis. Inspect hashes, strings, imports, metadata, and packing before the specimen is executed.
  • Interactive Host Analysis. Observe processes, copied files, registry changes, persistence, and other activity created during controlled execution.
  • Network Behavior Analysis. Examine DNS lookups, web requests, and service responses associated with the running specimen.
  • Manual Code Reversing. Review deobfuscated program logic to examine file selection, encryption, network dependencies, and behavior that earlier analysis left unresolved.
  • Enterprise Control Changes. Use confirmed malware behavior to improve record collection, test an alert, restrict the activity, and verify that compromised access is removed before recovery.

Section 6Operating Like a Defender

The final Applied Cyber Defense capstone draws on all five technical sections through independent challenges. Working individually or with a team, you must recover exact answers from the available artifacts and decide which challenge warrants the next block of time.

Overview

The Capture the Flags (CTF) capstone uses independent challenges that range from one precise command or lookup to several artifacts that must be combined before an answer can be submitted. You will work with network services, packet captures, filesystems, hashes, and code as you choose the order of the challenges. Working individually or with a team, you must decide whether the available records support an answer, whether another artifact is required, and when to move to another challenge.

Things You Need To Know

Important! Bring your own system configured according to these instructions.

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • Intel or AMD x64 CPU (2020 or later). ARM64/AArch64 and Apple M-series processors will not work and are not supported. SEC501:Applied Cyber Defense uses Cisco virtual appliances that cannot run on these platforms.
  • Virtualization enabled in BIOS/UEFI (Intel VT-x or AMD-V).
  • Minimum 16 GB RAM.
  • Minimum 125 GB free storage (VMs require at least 100 GB once installed).
  • Wireless networking capability (802.11) required for In-Person classes.
  • Optional: A second monitor or tablet may be helpful for viewing the SEC501 Electronic Workbook during labs.

Operating System and Configuration (Mandatory)

  • Windows 11 (Intel/AMD), fully patched. macOS and Linux are not supported.
  • Local Administrator access required.
  • Ability to disable antivirus/endpoint protection if necessary.
  • Ability to disable VPN clients and host firewalls if necessary.

Corporate security controls frequently interfere with virtualization and lab networking. If you cannot modify these settings, please arrange to use a different system.

Required Pre-Class Setup

Complete before the first day of class.

From your SANS Portal:

  • Download VMware Workstation, the SEC501 course media (.iso file, ~25 GB), and the SEC501 Lab Setup Instructions.
  • Follow the Lab Setup Instructions fully (may take 60+ minutes).
  • For In-Person/Live Online classes: Install Slack and join the SANS Training workspace and the SEC501 class channel.

If you have questions, please contact customer service.

SEC501 is designed for experienced technologists whose defensive responsibilities cross systems, platforms, and teams. It is an intermediate course for practitioners with SEC401-level knowledge or equivalent experience who must connect records and decisions across the enterprise before deeper specialization.

  • Security operations center (SOC) analysts moving into incident handling and scoping.
  • Security engineers responsible for detection, hardening, and response.
  • Network or system administrators taking on broader cyber defense duties.
  • Digital forensics and incident response (DFIR) practitioners who connect host artifacts with records held elsewhere.
  • Computer emergency response team (CERT) and computer security incident response team (CSIRT) members responsible for incidents that cross systems and teams.
  • Technical leads and managers responsible for access, authority, and corrective action.

The GIAC Certified Enterprise Defender (GCED) certification builds on the security skills measured by the GIAC Security Essentials certification. It assesses more advanced, technical skills that are needed to defend the enterprise environment and protect an organization as a whole. GCED certification holders have validated knowledge and abilities in the areas of defensive network infrastructure, packet analysis, penetration testing, incident handling and malware removal.

  • Network and cloud-based defensive infrastructure
  • Penetration testing; Digital forensics; Incident response
  • Network monitoring, forensics, and logging
  • Packet analysis; Intrusion analysis; Malware analysis

More Certification Details

  • MP3 audio files of the complete course lecture.
  • Course media with the lab virtual machines and case artifacts.
  • SEC501 Electronic Workbook with instructions for all technical labs.
  • Online video walkthroughs for every lab.
  • Capture the Flags capstone.

SEC401 or equivalent practical knowledge is recommended but not required. You should be comfortable working with TCP/IP from the Windows and Linux command lines and have basic experience administering systems or networks. Familiarity with virtualization will help you move efficiently through the labs.

SEC501 is the entry point to the Cyber Defense curriculum for practitioners with SEC401-level knowledge or equivalent experience. It connects visibility, detection, hardening, incident response, digital forensics, and malware analysis before deeper specialization. One persistent anomaly ties these functions to the same enterprise investigation.

Modern enterprises depend on cloud services and software supply chains. Managed security service providers may hold critical records, while AI agents may change systems under delegated authority. Applied cyber defense requires practitioners to follow suspicious activity across these boundaries and establish which systems and accounts require action. A network alert may require a host record, a hardening change, or malware analysis before containment is justified. Practitioners who make these connections reduce premature escalation, limit unnecessary disruption, and give leadership a clear technical basis for the response.

SEC501 prepares experienced technologists to take responsibility for investigations that cross systems, teams, and service providers.

  • Advance from alert review into incident handling and scoping.
  • Apply system or network administration experience to enterprise investigations.
  • Take on security engineering work that connects detection, hardening, and response.
  • Connect digital forensics and malware findings to enterprise control changes.
  • Prepare for GCED and deeper study across the Cyber Defense curriculum.
  • Make and explain technical decisions on escalation, containment, and recovery.

Relevant Job Roles

Protection

SCyWF: Protection And Defense

This role uses cybersecurity tools to protect information, systems and networks from cyber threats. Find the SANS courses that map to the Protection SCyWF Work Role.

Explore learning path

Vulnerability Assessment Analyst (DCWF 541)

DoD 8140: Cybersecurity

Assesses systems and networks to ensure compliance with policies and identify vulnerabilities in support of secure and resilient operations.

Explore learning path

Network Operations (OPM 441)

NICE: Implementation and Operation

Responsible for planning, implementing, and operating network services and systems, including hardware and virtual environments.

Explore learning path

Network Operations Specialist (DCWF 441)

DoD 8140: Cyber IT

Implements and maintains network services, including hardware and virtual systems, ensuring operational support for infrastructure platforms.

Explore learning path

Defense

SCyWF: Protection And Defense

This role uses monitoring and analysis tools to identify and analyze events and to detect incidents. Find the SANS courses that map to the Defense SCyWF Work Role.

Explore learning path

Cybersecurity Instruction (OPM 712)

NICE: Oversight and Governance

Responsible for developing and conducting cybersecurity awareness, training, or education.

Explore learning path

Information Security (SCTY)

Skills Framework for the Information Age

Implementation and oversight of security measures to protect organisational data, systems, and operations. Responsibilities include risk assessments, policy enforcement, and compliance with regulatory standards.

Explore learning path

Security Operations (SCAD)

Skills Framework for the Information Age

Monitoring and response to security incidents in live environments. Analysts detect anomalies, triage alerts, and coordinate defensive actions to maintain organisational security posture.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $8,780 USD*Prices exclude applicable local taxesBuy now for access on Aug 31. Use code Presale10 for 10% off course price!
    Registration Options
  • Location & instructor

    SANS Virginia Beach 2026

    Virginia Beach, VA, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Live Online Europe October 2026

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €8,230 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Dallas 2026

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Chicago 2027

    Chicago, IL, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
Showing 5 of 5

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources