Summit: December 4-5 | Training: December 6-11 | Co-Chairs: Justin Henderson & John Hubbard | CPE Credits: 16
The Tactical Detection & Data Analytics Summit will bring together leading security practitioners to present real-world case studies that demonstrate how to utilize high-value log sources, monitoring tools, and sound analysis techniques as a robust detection capability.
Security teams continue to miss intrusions that can be easily detected with their own data and current set of tools. As an example, many organizations deploy a SIEM, but they struggle to effectively parse, enrich, and filter their data to generate actionable intelligence and detect the bad guys. Join us at the Summit to learn first-hand from those who are generating practical solutions to common security challenges.
The Summit will explore the following topics:
- Detection techniques and tools
- Log collection
- Log enrichment (pre-ingestion or post-ingestion)
- Log analysis with emphasis on adversary detection
- Scripts that provide cool new ways of analyzing data
- Security in Continuous Monitoring
- Data Processing, Normalization, and Analysis
- Applying security expertise to data analytics
- False positive reduction
- Via scripts
- Via security expertise and processes
- Via data analytics
- Machine learning and statistical data analysis

“The more times this summit can be held, the better. I would recommend it to my entire SOC team and any other person I know would benefit from it!” - Todd Thomas, JM Family Enterprises
“As someone new to cyber security, I greatly appreciated hearing from and being able to talk to those on the front lines with battle scars, especially as they touched on the same idea across different industry sectors.” PJ Aguilar, EY
This event focuses on and delivers real, actionable solutions to the problems each of us face in our organizations. It also provided me with new and creative ways to find bad in our network. - Joel K, SwitchThink Solutions
“The content was really great and I was impressed how the presenters provided "nuts and bolts" information about their respective subjects.” – Scott Wickham, Chandler Gilbert Community College
Network with your peers and make invaluable connections
In addition to two days of in-depth discussions on tactical detection and data analysis, you'll have the opportunity to network with fellow attendees during breaks and at social events. Attendees tell us time and again that one of the greatest takeaways from SANS Summits is the many industry connections they forge or deepen during their time with us.

Compete in Cyber Defense and SIEM NetWars
The Tactical Detection & Data Analytics Summit & Training gives you two chance to test your skills in a fun and competitive environment with two nights of Cyber Defense NetWars and one evening of SIEM NetWars. Following the conclusion of the Summit, particapate in SIEM NetWars to help you develop the skills you need to efficiently and effectively leverage a SIEM. During the training portion of this event, compete in the all-new Cyber Defense Netwars challenge, where you'll take part in a defense-focused competition that tests your skills in Administration, Threat Hunting, Log Analysis, Packet Analysis, Cryptography, and much more.
Bundle your Summit experience with a course to expand your information security expertise
After the two-day Summit, choose from four closely aligned, immersion-style SANS courses to help you expand your information security expertise. SANS courses are taught by experienced practitioners who are among the best cybersecurity instructors in the world. They will provide you with the guidance and skills you need to defend your organization from ever-evolving threats. SAVE $400 off your Summit seat when you register for a course at SANS Tactical Detection & Data Analytics Summit & Training.
Available Courses
Title | Certification | Instructor |
---|---|---|
New SEC455: SIEM Design & Implementation |
—
|
Tim Garcia |
New SEC530: Defensible Security Architecture |
—
|
Justin Henderson |
New SEC599: Defeating Advanced Adversaries - Purple Team Tactics & Kill Chain Defenses | GDAT |
Bryce Galbraith |
SEC511: Continuous Monitoring and Security Operations | GMON |
Eric Conrad |
SEC555: SIEM with Tactical Analytics | GCDA |
John Hubbard |
Tactical Detection & Data Analytics Summit |
—
|
Justin Henderson John Hubbard |
Cyber Defense NetWars Tournament - Add-on (FREE with any 4-6 Day SANS Course Registration) |
—
|
Eric Conrad |