Group Purchasing
Group Purchasing

Course Features

GIAC Security Essentials (GSEC)

Learn About Certification

46 CPE

Apply your credits to renew your certifications.

Essential Skill Level

Course material is for individuals with an understanding of IT or cyber security concepts.

20 Hands-On Lab(s)

Apply what you learn with hands-on exercises and labs.

Role-aligned training mapped to DCWF/8140 workforce requirements, building Host Analyst skills in monitoring, detection, live investigation, and response.

MIL401H: Security Essentials for Host Analysts is a role-aligned training course for military and defense Host Analysts, aligned to DCWF 463 and DoD 8140 workforce requirements, covering network, cloud, and endpoint defense from asset discovery through live investigation exercises.

A Purpose-Built Course for Host Analysts

While derived from proven SANS content, MIL401H is separate and distinct from SEC401 and is purpose-built around the operational workflows, responsibilities, and readiness requirements for Host Analysts (DCWF 463) operating in military and defense environments.

Rather than approaching cybersecurity as a broad collection of topics, MIL401H organizes training around the day-to-day functions analysts perform in practice: asset and attack surface discovery, monitoring, detection, investigation, escalation, and response. Students build practical capability across networking, operating systems, cloud, and software supply chain security, endpoint defense, and incident response, while learning how those disciplines connect inside real-world cyber defense operations.

The course reflects how defensive operations have evolved. Students work with network detection and response (NDR) data, learn to recognize endpoint security bypass techniques, and use scripting and automation to move faster across Windows, Linux, macOS, and Microsoft cloud environments. A dedicated live investigation exercise pulls these skills together into a single scenario-driven forensics and incident response challenge.

The course is designed to support scalable workforce development across military and government organizations by aligning training directly to defined role requirements and operational outcomes. The emphasis is not simply on knowledge acquisition, but on preparing learners to operate effectively within modern SOC and cyber defense teams.

Hands-on labs reinforce this throughout. Rather than isolated technical exercises, the labs follow realistic operational scenarios requiring students to analyze activity, investigate suspicious behavior, and apply defensive techniques across network, endpoint, and cloud environments. The result is a workflow-driven learning experience focused on building practical analyst capability, not just course completion.

What You’ll Learn

  • Monitor and detect suspicious activity across network, endpoint, and cloud (DCWF 463)
  • Investigate security events and IOCs using traffic analysis and SIEM workflows
  • Identify adversary tactics and attack progression across the incident lifecycle
  • Implement defensive controls across Windows, Linux, macOS, cloud, and containers
  • Build skills in vulnerability analysis, threat detection, and incident response
  • Use analyst tools for log analysis, packet analysis, and event correlation
  • Understand how cyber defense operations integrate cloud and automation

Business Takeaways

  • Build scalable Host Analyst capability aligned to DCWF 463 / 8140
  • Standardize monitoring, detection, investigation, and response across cohorts
  • Reduce time-to-productivity for junior and transitioning cyber defense staff
  • Cut manual workload through built-in scripting and automation training
  • Strengthen readiness against software supply chain and endpoint threats
  • Deliver DCWF 463/8140-aligned training without building curriculum in-house
  • Develop analyst capability using realistic scenarios, hands-on workflows, and readiness

Author Statement

“Modern military operations depend on interconnected systems, communications networks, cloud services, mobile platforms, and digital infrastructure more than ever before. These capabilities provide tremendous operational advantages, but they also expand the attack surface available to adversaries. As military organizations become increasingly dependent on technology, cybersecurity becomes inseparable from mission readiness.

At first glance, a growing number of cyber incidents might be attributed to the increasing complexity and connectivity of modern systems. Yet technology alone does not explain the challenge. Adversaries continue to succeed because they understand how to exploit weaknesses in people, processes, and technology. The battlefield may be evolving, but the importance of strong security fundamentals remains unchanged.

The reality is that today's military professionals must be prepared to operate in environments where networks are contested, communications may be disrupted, and cyber attacks can directly affect mission success. In these conditions, cybersecurity is not simply an IT problem; it is a readiness issue. The ability to understand, identify, and respond to cyber threats has become an essential component of mission readiness.

MIL401H is built around a simple principle: offense informs defense. By understanding how adversaries operate and how attacks affect systems, students gain practical, immediately applicable knowledge that strengthens resilience, improves decision-making, and enhances mission effectiveness.

Just as importantly, the course is continually updated to reflect the evolving threat landscape and lessons learned from the real-world. Cybersecurity does not stand still, and neither should training. The goal is not simply to understand today's threats, but to build the enduring fundamentals necessary to adapt to tomorrow's.”

— Bryan Simon, GSE, Course Author

Meet Your Authors

Course Syllabus

Overview

In the first section, we explore the reality that while organizations strive to prevent as many attacks as possible, not all threats will be stopped. Therefore, timely detection becomes critical. Understanding how to construct a defensible network architecture—along with the various network designs and communication flows—is essential to responding effectively.

Next, we examine how, within any organization, not all data holds equal value. Some information may be routine, while other data is highly sensitive and critical, with its loss potentially causing irreparable damage. It’s crucial to understand how network-based attacks introduce risk to this critical data and where vulnerabilities lie within an organization’s infrastructure. This requires a thorough understanding of modern network communication protocols.

Cloud computing naturally comes into focus as part of modern public and private network discussions. No conversation about defensible networking would be complete without addressing the cloud—its security features, capabilities, and associated concerns.

As we delve deeper, it becomes clear that adversaries rely on our networks as much as we do. They pivot relentlessly from system to system, exploiting our infrastructure to reach their objectives. By learning how our networks function in relation to our unique needs, we can better detect and mitigate adversarial activity.

By the end of this section, you will have a solid understanding of defensible network architecture, protocols and packet analysis, virtualization and cloud fundamentals, and wireless network security.

Topics covered

  • Defensible Network Architecture
  • Protocols and Packet Analysis
  • Virtualization and Cloud Essentials
  • Software Supply Chain Security
  • Securing Wireless Networks

Labs

  • Lab 1.1: Tcpdump
  • Lab 1.2: Wireshark
  • Lab 1.3: AWS VPC Flow Logs

Overview

This section of the course explores large-scale threats to our systems and the strategies for defending against them, emphasizing the need for layered protection, known as defense-in-depth. We begin by laying the groundwork for information assurance, examining how security threats impact the confidentiality, integrity, and availability of our systems.

Since access controls are a fundamental component of defense-in-depth, we dive into the core aspects of identity and access management (IAM). Despite efforts to deprecate passwords as the primary authentication factor, they remain prevalent today, and many security breaches still stem from credential theft. This leads to an in-depth discussion on modern authentication methods and password security, particularly in the context of cloud computing. IAM is increasingly considered the new security perimeter for cloud-based systems, and its proper implementation is crucial for strong defense.

Midway through this section, we shift focus to contemporary security controls that are effective against today's adversaries. We do this by examining frameworks such as the Center for Internet Security (CIS) Controls, the NIST Cybersecurity Framework, and the MITRE ATT&CK knowledge base.

As we revisit earlier discussions on network architecture, we naturally explore additional ways to bolster network defensibility. This brings us to a broader environmental approach, emphasizing how best to secure data both in transit and at rest, leading to an in-depth conversation on data loss prevention (DLP) techniques.

Finally, no discussion on defense-in-depth would be complete without addressing one of the most critical technologies in use today-mobile devices. We conclude this section with a dedicated module on mobile devices, examining both the benefits and the security risks they present. Topics such as Bring Your Own Device (BYOD) and Mobile Device Management (MDM) are explored in detail to round out the discussion.

Topics covered

  • Defense-in-Depth
  • IAM, Authentication and Password Security
  • Security Frameworks
  • Data Loss Prevention
  • Mobile Device Security

Labs

  • Lab 2.1: Password Auditing
  • Lab 2.2: Data Loss Prevention
  • Lab 2.3: Mobile Device Backup Recovery

Overview

In this section, we turn our attention to the various areas within our environment where vulnerabilities can emerge. We begin by defining what constitutes a vulnerability and how to establish an effective vulnerability assessment program.

Since vulnerabilities represent the weaknesses that adversaries exploit, a discussion on this topic must also include an in-depth examination of modern attack methodologies, with real-world examples of compromises. Among the potential areas for vulnerabilities, web applications pose some of the greatest risks, often leading to the most severe consequences. Due to the extensive vulnerabilities associated with web applications, an entire module is dedicated to exploring web application security concepts.

While vulnerabilities may provide adversaries with easy access to systems, it's important to remember that their actions post-compromise can often be detected. By effectively leveraging the logging capabilities of hardware and software, we can detect adversarial activity more quickly. This capability is covered in our penultimate module, which focuses on Security Operations and Log Management.

Finally, it's crucial to have a well-structured response plan for handling any compromises. The methodology for an appropriate incident response is the focus of the final module in this section.

Topics covered

  • Vulnerability Assessments
  • Penetration Testing
  • Attacks and Malicious Software
  • Web Application Security
  • Security Operations, Log Management, and DFIR

Labs

  • Lab 3.1: Network Discovery
  • Lab 3.2: Binary File Analysis and Characterization
  • Lab 3.3: Web App Exploitation
  • Lab 3.4: SIEM Log Analysis

Overview

There is no single solution that guarantees complete security, but one technology that can address many security challenges--though often improperly deployed--is cryptography. In the first half of this section, we will delve into various cryptographic concepts and explore how they can be effectively used to safeguard an organization's assets.

In the second half, our focus shifts to prevention technologies that can stop adversaries from gaining access to your organization. This includes the use of firewalls and intrusion prevention systems. We will also examine detection technologies, such as intrusion detection systems, which can identify the presence of an adversary. These prevention and detection methods can be deployed at both the network and endpoint levels, and we will discuss the similarities and differences in their implementation.

Topics covered

  • Cryptography
  • Cryptography Algorithms and Deployment
  • Applying Cryptography
  • Network Security Devices
  • Endpoint Security and Bypass Techniques

Labs

  • Lab 4.1: Hashing and Cryptographic Validation
  • Lab 4.2: Encryption and Decryption
  • Lab 4.3: Intrusion Detection and Network Security Monitoring

Overview

Remember when Windows was simple? Back in the days of Windows XP desktops in small workgroups, things seemed straightforward. But much has changed. Today, we manage Windows tablets, Azure, Active Directory, PowerShell, Microsoft 365 (formerly Office 365), Hyper-V, Virtual Desktop Infrastructure, and more. As Microsoft competes with cloud giants like Google and Amazon, securing the cloud has become a critical challenge.

Windows remains the most widely used and targeted desktop operating system globally. At the same time, the complexities of Active Directory, Public Key Infrastructure (PKI), BitLocker, endpoint security, and user access control present both challenges and opportunities. This course section will guide you through mastering the essentials of Windows security while introducing tools that can streamline and automate your work, whether on-premises or in the cloud with Microsoft Azure. By the end of this section, you'll have a solid foundation in Windows security, including automation and auditing within the Windows ecosystem.

Topics covered

  • Windows Security Architecture
  • Windows as a Service
  • Windows Access Controls
  • Enforcing Security Configurations
  • Microsoft Cloud, Automation, Logging, and Auditing

Labs

  • Lab 5.1: Windows Process Exploration
  • Lab 5.2: Windows Filesystem Permissions
  • Lab 5.3: Applying Windows System Security Policies
  • Lab 5.4: Using PowerShell for Speed and Scale

Overview

While organizations may not have a large number of Linux systems, those they do have are often the most critical and require the highest levels of protection. This course section focuses on providing practical guidance to enhance the security of any Linux system. It offers step-by-step instructions with foundational background for Linux beginners, as well as advanced security advice and best practices for administrators of varying expertise levels.

Given Linux's reputation as a free and open-source operating system, it's no surprise that many advanced security concepts are first developed for Linux. One notable example is containers, which offer powerful and flexible capabilities for cloud computing deployments. Although containers weren't initially designed for security purposes, they are built on the principle of minimization, which can be leveraged as part of a defense-in-depth security strategy. We will explore what containers represent for information security, what they do not, and best practices for their management.

Finally, we conclude this section with a review of Apple's macOS, which is built on a UNIX foundation. Despite its robust hardware and software security features, macOS is often misunderstood regarding what it can and cannot achieve in terms of security.

Topics covered

  • Linux Fundamentals
  • Containerized Security
  • Linux Security Enhancements and Infrastructure
  • macOS Security

Labs

  • Lab 6.1: Linux Permissions
  • Lab 6.2: Linux Containers
  • Lab 6.3: Linux Logging and Auditing

Virtual (OnDemand) | Self-Paced, 4 Months Access | $8,780 USD

Register

Things You Need To Know

Important! Bring your own system configured according to these instructions.

If you do not carefully read and follow these instructions, you will not be able to fully participate in the hands-on exercises. Please arrive with a system meeting all specified requirements.

Back up your system before class and ensure it contains no sensitive or critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • CRITICAL: Apple Silicon devices (M-Series Chips) cannot perform the virtualization required for the labs and cannot be used for this course.
  • CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A 64-bit, 2.0+ GHz or newer processor is mandatory.
  • BIOS settings must enable virtualization technology, such as "Intel-VTx" or "AMD-V" extensions. Be absolutely certain you can access your BIOS/UEFI if it is password protected, in case changes are necessary.
  • 16GB of RAM or more is required.
  • 100GB of free internal storage space or more is required.
  • At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for laptops with only USB-C ports. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Wireless networking (802.11) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration and Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 10.15.x or newer (Intel-based Macs only).
  • Linux hosts are not supported in the classroom due to the variability of Linux configurations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and virtual machines.
  • Fully update your host operating system prior to class to ensure you have the correct drivers and patches installed.
  • Local Administrator access is required. If your organization will not permit this access for the duration of the course, arrange to bring a different laptop.
  • Ensure that antivirus or endpoint protection software can be disabled or fully removed, and that you have the administrative privileges to do so. These products can prevent successful lab completion.
  • Any filtering of egress traffic may prevent successful lab completion. Firewalls may need to be disabled — ensure you have the administrative privileges to do so.
  • Download and install VMware Workstation Pro 16.2.X+ (for Windows 10 hosts), VMware Workstation Pro 17.0.0+ (for Windows 11 hosts), or VMware Fusion Pro 12.2+ (for Intel-based macOS hosts) prior to class.
  • On Windows hosts, VMware products may not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine before class — this may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are included in the setup documentation accompanying your course materials.
  • Download and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts – Intel-based ONLY). These tools are also included in your downloaded course materials.

Your course media is delivered via download. The media files for class can be large. Many are in the 30 GB range. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.

If you have additional questions about the laptop specifications, please contact customer service.

MIL401H is designed for military, government, and defense personnel preparing to perform Host Analyst functions aligned to DCWF 463 / DoD 8140 workforce requirements. The course is built for learners who need practical capability in monitoring, detection, investigation, escalation, and defensive cyber operations, not broad, general cybersecurity awareness.

You should attend if:

  • You are preparing for a Host Analyst, SOC analyst, monitoring and triage, or defensive cyber operations role
  • You are transitioning into cyber defense from another military, intelligence, IT, communications, or operational background
  • You support workforce development initiatives aligned to DCWF, DoD 8140, CFP, DCCF, or similar cyber workforce frameworks
  • You need hands-on training focused on operational analyst workflows, incident response, logging, SIEM operations, and defensive monitoring
  • You are building or scaling analyst capability across military, government, or defense cyber teams
  • You need a structured, role-aligned pathway into modern cyber defense operations using practical labs and operational scenarios

This training course aligns to NICE / DCWF workforce roles including:

  • Primary Alignment
    • Host Analyst (OPM 463)
  • Supporting / Adjacent Roles
    • Cyber Defense Infrastructure Support Specialist (OPM 521)
    • Network Operations Specialist (OPM 441)
    • Systems Security Analyst (OPM 461)
    • Incident Responder (OPM 531)

MIL401H is specifically designed to support workforce development for Host Analyst functions aligned to DCWF 463 and DoD 8140 role requirements, with emphasis on monitoring, detection, investigation, escalation, and defensive cyber operations workflows.

The GIAC Security Essentials (GSEC) certification validates a practitioner's knowledge of information security beyond simple terminology and concepts. GSEC certification holders are demonstrating that they are qualified for hands-on IT systems roles with respect to security tasks.

  • Defense in depth, access control and password management
  • Cryptography: basic concepts, algorithms and deployment, and application
  • Cloud: AWS and Azure operations
  • Defensible network architecture, networking and protocols, and network security
  • Incident handling and response, data loss prevention, mobile device security, vulnerability scanning and penetration testing
  • Linux: Fundamentals, hardening and securing
  • SIEM, critical controls, and exploit mitigation
  • Web communication security, virtualization and cloud security, and endpoint security
  • Windows: access controls, automation, auditing, forensics, security infrastructure, and services

More Certification Details

  • Coursebooks and lab workbook with over 500 pages of exercises
  • Virtual machines pre-installed with essential tools
  • TCP/IP reference guides
  • MP3 audio files of complete course lectures

The MIL401H course covers all the core areas of security and assumes a basic understanding of technology, networks, and security. For those who are new to the field and have no background knowledge, SEC275: Foundations - Computers, Technology and Security would be the recommended starting point. While this course is not a prerequisite for MIL401H, it does provide the introductory knowledge to help maximize the experience with MIL401H training.

MIL401H is part of a role-aligned Host Analyst (DCWF 463) workforce development pathway designed to support defensive cyber operations, monitoring and triage, SOC operations, and incident response functions aligned to DoD 8140 workforce requirements.

The course establishes the foundational operational capability required for Host Analyst roles and prepares learners for progression into more specialized defensive cyber operations training.

Depending on your operational role or workforce development pathway, recommended next steps include:

Cyber Defense Operations / SOC Progression

Incident Response / DFIR

Cloud and Defensive Infrastructure

Advanced Defensive Operations

Modern cyber defense operations depend on analysts who can monitor, detect, investigate, escalate, and respond effectively across network, endpoint, cloud, and hybrid environments. Those capabilities are not built through isolated technical skills alone—they require a structured operational foundation aligned to how defensive cyber operations are actually performed.

MIL401H establishes that foundation by developing the core technical and analytical capabilities required for Cyber Defense Analyst roles aligned to DCWF / DoD 8140 workforce requirements. The course focuses on the operational disciplines that underpin effective cyber defense, including:

  • Monitoring and analyzing network, endpoint, and cloud activity
  • Investigating suspicious events and indicators of compromise
  • Understanding adversary behavior, attack techniques, and escalation paths
  • Applying defensive controls across Windows, Linux, cloud, and hybrid infrastructure
  • Using SIEM, logging, traffic analysis, and incident response workflows in operational environments
  • Supporting defensive cyber operations through structured, workflow-driven analysis and response

These are the capabilities that allow organizations to build scalable analyst readiness across SOC and cyber defense teams. Without them, advanced tooling and specialized capabilities operate without the operational foundation required to use them effectively.

Cyber defense organizations increasingly need analysts who can contribute operationally from day one, not simply understand cybersecurity concepts in theory. MIL401H is designed to build the practical monitoring, detection, investigation, and response capabilities required for Host Analyst roles aligned to DCWF 463 / DoD 8140 workforce requirements.

Here is what that means in practice:

  • Build operational Cyber Defense Analyst capability: MIL401H is structured around how defensive cyber operations actually function: monitoring activity, analyzing events, investigating suspicious behavior, escalating incidents, and supporting response operations across network, endpoint, cloud, and hybrid environments.
  • Develop practical, hands-on analyst experience: The course uses realistic operational scenarios and hands-on labs to reinforce analyst workflows using SIEM processes, traffic analysis, logging, vulnerability investigation, defensive tooling, and incident response techniques. The emphasis is on operational readiness—not passive learning.
  • Prepare for modern SOC and cyber defense environments: Students develop practical familiarity with the technologies and workflows commonly used in modern cyber defense operations, including cloud infrastructure, defensive monitoring, AI-assisted analysis, and hybrid enterprise environments.
  • Establish a foundation for advanced defensive cyber operations training: MIL401H provides the operational and technical foundation required for progression into more advanced SOC, cyber defense, threat detection, DFIR, and cloud security training pathways.
  • Align to recognized workforce frameworks and career pathways: The course is aligned to Cyber Defense Analyst-style workforce requirements used across military, government, and defense organizations, helping students build capability directly relevant to operational cyber defense roles.
  • Learn skills that transfer immediately to operational environments: The labs, workflows, and scenarios in MIL401C are designed around realistic analyst activities and operational decision-making. Students return to work with practical capability they can apply immediately within SOC and cyber defense teams.

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources

MIL401H: Security Essentials for Host Analysts | SANS Institute