Matt Bromiley
Certified InstructorSecurity R&D at Prophet Security
Specialities
Cybersecurity Leadership

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCybersecurity Leadership
Matt Bromiley is the Lead Solutions Engineer at LimaCharlie, where they build and maintain some of the best cybersecurity infrastructure capabilities. He has 12+ years of experience in the cybersecurity industry making life difficult for cyber threat actors. He also serves as a GIAC Advisory Board member, a subject-matter expert for the SANS Security Awareness, and a technical writer for the SANS Analyst Program. Matt brings his passion for incident response and leadership to the classroom as a SANS Instructor for LDR553: Cyber Incident Management.
"SANS is the only organization where I have seen students bursting to get out of class to apply their newly acquired skills to current casework," he says.
Matt fell into this career somewhat by accident, taking on a junior analyst role because the team was great and the work sounded exciting. "My first day, I was working a keylogger case that required me to examine various hardware, test information, extract USB information, and decode logged keys," he recalls. "I was hooked!"
Since then, Matt has built a wide-ranging career that gives him a broad perspective on digital forensics. He has helped organizations of all types and sizes, from multinational conglomerates to small, regional companies. His skills run the gamut from disk, database and network forensics to malware analysis and classification, incident response/triage and threat intelligence, memory analysis, log analytics, and network security monitoring. Along with traditional database forensics, Matt has experience deploying such tools as Elasticsearch, Splunk, and Hadoop to assist in large-scale forensic investigations, network security monitoring, and rapid forensic analysis on over 100 systems and over 10TB of logs. He has a particular interest in database and Linux forensics, as well as in building scalable analysis tools using free and open-source software.
Matt understands the importance of making the information he's teaching relatable to students. "It's easy to picture every scenario as an advanced persistent threat attack, but some students don't perform those investigations," he explains. So Matt looks for the common ground among all of the specific artifacts and the bigger picture that each artifact helps develop, thus enabling students to enhance their investigations and succeed in their day-to-day careers.
His extensive experience in digital forensics shines through in his teaching. An energetic, enthusiastic instructor, Matt sees digital forensics as a puzzle that is begging to be solved. He loves piecing together artifacts to tell a vivid story about what has happened, and he strives to inspire his students to have the same passion for "completing the puzzle".
Outside of work, Matt loves spending time with his family, cooking Texas BBQ, and making his house as automated as possible in hopes that it will one day do work for him.
Matt continues to demonstrate passion for the topics being taught. The real-world examples he provides are a great addition to supplement the content in the book.
FOR508 lead by Matt Bromiley has dramatically increased my DFIR skills in less than a week, anyone serious about incident response or windows forensics must take this course.
I really valued Matt's lectures, and most importantly, his enthusiasm and expertise on forensics.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
New SANS research reveals how organizations are managing human-layer risk in the age of AI. Discover where incidents begin, how AI is reshaping user risk, what drives investment, and the strategies security leaders believe best strengthen human defenses.

The SANS Fall Cyber Solutions Fest 2026 AI Track explores how artificial intelligence is transforming cybersecurity—from accelerating threat detection and response to reshaping automation, analytics, and SOC workflows.

The SANS 2026 Government Forum, presented in partnership with Carahsoft, brings together federal, state, and local government cybersecurity professionals to explore the evolving threat landscape and the solutions shaping secure, mission-ready environments.

Risk-Adaptive DLP Strategy Guide

This webcast examines how OpenText Endpoint Forensics and Response can bridge the gap between detection tools and deep forensic investigation, enabling organizations to pivot directly from discovery to containment and recovery.

Your biggest email threats aren’t strangers, they’re trusted partners whose accounts have been compromised. Discover how self‑learning AI uncovers subtle behavioral shifts that signal BEC and supply chain attacks before damage is done.

Identity compromise now drives 80% of cyber intrusions—making it the primary attack vector in modern cybersecurity. When Active Directory fails, entire business operations halt: employees can't authenticate, applications fail, and critical services go dark.

Artificial intelligence is transforming how security teams detect threats, automate response, and make critical decisions—but effective adoption requires more than just powerful tools. This Solutions Track session explores real-world approaches to applying AI in cybersecurity programs, focusing on how to move from theory to measurable impact.

This session explores the strategic shift toward unified DFIR platforms that merge forensic-grade investigation capabilities with incident response. Attendees will gain insight into how integrating evidence collection, artifact triage, endpoint isolation, and threat remediation into a single workflow reduces tool fatigue, shortens dwell time, and improves regulatory compliance.

This isn't your typical "don't pay ransoms" talk. We'll explore the harsh realities where business continuity and regulatory pressure create impossible choices, providing practical frameworks for decision-making under duress, technical protocols for verifying attacker claims, and strategies for maintaining leverage when all seems lost.

Cybersecurity leaders and compliance professionals are under increasing pressure to meet a growing array of global regulations—all while maintaining effective threat detection and response capabilities. Traditional monitoring is no longer enough. Full Packet Capture (FPC) is rapidly emerging as a foundational requirement—not only for real-time visibility and forensic analysis, but as a direct response to regulatory mandates in the U.S., EU, and beyond.

Join Matt Bromiley and Chris Schwind for a first look at Tanium Autonomous Endpoint Management (AEM), a next-generation platform that unifies IT and Security operations with AI-driven intelligence.

Join leading experts as they discuss how AI is transforming business operations, enhancing decision-making, and creating new opportunities for growth.

Join us on September 16, 2025, at 1:00pm ET for a deep dive into how modern enterprises can keep pace with today’s fast-moving threat landscape.

This webcast explores how to bring clarity and control back to your hybrid security strategy—with practical guidance on Zero Trust, unified monitoring, and the evolving role of AI in modern defense.

Join us at the 2025 Government Security Forum on July 22nd at 10:00 AM ET to gain intelligence, tools, and real-world strategies needed to defend your agency against next-generation cyber threats. Register for free today!

Join us for the Ransomware Summit Solutions Track 2025 to explore the full spectrum of ransomware dynamics. Learn how threat actors are adapting their strategies, where vulnerabilities still exist, and why the cycle of paying ransoms endures.

Explore the latest breakthroughs shaping the future of cybersecurity. The Emerging Technology track brings together though leaders and innovators to showcase advancements. Gain insights on how these developments will impact defense strategies in the coming years.

As cloud security controls mature, it's common to find that a wide variety of security controls and configuration capabilities are melding into a single platform or service fabric, in addition to the cloud provider infrastructure. Ranging from CNAPP to CSPM to CWPP and beyond, controls that cover the pipeline, workload security, cloud environment configuration, IaC templates, and runtime (and much more) are starting to evolve into a much more consolidated set of solutions. What does cloud security look like in 2024 and beyond? Chances are, you are talking to a set of providers that offer a lot of these features, and that's a great thing for security and cloud engineering teams.Register for this webcast now and be among the first to receive this white paper.

Two years ago, artificial intelligence (AI) was primarily a buzzword, but the times have changed quickly! The rapid integration of artificial intelligence in multiple sectors has revolutionized operational efficiency, data analytics, and automation.Join us for our AI-focused solutions track and explore how leading cybersecurity companies are implementing AI into their offerings, along with discussions on a variety of topics, including successes, challenges, and strategies to utilize these emerging technologies to help us secure our organizations and accomplish tasks that weren’t feasible until now.

Review relevant educational resources made with contribution from this instructor.