SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsJoin us for three nights at the Hyatt Regency Riyadh Olaya for our next Community Night Talks in Riyadh! October 6, 13 and 20, 2025
SANS Community Nights are a great way to stay in touch with your local InfoSec community and to hear the latest in technical wizardry, industry intelligence, and thought leadership from our amazing instructors.
View the agendas for Monday, October 6th, 13th and 20th below.
Location: Hyatt Regency Riyadh Olaya, Olaya St, Al Olaya, Riyadh 12213
Abstract: Large Language Models (LLMs) such as ChatGPT, Claude, and Grok have become very powerful. This talk is full of live demonstrations of the kinds of things information security professionals can do with the LLMs. Examples include analyzing and manipulating shell code, writing exfiltration code, analyzing logs, and more.
Presented by
Timothy McKenzie
Principal Instructor
Abstract: Actionable intelligence is only as good as your ability to share it — quickly, reliably, and with the right context. In this talk, we’ll explore how MISP can be used not just as a threat intel repository, but as a powerful engine for real-time collaboration and operational impact. We’ll cover how to make MISP highly available, build and sustain a community around it, and create qualitative events that provide the necessary context for detection, decision-making, and response. You’ll also see how we’re integrating AI into our workflows to improve speed, reduce manual effort, and enrich intelligence automatically — without sacrificing quality. Whether you’re just getting started with MISP or looking to take your threat sharing to the next level, this talk will give you concrete ideas to make it work in high-pressure, real-world environments.
Presented by
Kevin Holvoet
Certified Instructor
Abstract: In Digital Forensics, Incident Response, and other Cyber Security topics, we're frequently tasked with consuming HUGE amounts of data and finding the "interesting" parts quickly. We've had great tools to do this for decades. But, those tools we're optimized for old computing hardware. In our modern day we have setups with multiple CPU cores and flash storage. This talk will present some techniques to speed up those old techniques fully utilizing modern hardware.
Presented by
Mark Jeanmougin
Certified Instructor
Timothy McKenzie redefined offensive security through decades of Red and Purple Team operations, advancing the industry’s threat simulation standards and influencing thousands of cybersecurity professionals with his adversary emulation strategies.
Learn moreKevin holds a Master of Science in Applied Informatics, Software Development & Distributed Systems. He is also an NSA Center of Academic Excellence in Cyber Defense and multiple winner of the National Cyber League competition.
Learn moreMark loves the ever-changing landscape of security and views it as a puzzle that must be solved. He especially loves the challenges in ICS security, where the cyber meets the physical. There is no greater success than a safe and effective process.
Learn moreTitle: Information Security and LLMs Presentation by Timothy McKenzie, Principal Instructor
Title: From Intel to Action: Building a High-Speed Early Warning System with MISP and AI Presentation by Kevin Holvoet, Certified Instructor
Title: Save Time with Modern Search Techniques Presentation by Mark Jeanmougin, Certified Instructor