Group Purchasing
Group Purchasing

Anurag Khanna

Certified InstructorDirector, Incident Response at CrowdStrike

Specialities

Offensive Operations

Connect with Anurag

Anurag Khanna

About Anurag Khanna

Anurag Khanna is a SANS Certified Instructor and Director of Incident Response at CrowdStrike. He teaches SEC504: Hacker Tools, Techniques, and Incident Handling, a course aligned with the GIAC Certified Incident Handler (GCIH) certification and built around hands‑on labs. Drawing on frontline breach response expertise across the Asia Pacific region, he equips defenders to recognize attacker tradecraft, respond under pressure, and build repeatable incident handling workflows.

Anurag’s career bridges offensive and defensive domains. Early roles included network operations at Google and security consulting, followed by research and red teaming with positions at EY, Symantec Security Response, and IBM X‑Force. He later served as Senior/Solution Architect at Verizon and Security Practice Architect at HPE before pivoting fully into DFIR leadership as Lead Investigator at Symantec and then as Principal Consultant at Mandiant. Today, as Director of Incident Response at CrowdStrike, he leads investigations involving nation‑state APTs and organized eCrime across the region—experience that directly informs the labs and real‑world scenarios students tackle in class.

His credentials include GIAC Security Expert (GSE #97), GIAC Certified Detection Analyst (GCDA), Certificate of Cloud Security Knowledge (CCSK), and Red Hat Certified Engineer (RHCE). He holds an MS in Digital Forensics Science (Champlain College), an MBA in Networks & IT Infrastructure (Symbiosis International University), and a B.Tech. in Information Technology (Punjab Technical University). Anurag is also a faculty member of the SANS Technology Institute, a member of the NSA Centers of Academic Excellence in Cyber Defense, and a multi-year National Cyber League competition winner. Beyond corporate incident response, Anurag designs hands‑on training on Active Directory attack, defense, and investigation, reflecting his ongoing research and speaking engagements at Black Hat Asia, Virus Bulletin, BSides, and the RSA Conference.

In the classroom, Anurag is known for his calm, incident‑commander style and scenario‑driven labs that simulate active adversaries. By week’s end, students are able to triage intrusion timelines, analyze Windows and Linux credential abuse, pivot from indicators to durable detections, craft and execute evidence‑based eviction plans, and prepare effectively for the GCIH exam—all grounded in repeatable processes he’s used during high‑stakes engagements.

Qualifications Summary
  • SANS Certified Instructor teaching SEC504: Hacker Tools, Techniques, and Incident Handling (GCIH‑aligned; hands‑on labs).
  • Director, Incident Response, CrowdStrike, leading DFIR investigations across Asia Pacific.
  • Former Principal Consultant (Mandiant) and Lead Investigator (Symantec); earlier roles with IBM X‑Force, Verizon, HPE, EY, and Symantec Security Response.
  • GIAC Security Expert (GSE #97); additional certifications include GIAC Certified Detection Analyst (GCDA), Certificate of Cloud Security Knowledge (CCSK), and Red Hat Certified Engineer (RHCE).
  • Speaker at Black Hat Asia, Virus Bulletin, BSides, and RSA Conference; focusing on Active Directory attack and defense.
  • Academic background: MS (Digital Forensics Science), MBA (Networks & IT Infrastructure), B.Tech. (Information Technology).

Press & Media