Brian Almond
Certified InstructorPrincipal Security Researcher at Presidio
Specialities
Offensive Operations

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsOffensive Operations

Brian Almond is a SANS Certified Instructor, Director of Engineering Advanced Security at Presidio, and a cybersecurity leader whose career spans offensive operations, threat hunting, incident response, and security architecture. He teaches SEC598: AI and Security Automation for Red, Blue, and Purple Teams and SEC599: Defeating Advanced Adversaries – Purple Team Tactics & Kill Chain Defenses, bringing students a practitioner-focused perspective shaped by years of building enterprise detection and response programs. His experience designing purple team engagements and advanced detection strategies gives learners practical insight into how attackers operate and how defenders can rapidly detect and contain them in modern environments.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
What? A webcast in 2025 about phishing...haven’t we sorted that stuff yet? Almost! :)

In cybersecurity, adversaries continuously develop innovative methods to circumvent traditional security controls. This presentation delves into these unconventional techniques and highlights how they bypass established defense mechanisms. Based on real-world case studies, we examine many of these abnormal approaches, including non-standard tools, novel C2 methods, and developer tools used to subvert security controls. Understanding the diversity in adversary sophistication is crucial. Some groups use highly technical hacks, developing custom exploits and advanced malware.

Review relevant educational resources made with contribution from this instructor.