Christopher Crowley
Senior InstructorIndependent Consultant at Montance, LLC
Specialities
Cyber Defense, Offensive Operations

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCyber Defense, Offensive Operations

Chris Crowley has spent his career transforming how defenders detect and respond to advanced threats—most recently harnessing data science and artificial intelligence to make security operations smarter and more adaptive. As a Senior Instructor at the SANS Institute, he teaches SEC511: Cybersecurity Engineering – Advanced Threat Detection and Monitoring, SEC504: Hacker Tools, Techniques, and Incident Handling, and SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals. His mission: to equip defenders with the technical depth and analytical mindset to thrive in a world where AI reshapes both attacks and defense.
Starting as a systems and network engineer, Chris advanced into cybersecurity leadership—managing incident-response teams and building detection architectures for federal and commercial environments. He led security operations at the U.S. Department of Energy, establishing forensic programs and 24×7 monitoring that improved response speed and reliability. Over the past two decades, he has trained hundreds of defenders and advised dozens of enterprise SOCs on operational maturity. Those experiences directly inform his courses, where students learn to design scalable detection systems, analyze adversary behavior, and lead coordinated responses with confidence.
Through Montance® LLC and as an IANS Subject Matter Expert, Chris helps organizations integrate machine learning and AI-driven analytics into SOC workflows, enhancing detection fidelity while reducing analyst fatigue. In SEC595, he demystifies the use of large language models (LLMs) and AI—teaching practical methods for automating analysis, generating intelligence summaries, and turning raw data into action. Widely regarded for his expertise in SOC design and operational maturity, his research and frameworks are used worldwide to benchmark and improve defensive posture. He holds nine GIAC certifications—including GCIA, GCIH, GCFA, GPEN, GREM, and GXPN—and the CISSP® credential. He is the lead author of the annual SANS SOC Survey and a frequent speaker at RSA Conference and Black Hat. Chris Crowley is also a faculty member of the SANS Technology Institute, an NSA Center of Academic Excellence in Cyber Defense and multi-year winner of the National Cyber League competition.
Known for his clarity, realism, and humor, Chris makes complex operations and AI-driven analytics approachable and actionable. He’s most proud when former students share how his courses helped them stop real attacks or build new programs—proof that learning, when applied, changes outcomes. Chris believes the defenders of tomorrow will pair human intuition with machine precision—and he’s passionate about preparing his students to lead that transformation. Outside cybersecurity, he’s an avid mountain biker and culinary explorer, pursuits that mirror the curiosity and endurance he brings to the art of defense.
Each day's content was better and better, presented in the unbeatable combination of Chris Crowley's lecture followed by incredible labs. I'm simply amazed at Chris's vast knowledge and experience. He is truly a consummate professional who is unquestionably dedicated to his students.
Chris Crowley is an outstanding teacher and presenter! I learned so much from him in SEC504, it's unbelievable.
Chris is awesome! He's excellent at answering questions and giving real-world examples. I'm very grateful to have been able to take this class and will highly recommend to peers of mine that they take SANS classes taught by Chris, as I know they'd learn a ton from him as well! Thank you, SANS, for another excellent course!
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
The SANS Fall Cyber Solutions Fest 2026 SOC Track brings together frontline defenders, analysts, engineers, and SOC leaders to dissect the evolving threat landscape and the technologies reshaping modern security operations.

Crowley has published the SOC Survey for a decade. This session will start with high level findings, then deep dive into Jupyterlab python minutae as he discusses the analysis he performed to attempt to extract interesting correlations.

Crowley will review findings from the 2026 survey: AI use, technology satisfaction, staffing, metrics, funding, and security operations capabilities.

Discover how to effectively incorporate artificial intelligence and machine learning into SOC detection engineering workflows.

We'll discuss the current state of operational deployment in security operations, worthwhile use and implementation scenarios, and guide you on the risks and potential exposures by talking through current attack vectors in AI/ML workflows and agentic applications.

AI won't fix a broken SOC, but deployed right, it changes everything.

Over the past few years, the cyber threat landscape has been defined by supply chain compromises, the targeting of cloud and SaaS environments, and the growing use of AI by both defenders and adversaries.

Discover how to effectively incorporate AI and machine learning into your SOC detection engineering workflows.

Learn how to “shape and make” AI/ML enhanced detections that strengthen your defensive posture.

Join SANS Instructor Chris Crowley and Tidal Cyber Co-Founder and Chief Innovation Officer Frank Duff to explore how to move beyond theory and operationalize MITRE ATT&CK across your environment.

Join us to hear how others are succeeding and failing to maintain an operational balance between competing internal priorities and threats which seem to relentlessly improve.

Register for the SANS 2025 SOC Survey webcast today and learn how to use results from this year’s survey to inform and recalibrate your near-term plans and long-term goals.

In this brief, informative, and useful session, Christopher Crowley will discuss the concept of a variational autoencoder, then show how you could implement this to train an autoencoder based on your logs.

大規模言語モデル (LLM)に基づくGPT(Generative Pretrained Transformers)は、多くの課題に対して優れた性能を発揮します。しかし、ログデータ内の異常値を見つけるためのトレーニングはされていません。

GPTs (Generative Pretrained Transformers) based on Large Language Models are great for a lot of challenges. But they're not trained to find outliers within your log data.

For people who don't work in a SOC, or in cybersecurity at all, the image of a cybersecurity operations center is that of an all-seeing, all-knowing marvel of technology. For those of us who work in a SOC, we know the technology requires constant care and maintenance to preserve visibility into the systems we're protecting. If we can preserve that visibility, we then strive to deploy appropriate and effective detections. Once we've tuned those detections due to excessive false positives, we flexibly adjust them based on changing data. We also tune them to attempt to keep up with adaptive threats. If we can manage to preserve visibility, and implement good detections, we can start to hunt in the various troves of data for undetected threats. As we're hunting in the disparate data sources, we pursue the objective of fusion of information into that all-seeing, all-knowing marvel.Wherever you are on this journey from wizard behind the curtain to fully-integrated multi-cloud, machine learning, optimized security operations; you can learn something from your vendors and peers in this SANS Cyber Solutions Fest SOC & SOAR Track.

On this webcast, Chris Crowley examines the 2024 SOC Survey results to understand how SOCs are architectured, favorite and frustrating technologies, staffing, funding, threat intel, and automation.

Attend the Cyber Solutions Fest to explore implementations via the lens of people, process, and technology. There will also be highlights on managed service offerings and cloud deployments, as our IT deployment and the security applied to them becomes more distributed within our supply chain and vendor partnerships.There will be examples of lessons learned from customer deployments, as well as insights from their tool developers and designers about how they see the tools being deployed. The people building the next generation of tools will identify where they project the market to go. Attend this event to get all of this and much, much more!

Presentation 1 - DevSecOps - We Are The Champions and 2023 Chris Edmundson, Associate InstructorPresentation 2 - 2023 SOC Survey - Highlights and Deep Drive presentedChristopher Crowley, Senior Instructor

With survey data from active SOC managers and analysts, this webcast will cover the escalating movement to the cloud, orchestration, and tool changes. It explores the developing promise of deception, AI and machine learning.

Review relevant educational resources made with contribution from this instructor.