Dr. Johannes Ullrich
FellowDean of Research at SANS Technology Institute
Specialities
Cyber Defense, Cloud Security

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCyber Defense, Cloud Security

Dr. Johannes Ullrich is the Dean of Research for SANS Technology Institute, a SANS Faculty Fellow, and founder of the Internet Storm Center which provides a free analysis and warning service to thousands of Internet users and organizations. He is the host of the SANS Internet Storm Center Daily Stormcast, a daily podcast that provides a brief 5-minute summary of current network security related events, co-author of SANS SEC522: Application Security: Securing Web Applications, APIs, and Microservices, and can be found teaching his own courses as well as SEC503: Network Monitoring and Threat Detection In-Depth.
Prior to his two decades at SANS, Johannes worked as a lead support engineer for a web development company and as a research physicist. Johannes has always been attracted to the fast pace of information security and curious to understand and measure the intricate dependencies of attacks and countermeasures. While the fast pace of the field can be overwhelming at times, it does offer constant opportunities for learning, and any change and impact is quickly measurable.
Johannes’s first network was a lab network used to remote control physics experiments. When he first got his hands on an "early" cable modem, which allowed him to control experiments from home, he overlooked the fact that the router (which he built himself from a Linux distribution) was also an open mail relay. Of course, it didn't take long for a spammer to find and abuse it, which led to an angry call from his ISP. Like most of us who start to worry about security after an incident, that was when he started learning about firewalls and security. In the process, he discovered his interest in collecting data about the attackers scanning for systems like his own. This led to the development of DShield.org, a website that still today collects logs from users worldwide to better understand these attacks.
Johannes’s daily work revolves around the Internet Storm Center. Leading this group brings him in direct contact with packets, web applications, and malware on a day-to-day basis. This work keeps his skills sharp and relevant while informing the material he presents in class. Johannes enjoys working for SANS due to the ability to disseminate what he’s learned researching current attacks, as well as bringing him in contact with students who are working in the trenches of information security. This back-and-forth sharing and learning with others drives his passion for information security.
It can be exhausting to have to deal with "yet another attack" day in and day out, but being part of the great team at the Internet Storm Center allows Johannes to affect how networks are defended. It is rewarding for him to hear from former students, readers of the Internet Storm Center, or listeners to the podcast how they applied what they learned and how it helped them. Teaching technology "from the ground up" can be challenging at times, yet crafting even a dry topic like packet analysis into something exciting and seeing students light up as they capture new concepts makes even hex conversion and counting offsets more exciting than a good movie for Johannes.
Johannes has found that students starting out in the field will often question why they need to know some of the background and details about protocols that are taught. His ability to link these topics to practical examples where this detail made the difference wins them over. His approach to teaching is to convey an understanding for the underlying principles to get students ready for what's next since information security is developing too fast to focus on specific techniques and tools.
Johannes is a partner of the Cyberwire Podcast, a member of the Board of Advisors for Threatstop, Inc, earned a PhD in physics from SUNY Albany, and holds multiple security-related certifications, including the GIAC GMON, GNFA, GWEB, GCIA and GSIP. Over the years, Johannes has been honored with a variety of awards, as well:
Dr. Johannes Ullrich is extremely experienced with information security and has been able to answer every question asked. The course material is very good, and I feel like I'm learning a lot, and the labs are well-designed and are helping to reinforce what I'm learning from the slides and presentation. I'm happy with my choice to attend SANS Technical Institute for my master's degree, so thank you for providing good content and excellent instructors!
Dr. Ullrich is a fantastic instructor. Even during breaks he was readily available for questions. He is definitely a master at this, providing those critical details which students need to make some of their own discoveries but also allowing enough space so they aren't crowded.
Dr. Ullrich has fantastic knowledge in this space, and I liked how he demoed a new vulnerability that fit perfectly into the course.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
AI accelerates development, attacks and to some extent, just maybe, defense. Our new ISC "Skynet 1.0" sensor takes advantage of LLMs to better disguise itself, find answers to attacks faster and inform defense after about ongoing attacks.

Ever wondered how the SANS Internet Storm Center will help you protect your network?

This talk will use little PowerPoint but instead offer an engaging walk-through of recent events, how they manifested themselves in the ISC's data, how our different data feeds work, and more. A talk not just for packet connoisseurs but for everybody interested in a good story.

During this presentation, we interview several defenders to learn what turned out to be just a distraction, or what tools turned out to be a game changer for operations once properly integrated.
