James Shewmaker
Principal InstructorFounder and Principal Consultant at Bluenotch Corporation
Specialities
Offensive Operations

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsOffensive Operations

James Shewmaker is a SANS Principal Instructor, founder and principal consultant at Bluenotch Corporation, and a longtime contributor to some of the most advanced offensive security training in the industry. He teaches and contributes to many courses, including SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking, helping students develop the technical depth needed for modern penetration testing, exploit development, and red team operations. With more than two decades of experience designing secure systems and investigating complex environments, James brings a practitioner’s perspective to the classroom, combining offensive tradecraft with real-world operational insight.
Jim Shewmaker was terrific. He's a skilled instructor and clearly knowledgeable in every domain of information presented. He was also experienced enough to inject his own opinions on tool usage and recommend alternative approaches and tools.
James Shewmaker is engaging to listen to and cares about the topics. He takes the conversation beyond the text, and all of the personal experiences and anecdotes he includes are what make the information stick.
Jim is awesome and went in depth on the details that mattered to me.
Here are upcoming opportunities to train with this expert instructor.
With the proliferation of multi-factor authentication, penetration testers need to apply existing tooling to manipulate even internal applications. Building attack infrastructure internally during a penetration test is resource exhausting, but modern tools like evilginx can do most of the heavy lifting for us.

With the proliferation of multi-factor authentication, penetration testers need to apply existing tooling to manipulate even internal applications.

Red Teamなどで働く攻撃技術の専門家の方であっても、既知の脆弱性を利用して侵入を行った経験はあるものの、自身で脆弱性の発見に取り組んだことのある方はそれほど多くありません。Jim ShewmakerとStephen Simsはファジングのコンセプトと具体的な手法について解説し、最新のファジング技術のデモを行います。何をファジングするべきか、どのような種類があるのか、どのようにそのバグを悪用するのかなどの質問を1時間のセッションでカバーしていきます。

A lot of offensive security professionals have experience weaponizing simple vulnerabilities, but may not have worked much with bug discovery. Join Jim Shewmaker and Stephen Sims as they talk through fuzzing concepts and methodology, and then jump into a demonstration on setting up a modern fuzzing harness. What should you fuzz for? What types of fuzzing is there? How do you know if a bug is weaponizable? We’ll aim to answer these questions and more in this one hour session.
