James Shewmaker
Principal InstructorFounder and Principal Consultant at Bluenotch Corporation
Specialities
Offensive Operations

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsOffensive Operations

James Shewmaker is a SANS Principal Instructor, founder and principal consultant at Bluenotch Corporation, and a longtime contributor to some of the most advanced offensive security training in the industry. He teaches and contributes to many courses, including SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking, helping students develop the technical depth needed for modern penetration testing, exploit development, and red team operations. With more than two decades of experience designing secure systems and investigating complex environments, James brings a practitioner’s perspective to the classroom, combining offensive tradecraft with real-world operational insight.
James began his career in 1996 working as a System Administrator and later IT Manager and Director for a major national radio network, where he developed and maintained infrastructure supporting broadcast, internet, and satellite technologies. His work evolved into penetration testing, investigations, and security research through Bluenotch Corporation, the consulting firm he founded in Long Beach, California. Over the years, he has contributed to large-scale cybersecurity initiatives, including the development and operation of the NetWars US Cyber Challenge beginning in 2009. His experience designing realistic attack-and-defense environments directly influences the labs and exercises that students encounter in the course, where they learn to think like adversaries while improving defensive decision-making under pressure.
James holds a Bachelor of Science in Computer Science from the University of Idaho and was among the first GIAC Platinum certified Malware (GSM) experts. He has also contributed to SEC401: Security Essentials and FOR610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques. Beyond courseware development, he is known for his work building offensive training environments, cyber ranges, and challenge platforms, including Bunker011. James is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition.
In the classroom, James is recognized for blending deep technical expertise with practical, hands-on instruction that emphasizes experimentation, problem solving, and operational realism. Students consistently praise his ability to move beyond slides and connect concepts to real-world offensive operations through immersive labs and challenge-based learning. Outside of teaching, he regularly contributes to the cybersecurity community through conference presentations, cyber competitions, and mentoring efforts focused on developing the next generation of offensive security professionals. When he is not immersed in cybersecurity research and gadgets, James enjoys snow skiing, water sports, and aviation with his wife and son.
Jim Shewmaker was terrific. He's a skilled instructor and clearly knowledgeable in every domain of information presented. He was also experienced enough to inject his own opinions on tool usage and recommend alternative approaches and tools.
James Shewmaker is engaging to listen to and cares about the topics. He takes the conversation beyond the text, and all of the personal experiences and anecdotes he includes are what make the information stick.
Jim is awesome and went in depth on the details that mattered to me.
Here are upcoming opportunities to train with this expert instructor.
Initial access is only the beginning. This session shows how attackers escape endpoint restrictions and pivot from constrained environments, with a new lab focused on breaking out of a Dockerized network appliance.

With the proliferation of multi-factor authentication, penetration testers need to apply existing tooling to manipulate even internal applications. Building attack infrastructure internally during a penetration test is resource exhausting, but modern tools like evilginx can do most of the heavy lifting for us.

With the proliferation of multi-factor authentication, penetration testers need to apply existing tooling to manipulate even internal applications.

Red Teamなどで働く攻撃技術の専門家の方であっても、既知の脆弱性を利用して侵入を行った経験はあるものの、自身で脆弱性の発見に取り組んだことのある方はそれほど多くありません。Jim ShewmakerとStephen Simsはファジングのコンセプトと具体的な手法について解説し、最新のファジング技術のデモを行います。何をファジングするべきか、どのような種類があるのか、どのようにそのバグを悪用するのかなどの質問を1時間のセッションでカバーしていきます。

A lot of offensive security professionals have experience weaponizing simple vulnerabilities, but may not have worked much with bug discovery. Join Jim Shewmaker and Stephen Sims as they talk through fuzzing concepts and methodology, and then jump into a demonstration on setting up a modern fuzzing harness. What should you fuzz for? What types of fuzzing is there? How do you know if a bug is weaponizable? We’ll aim to answer these questions and more in this one hour session.
