Group Purchasing
Group Purchasing

Jim Clausing

Principal InstructorTechnical Consultant, Network Security Architect at AT&T

Specialities

Digital Forensics and Incident Response

Connect with Jim

Jim Clausing

About Jim Clausing

Jim Clausing first caught an attacker in 1981 after discovering a Trojan login program planted on his college's only computer. That experience sparked a career spanning more than 45 years dedicated to understanding how attackers operate and helping organizations defend against them.

Today, Jim is a SANS Principal Instructor, Technical Consultant and Network Security Architect at AT&T, and lead instructor for FOR577: Linux Incident Response and Threat Hunting. He also teaches FOR610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques, bringing decades of experience in malware analysis, Linux security, packet analysis, digital forensics, incident response, intrusion detection, system hardening, and botnet tracking into the classroom.

For more than 25 years at AT&T, Jim has investigated malware, analyzed network intrusions, responded to incidents, and helped strengthen enterprise security programs. His operational experience directly shapes the hands-on investigations and threat hunting techniques taught in FOR577, giving students practical skills they can immediately apply in real-world environments. Throughout his career, he has also worked in systems and database administration and conducted research in parallel processing and distributed systems, giving him a broad perspective on the evolution of enterprise security.

Jim believes strongly in giving back to the cybersecurity community—a philosophy inspired by his first SANS instructor, Stephen Northcutt. He has served as a volunteer Incident Handler with the SANS Internet Storm Center since 2002, a member of the GIAC Board of Directors since 2006, and is a faculty member of the SANS Technology Institute, an NSA Center of Academic Excellence in Cyber Defense and multi-year winner of the National Cyber League competition. Beyond teaching, Jim develops and maintains practical open-source DFIR tools, including docker_mount.py, mac_robber.py, sigs.py, and tln_parse.py, that are widely used by investigators and incident responders.

Jim co-authored the SANS Press book Securing Solaris 8 & 9 Using the Center for Internet Security Benchmark and holds the GIAC Security Expert (GSE #26) certification along with numerous advanced GIAC certifications and the CISSP. Known for his approachable, hands-on teaching style, Jim believes the best way to learn is by doing. Whether teaching Linux incident response, reverse engineering malware, or mentoring the next generation of defenders, he enjoys sharing practical experience while continuing to learn from every class he teaches. Outside of cybersecurity, Jim enjoys cycling, flying as an instrument-rated private pilot, and spending time with his family and their pets.

Qualifications Summary
  • SANS Principal Instructor; lead instructor for FOR577: Linux Incident Response and Threat Hunting and instructor for FOR610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques
  • More than 45 years of experience in malware analysis, Linux security, packet analysis, digital forensics, incident response, intrusion detection, and network security
  • Technical Consultant and Network Security Architect at AT&T, helping organizations investigate threats and strengthen enterprise security for more than 25 years
  • Incident Handler with the SANS Internet Storm Center since 2002 and GIAC Board of Directors member since 2006; faculty member at the SANS Technology Institute
  • Developer of open-source DFIR tools, including docker_mount.py, mac_robber.py, sigs.py, tln_parse.py, ficheck.py, and le-hex-toip.py supporting the global incident response community
  • Co-author of Securing Solaris 8 & 9 Using the Center for Internet Security Benchmark; GIAC Security Expert (GSE #26), GIAC Gold certifications (GCFA, GCIA, GREM, GLIR), multiple advanced GIAC certifications, and CISSP

Press & Media

More From Jim

  • sigs.pyGenerate md5, sha1, sha256, sha512, sha3-384 signatures from files (potentially recursively)
  • mac_robber.pymac_robber rewritten in python
  • docker_mount.pyScript to read-only mount docker layered filesystems (currently supports underlying aufs and overlay2)
  • tln_parse.pyPython script to replace parse.exe in Mari's KAPE mini-timeline workflow to give me good yyyy-dd-mm UTC timestamps