Jim Clausing
Principal InstructorTechnical Consultant, Network Security Architect at AT&T
Specialities
Digital Forensics and Incident Response

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsDigital Forensics and Incident Response

Jim Clausing first caught an attacker in 1981 after discovering a Trojan login program planted on his college's only computer. That experience sparked a career spanning more than 45 years dedicated to understanding how attackers operate and helping organizations defend against them.
Jim takes the time to explain complex concepts and make sure that everyone is on the same page.
Jim was a great instructor; really good delivery of the content, well paced, and lots of opportunity to ask questions.
The speed at which Jim moves is perfect. I really enjoy his teaching style.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
Protocol-SIFT has been getting a lot of attention lately, but the first release was 100% focused on Windows investigations. In this talk, we'll look at what it takes to extend this to cover Linux investigations.

この講演では、攻撃者が攻撃対象のLinuxシステム上で永続性を確立するための様々な方法について説明します。Windowsシステムにおいて永続性を確立する方法として、Run/RunOnceレジストリキーやタスクスケジューラなどを悪用する手法が広く知られていますが、Linux上で攻撃者がどこに隠れているかをご存知ですか?

This talk will discuss the various ways that attackers try to maintain persistence on victim systems.

Review relevant educational resources made with contribution from this instructor.