Jim Clausing
Principal InstructorTechnical Consultant, Network Security Architect at AT&T
Specialities
Digital Forensics and Incident Response

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsDigital Forensics and Incident Response

Jim Clausing first caught an attacker in 1981 after discovering a Trojan login program planted on his college's only computer. That experience sparked a career spanning more than 45 years dedicated to understanding how attackers operate and helping organizations defend against them.
Today, Jim is a SANS Principal Instructor, Technical Consultant and Network Security Architect at AT&T, and lead instructor for FOR577: Linux Incident Response and Threat Hunting. He also teaches FOR610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques, bringing decades of experience in malware analysis, Linux security, packet analysis, digital forensics, incident response, intrusion detection, system hardening, and botnet tracking into the classroom.
For more than 25 years at AT&T, Jim has investigated malware, analyzed network intrusions, responded to incidents, and helped strengthen enterprise security programs. His operational experience directly shapes the hands-on investigations and threat hunting techniques taught in FOR577, giving students practical skills they can immediately apply in real-world environments. Throughout his career, he has also worked in systems and database administration and conducted research in parallel processing and distributed systems, giving him a broad perspective on the evolution of enterprise security.
Jim believes strongly in giving back to the cybersecurity community—a philosophy inspired by his first SANS instructor, Stephen Northcutt. He has served as a volunteer Incident Handler with the SANS Internet Storm Center since 2002, a member of the GIAC Board of Directors since 2006, and is a faculty member of the SANS Technology Institute, an NSA Center of Academic Excellence in Cyber Defense and multi-year winner of the National Cyber League competition. Beyond teaching, Jim develops and maintains practical open-source DFIR tools, including docker_mount.py, mac_robber.py, sigs.py, and tln_parse.py, that are widely used by investigators and incident responders.
Jim co-authored the SANS Press book Securing Solaris 8 & 9 Using the Center for Internet Security Benchmark and holds the GIAC Security Expert (GSE #26) certification along with numerous advanced GIAC certifications and the CISSP. Known for his approachable, hands-on teaching style, Jim believes the best way to learn is by doing. Whether teaching Linux incident response, reverse engineering malware, or mentoring the next generation of defenders, he enjoys sharing practical experience while continuing to learn from every class he teaches. Outside of cybersecurity, Jim enjoys cycling, flying as an instrument-rated private pilot, and spending time with his family and their pets.
Jim takes the time to explain complex concepts and make sure that everyone is on the same page.
Jim was a great instructor; really good delivery of the content, well paced, and lots of opportunity to ask questions.
The speed at which Jim moves is perfect. I really enjoy his teaching style.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
Protocol-SIFT has been getting a lot of attention lately, but the first release was 100% focused on Windows investigations. In this talk, we'll look at what it takes to extend this to cover Linux investigations.

この講演では、攻撃者が攻撃対象のLinuxシステム上で永続性を確立するための様々な方法について説明します。Windowsシステムにおいて永続性を確立する方法として、Run/RunOnceレジストリキーやタスクスケジューラなどを悪用する手法が広く知られていますが、Linux上で攻撃者がどこに隠れているかをご存知ですか?

This talk will discuss the various ways that attackers try to maintain persistence on victim systems.

Review relevant educational resources made with contribution from this instructor.