Joshua Wright
FellowDirector and Senior Security Analyst at CounterHack
Specialities
Offensive Operations, Digital Forensics and Incident Response

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsOffensive Operations, Digital Forensics and Incident Response

Joshua Wright is a SANS Faculty Fellow, Senior Technical Director at Counter Hack Innovations, and the author of SEC504: Hacker Tools, Techniques, and Incident Handling, one of the most widely taken courses in the SANS curriculum. Over more than two decades, he has trained thousands of professionals worldwide while contributing groundbreaking research, tools, and publications to the security community.
Joshua’s professional journey began when, after being caught hacking into his alma mater, Johnson & Wales University, he was subsequently hired to strengthen its systems. From there, he built his early career conducting penetration tests and vulnerability assessments that exposed critical weaknesses in enterprises and national infrastructure. As a Senior Security Analyst at InGuardians, he specialized in offensive operations and protocol exploitation. Today, at Counter Hack, he leads a team of cybersecurity consultants, specializing in penetration testing and red-team simulations, experiences that have shaped his teaching and research.
Joshua is the co-author of Hacking Exposed Wireless, Third Edition and the developer of widely used open-source tools. These include KillerBee, a toolkit for testing ZigBee wireless networks; KillerZee, designed for Z-Wave research; and several other tools. His research and technical contributions laid the foundation for SEC504, a course that set the standard for developing incident response skills and supporting students pursuing the GIAC Certified Incident Handler (GCIH) certification.
Joshua has been part of the SANS instructor community since 2003, shaping the curriculum for more than two decades and mentoring both students and instructors. He also serves as the Dean of Students at the SANS Technology Institute, an NSA Centers of Academic Excellence in Cyber Defense, a multi-year winner of the National Cyber League competition, and was named 2023 Instructor of the Year by his peers.
In the classroom, Joshua is recognized for his approachable teaching style and focus on practical, hands-on learning. Students describe his ability to break down complex concepts and build resilience through exercises that replicate real adversary behavior. Beyond his professional roles, Joshua supports the broader community by maintaining open-source projects, mentoring emerging professionals, and volunteering his time as a nonprofit photographer. His career embodies a steadfast belief that strong defenders are developed not only through technical skills but also through collaboration, creativity, and human connection.
The amount of detail that Joshua puts into the course and presentation of the material is a gold standard. He's able to break down details and make it so the material is understood by a newbie in the field. Further, Josh's excitement for the material is contagious!
To be taught by someone who has the knowledge, the background, and the ability to articulate this kind of information for learning was invaluable. I wish I could have back to back courses with Joshua.
Joshua's teaching style is phenomenal. He's very engaging, and does a great job of promoting discussions without getting too far off on a tangent.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
This month, an OpenAI model, running inside a sealed evaluation with its safety limits turned down, found a previously unknown flaw, broke out on its own, and took control of Hugging Face's live systems over a weekend. No human directed it. For years, industry leaders across the field warned this day would come. The disclosures suggest it has arrived.

In this talk, you'll learn how to apply the same workflow attackers are using to find zero-day vulnerabilities in open-source projects.

According to Anthropic, their new Claude Mythos model discovered thousands of zero-day vulnerabilities across every major operating system and web browser—and the model is so powerful they will not release it publicly. The conversation so far has been heavy on alarm and light on practical guidance.

The Verizon DBIR says stolen credentials cause more breaches than phishing and exploits combined. Now, AI is making these attacks even more effective. Join SANS Fellow Joshua Wright to learn what you can do to protect your environment.

SANS instructors quickly analyzed the axios supply chain attack, uncovering RAT functionality and providing immediate guidance to help organizations identify exposure and respond.

Annual penetration testing is no longer enough to keep pace with modern threats.

Attackers evolve to exploit new opportunities, including attacks against cloud systems. As defenders, we also need to evolve, developing new skills and understanding in how attackers exploit cloud platforms, and how we should respond to these incidents.

Review relevant educational resources made with contribution from this instructor.