Kenneth G. Hartman
Certified InstructorFounder at Lucid Truth Technologies
Specialities
Cloud Security

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCloud Security

Kenneth G. Hartman is a SANS Certified Instructor and Founder at Lucid Truth Technologies, a Michigan-based digital private investigation agency and forensic consulting firm. He teaches SEC502: Cloud Security Tactical Defense and taught SEC510: Cloud Security Engineering and Controls, bringing cloud security, architecture, engineering, compliance, product management, and digital forensics experience into the classroom. His work helps students connect cloud controls, tactical defense, and risk management to the evidence, systems, and business decisions they face at work.
Ken’s career sits at the intersection of technology and investigation. He was shaped early by an uncle in engineering and a father who was a detective, then later handled his first criminal forensic case in the 2008 murder trial of Charles Curtis Merriman. Before founding Lucid Truth Technologies, he helped launch and lead Visonex, worked in industrial controls at Kraft Foods, and held cloud and security roles at Shopbop.com, OneNeck IT Solutions, Google, SAP Ariba, and Illumina. He draws on that experience while teaching the labs, helping students connect identity, logging, network controls, compliance, incident response, cloud-focused penetration testing, Cloud Custodian, and automation to the realities of defending cloud environments.
Ken holds a Master of Science in Information Security Engineering from the SANS Technology Institute, a Bachelor of Science in Electrical Engineering from Michigan Technological University, the Certified Information Systems Security Professional credential, the GIAC Security Expert credential, and multiple GIAC certifications. Kenneth G. Hartman is also a faculty member of the SANS Technology Institute (SANS.edu). SANS.edu is an NSA Center of Academic Excellence in Cyber Defense and multi-year winner of the National Cyber League competition. Beyond teaching, he maintains forensicate.cloud, an open-source resource for cloud forensics, and has published research on BitTorrent investigations, Amazon EC2 forensics, DevSecOps, and multicloud security.
Ken teaches from a simple mission: make the truth clear. He wants students to understand what to care about, where to focus, and how to use automation to keep pace with cloud scale and constant change. Students should leave able to select practical controls, investigate cloud activity, explain risk clearly, and build safer habits across their organizations without becoming the “cyber policeman.” Students describe Ken as clear, knowledgeable, articulate, and grounded in real-world examples. Away from work, Ken enjoys barbeques, boating, and riding his Harley with friends.
It's clear Ken knows his stuff.
Dude you rock! Clear and spot on.
Kenneth is knowledgeable and articulate, using real life anecdotes to relate material to real world examples.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
Security tools are no longer just defenses, they’re targets. This sessions explores how attackers are weaponizing scanners, exploiting CI/CD pipelines, and turning trusted tooling into attack vectors.

Security teams often find themselves reacting to cloud misconfigurations and policy violations after they occur—playing an endless game of security Whack-a-Mole.

This webcast aims to provide insights into survey results, including the tools, techniques, and strategies needed to secure multicloud environments effectively—offering valuable guidance for organizations navigating the complexities of cloud security at scale.

Graphical interfaces are great for quick tasks, but real cloud power users know that mastery of command-line interfaces (CLIs) unlock unparalleled efficiency, automation, and precision.

This webcast offers invaluable knowledge to help you navigate the complexities of securing multiple cloud environments, stay ahead of evolving threats, and implement robust security practices across your organization.

This study takes a fresh look at multicloud adoption trends, in the face of a looming recession, tech layoffs, and the excitement about the advancements of artificial technologies.

When a cloud service provider (CSP) says they are using encryption, that’s when you know you need to dig deeper into the details rather than succumb to the Jedi mind tricks of encryption.

Abstract: This workshop will teach you everything you need to know to provision your own Cloud-Based Ubuntu Workstation in AWS for Remote Browsing. Sometimes there are valid security and privacy reasons to use a temporary workstation for potentially malicious websites or to avoid tracking. Prerequisites: Attendees will need an AWS Account and should be comfortable launching an EC2 instance and connecting to it. Here is a tutorial on launching an EC2 virtual machine instance: https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EC2_GetStarted.html During the session we will briefly cover some basic git commands as well as Terraform basics, including installation. System Requirements:Link to Sign Up for an AWS Account: https://aws.amazon.com/freeTerraform is available for download here: https://www.terraform.io/downloads.htmlUp to date Web BrowserFor a consistent experience, we will be using the new AWS CloudShell.Mac users will need to add RDP capability per https://docs.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/remote-desktop-mac *Due to the nature of these workshops, many have a capacity limit. To help us offer this opportunity to as many people as possible, we are asking that you please only register if you plan to attend live.

Review relevant educational resources made with contribution from this instructor.