Mark Baggett
FellowChief Technology Officer at The Internet Storm Center
Specialities
Cyber Defense
Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCyber Defense
Every defender faces moments when the data feels endless and the stakes are high. Mark Baggett teaches practitioners to turn that complexity into control. A SANS Faculty Fellow and author of SANS SEC573: Automating Information Security with Python, SANS SEC673: Advanced Information Security Automation with Python, and SANS SEC406: Linux Security for InfoSec Professionals, Mark shows security professionals how to harness Python to detect, respond to, and outthink adversaries. As Chief Technology Officer of the SANS Internet Storm Center, he leads global collaboration on threat analysis and defensive innovation, turning field experience into lessons that make defenders stronger. His mission: make automation accessible, impactful, and achievable for every defender—regardless of coding background.
Mark's teaching style is very relevant and sets an atmosphere where you are excited to learn.
Mark is really knowledgeable and knew how to engage us right away by pulling off a PEMDAS 'magic trick'. Some of the material is dry by nature, but he's made it very engaging and has been flexible with the different paces we're working at.
I'm fairly certain Mark Baggett is a genius, plus he's engaging and illustrative in his examples. I'm not the best coder, but the course challenges build on each other perfectly and illustrate the concepts they're meant to represent.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
In 2026, as information security professionals, you’re facing your own steam-powered saw: Artificial Intelligence. AI is reshaping cybersecurity faster than Paul could clear a forest, and some of you might feel like you’re swinging your axe against an unstoppable machine.
Picture this: you approach a machine where you know an incident has occurred, but all traditional logs are missing or wiped leaving you with no clear starting point.
Join us for SANS Secure Your Fortress: Building Robust and Resilient Defenses for 2025, where cutting-edge techniques meet hands-on practicality. Designed for cybersecurity professionals at all levels, this event equips you with the tools, strategies, and insights needed to overcome today’s toughest challenges and prepare for tomorrow’s emerging threats.
Have you heard that SANS has a new Advanced Python Automation class? Are you interested in trying out some of the content? Join us for this workshop where SANS Fellow and course author Mark Baggett will deliver the first hour and a half of content.
Join us at the forefront of cybersecurity at "SANS Secure Your Fortress: 2024's Top Defense Strategies and Trends!"
Are you ready to elevate your Python skills? Join SANS for an exclusive Advanced Python Automation workshop led by SANS Fellow and course author Mark Baggett. In this interactive session, you'll experience the first hour and a half of the course content, packed with practical, hands-on material. Skip the typical introductions and dive straight into advanced automation techniques. Don't miss this opportunity to enhance your Python automation expertise with real-world applications. Register now and take your Python skills to the next level!
Cracking the Code: The Role of Programming in Information Security by SANS Fellow Instructor Mark Baggett and Why Do We Do What We Do? A Motivational Talk by Certified Instructor Candidate Justin Parker
Step into a world where cutting-edge defense meets practicality in cybersecurity! "SANS Secure Your Fortress" will teach you how to master the latest and most effective defense techniques. Whether you're a seasoned expert or just beginning your cyber journey, this event is for you.
From one of our early GSE’s (GIAC Security Expert) Mark in this presentation will explore an unpatched vulnerability within Windows, one that attackers can likely exploit to bypass your defenses. Through the lens of this attack, we'll address a significant question: "Are programming skills a requisite for excelling in the field of information security?" Recent research indicates that approximately 20% of entry-level positions in information security demand proficiency in programming. Yet, the ongoing debate in online forums highlights the uncertainty surrounding the necessity of coding skills. Join Mark as we navigate through this discussion, who has vast experience on various cybersecurity roles through his certifications and work experience, examining the intricate relationship between coding expertise and achieving success in the realm of information security.
Do you remember that one time that awesome information security tool came out on Windows? I think that happened once. Didn't it? But let's face it, if you want to use the best information security tools around you are probably going to be using Linux.
Have you heard that SANS has a new Advanced Python Automation class? Are you interested in trying out some of the content? Join us for this workshop where Senior SANS Instructor and course author Mark Baggett will deliver the first hour and a half of content.
Advanced Python CTF based on Mark Baggett’s SEC673 Advanced Information Security Automation with Python.
Have you heard that SANS has a new Advanced Python Automation class? Are you interested in trying out some of the content? Join us for this workshop where Senior SANS Instructor and course author Mark Baggett will deliver the first hour and a half of content. But wait, isn't the first hour and a half always introductions and no real hands on material? Maybe in other classes but not in this one. Come check it out!
Have you heard that SANS has a new Advanced Python Automation class? Are you interested in trying out some of the content? Join us for this workshop where Senior SANS Instructor and course author Mark Baggett will deliver the first hour and a half of content. But wait, isn't the first hour and a half always introductions and no real hands on material? Maybe in other classes but not in this one. Come check it out!
Review relevant educational resources made with contribution from this instructor.