Ryan Chapman
Certified InstructorTeam Lead, Managed Threat Hunting at Palo Alto Networks
Specialities
Digital Forensics and Incident Response

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsDigital Forensics and Incident Response

Ryan is a Threat Hunter who has worked in the Digital Forensics & Incident Response (DFIR) realm for 15 years. He is the author of SANS FOR528: Ransomware and Cyber Extortion and also teaches SANS FOR610: Reverse Engineering Malware.
Prior to working as a Threat Hunter, Ryan worked as a Principal Incident Response Consultant for 5 years. During his overall career, he has worked in Security Operations Center and Cyber Incident Response Team roles that handled incidents from inception through remediation. With Ryan, it's all about the blue team. Ingesting intelligence, hunting through log aggregation utilities, analyzing malware, and performing host and network forensics are all skills in his repertoire.
Prior to moving to security, Ryan worked as a technical trainer for six years. His stint as a full-time trainer prepared him for the rigors of life-long learning. He loves training and often assists with training development.
Ryan’s current passion is researching ransomware in order to help as many people as possible learn to deter, detect, and respond to the threat. For development of FOR528, Ryan drew on his extensive expertise working ransomware incidents. The course features numerous labs, a full day Capture the Flag exercise, and provides tools that can be used to share and collaborate on hunting queries between entities and disparate systems.
"When it comes to ransomware, the primary blocker for students is realizing that early detection often requires hunting," Ryan explains. "Some students who take the FOR528 course may not have experience with hunting, so the concept is simply new to them. We are not just relying on detection systems. Rather, we are relying on our ability to seek out and hunt the adversary within our networks."
Outside of ransomware, one of Ryan’s interests in the security realm is the exciting world of reverse engineering. “Malware has become pervasive,” he says, “and I relish in the ability to dissect, understand, and protect against evolving threats." Ryan loves finding all the new tricks that malware authors use to circumvent security appliances.
Ryan's association with SANS began when he took a course in 2013, a path that eventually led to him becoming a course instructor and author.
"These days it’s difficult to have a conversation concerning DFIR without referencing SANS in some way, shape, or form,” he says. “The power of SANS isn’t just behind the courses, but rather behind the family as a whole. The course authors, instructors, and folks in all other departments have come together to create an ever-evolving beast of a training institute."
As a teacher, Ryan wants his students to walk away with a full understanding of the content covered in class. "I don’t want to teach people how to push buttons to get bananas. I aim for every student to understand the ‘why’ behind the ‘how.’ For example, I want to ensure that students leave the class knowing why we look for VirtualAlloc and VirtualProtect calls in packed malware samples. I want my students to know WHY these are important function calls," he says.
Ryan also wants students to recognize their potential for mastering the topics covered in class. "Be it ransomware or general malware analysis, I strive to instill confidence in my students. Sure, we learn the foundations and advanced topics. But these things are doable outside of the classroom, even at their daily jobs. My classes aren’t magical adventures that end when the class concludes. Rather, these are skills that can be translated to the daily lives of every student."
When teaching, Ryan often stays after class to provide additional examples of the topics covered each day. He provides additional resources such as vetted and trusted YouTube videos and articles that cover the topics in slightly different ways. "I tell any student struggling with a given concept that it’s all about the practice and recognition of the activity involved. Thus, I provide plenty of examples to ensure that if they put in the time, the concept will solidify for them."
Ryan also previously led a hacker and security conference in Arizona called CactusCon. Outside of work, he enjoys watching anime with his daughter, mountain biking, and collecting retro video games.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
The Insider Threat / Malware / Ransomware Track at SANS Spring Cyber Solutions Fest 2026 brings together leading practitioners, researchers, and solution providers to explore how modern threats are evolving inside and outside the organization.

A large majority of ransomware incidents involve both obfuscated scripts and Cobalt Strike. PowerShell reigns supreme as the most common type of obfuscated script found in ransomware cases. Do you know what to do should you find an obfuscated PowerShell script during response? What if you run into an obfuscated, PowerShell-based Cobalt Strike downloader? Do you know how to decode the downloader? Do you know how to review the shellcode found multiple levels within the code structure to determine where the Cobalt Strike beacon is being hosted?

今回のCommunity Nightでは、SANSの「FOR528: Ransomware for Incident Responders」の開発者であるRyan Chapmanが、ランサムウェアの運用に活用されているツールについて紹介します。ランサムウェアの運用については様々なバリエーションが存在しますが、活用されているツールには重複している点も少なくありません。

Join us in this Community Night talk as Ryan Chapman, author of SANS FOR528: Ransomware for Incident Responders, provides an overview of tools leveraged often by ransomware operators. Though a multitude of ransomware operations and affiliate groups exist, we see a great deal of overlap between the tools leveraged by these groups (and that's an understatement!).

Review relevant educational resources made with contribution from this instructor.