Stephen Sims
FellowResearch Fellow
Specialities
Offensive Operations

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsOffensive Operations

Stephen Sims began working on computers at a young age with a fellow enthusiast: his father. Amazed by how easy it was to change an application's intended behavior, Stephen was quickly hooked. Today, he's an industry expert with over 20 years of experience in information technology and security. He's authored SANS most advanced course, SEC760: Advanced Exploit Development for Penetration Testers, was the 9th person in the world to earn the GIAC Security Expert certification (GSE), and co-author of the Gray Hat Hacking book series, as well as a keynote speaker who's appeared at RSA USA and APJ, DEF CON, OWASP AppSec, BSides events and more. On top of all this, Stephen is Curriculum Lead for SANS Offensive Operations.
Stephen has worked for Wells Fargo, Charles Schwab, CSC, and is now a full-time consultant helping clients with product security testing, reverse engineering, penetration testing, exploit developing, threat modeling, secure coding, and other areas, giving him ample opportunity to use his skills in a variety of ways. "You will never know everything in this field and there are so many directions one can take," he says. "If you ever get bored with an area in security you can change over to a hundred other exciting roles."
Shortly after launching his career, Stephen set the goal of becoming a SANS instructor. After attending a SANS training in 2003, he was blown away by the knowledge and presentation skills of the instructor. "SANS also gives so much back to the community through immersion programs and scholarships to veterans and underrepresented groups," says Stephen. "I set becoming a SANS instructor as a goal of mine and went after it."
Stephen became a SANS instructor in 2006, and today is curriculum lead for SANS Offensive Operations, as well as faculty fellow for the SANS Institute. He authored SANS' most advanced technical course, SEC760: Advanced Exploit Development for Penetration Testers, which concentrates on complex heap overflows, patch diffing, and client-side exploits. He's also the lead author of SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking and coauthor of SEC599: Defeating Advanced Adversaries - Purple Team Tactics & Kill Chain Defenses.
As an instructor, Stephen enjoys watching his students work through a problem to completion, either on their own or in collaboration with another student. "You learn a lot more when you work hard to solve a complex problem without asking for assistance," he says, noting that you should never be afraid to ask for help when you need it. "Sometimes we all need a little nudge in the right direction, but it's always best to exhaust all possibilities first."
Stephen says his most successful students are ones who come to class well-rested and with an open mind. "Be prepared to have to work through solutions and spend additional time after class is over to go back through in order to absorb all of the material," he says.
Stephen is the 9th person in the world to receive the prestigious GIAC Security Expert certification (GSE). He is a Certified Information Systems Auditor (CISA) and certified Immunity Network Offense Professional (Immunity NOP), along with many other certifications. Stephen is also a faculty member of the SANS Technology Institute, an NSA Center of Academic Excellence in Cyber Defense and multiple winner of the National Cyber League competition.
An author of the Gray Hat Hacking book series, Stephen holds a master's degree in Information Assurance from Norwich University. A frequent presenter, Stephen has spoken at RSA USA in previous years and was keynote speaker for the 2019 event. He's also presented at RSA APJ, DEF CON, OWASP AppSec, BSidesCharm, AISA, and more. When he's not working, you'll find him hitting the slopes on his snowboard and writing music.
Looking at everything I have learned from Stephen, I definitely feel I have gained an edge when it comes to the augmentation of my pentest skills. He made the impossible understandable and I am grateful for that.
Cryptography is such a complex topic, and Stephen does an excellent job of explaining these complex topics and making it easier to understand.
Steve Sims has real-world experience and fantastic skills in explaining the problem in different ways.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
The session will demonstrate how AI can be applied as both a SAST and DAST capability for discovering and exploiting zero-day vulnerabilities in web applications, as well as its growing role in binary exploitation.

AI can accelerate advanced pentesting, but only if you can validate the results. Join Stephen Sims for a look at SEC660 updates on AI-assisted reversing, debugging, vuln research, and exploit development without losing technical edge.

In this talk we will take a look at the most recent attack techniques, targets, and trends.

Modern offensive security teams and attackers can no longer rely on traditional tactics, techniques, and procedures. Whether it be developing custom implants to evade EDR/AV, reverse engineering patches to quickly weaponize privately disclosed vulnerabilities, or leveraging AI to accelerate adversarial campaigns, successfully compromising a target environment requires cutting-edge skills.

現代の攻撃者を模倣するために必要な幅広いスキルについてご紹介します。セキュリティは、自動化、人工知能、エクスプロイト緩和策、検知能力、そしてその他多くのコントロールやプロセスにより、2000年代から大きな進化を遂げてきました。現代の攻撃的セキュリティチームや攻撃者は、もはや従来の戦術、技術、手順に頼ることはできません。

Annual penetration testing is no longer enough to keep pace with modern threats.

Join me in this talk where we will utilize an AI Chatbot to aid us in vulnerability discover and exploitation.

We are excited to invite you to an exclusive webcast where we'll unveil the latest updates to the SEC699 SANS Purple Teaming course. This session will provide an in-depth look at the enhancements we've made to ensure that our course remains at the forefront of cybersecurity training.

Join Stephen Sims and Erik Van Buggenhout as they present, "The Always- On Purple Team: An Automated CI/CD for Detection Engineering", which they previously introduced at RSA Conference 2024. During this webcast, they will share tips on building the always-on purple team!

Join us for an interactive SANS Day where cybersecurity experts and enthusiasts come together to explore the latest trends, challenges, and innovations in the field. This event promises a full day of insightful presentations, hands-on experiences, and valuable networking opportunities, and is designed for professionals at all levels. You will have the opportunity to engage with SANS Instructors and hear their insights on cybersecurity threats, customer landscape, AI, and how you can continue to development and advance in your career path. This is a must attend event for anyone passionate about staying ahead in the rapidly evolving world of cybersecurity. Don't miss out on the chance to learn, engage, connect, and grow in your cybersecurity journey!

Join us for an interactive SANS Day where cybersecurity experts and enthusiasts come together to explore the latest trends, challenges, and innovations in the field. This event promises a full day of insightful presentations, hands-on experiences, and valuable networking opportunities, and is designed for professionals at all levels. You will have the opportunity to engage with SANS Instructors and hear their insights on cybersecurity threats, customer landscape, AI, and how you can continue to development and advance in your career path. This is a must attend event for anyone passionate about staying ahead in the rapidly evolving world of cybersecurity. Don't miss out on the chance to learn, engage, connect, and grow in your cybersecurity journey!

Red Teamなどで働く攻撃技術の専門家の方であっても、既知の脆弱性を利用して侵入を行った経験はあるものの、自身で脆弱性の発見に取り組んだことのある方はそれほど多くありません。Jim ShewmakerとStephen Simsはファジングのコンセプトと具体的な手法について解説し、最新のファジング技術のデモを行います。何をファジングするべきか、どのような種類があるのか、どのようにそのバグを悪用するのかなどの質問を1時間のセッションでカバーしていきます。

A lot of offensive security professionals have experience weaponizing simple vulnerabilities, but may not have worked much with bug discovery. Join Jim Shewmaker and Stephen Sims as they talk through fuzzing concepts and methodology, and then jump into a demonstration on setting up a modern fuzzing harness. What should you fuzz for? What types of fuzzing is there? How do you know if a bug is weaponizable? We’ll aim to answer these questions and more in this one hour session.

Review relevant educational resources made with contribution from this instructor.