Timothy McKenzie
Principal InstructorOwner at 3L337 Consulting, LLC
Specialities
Offensive Operations, Cloud Security

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsOffensive Operations, Cloud Security

Timothy McKenzie is a SANS Principal Instructor, founder and principal consultant of 3L337 Consulting, and a co-author of SEC542: Web Application Penetration Testing and Ethical Hacking. He also teaches SEC588: Cloud Penetration Testing. With more than 30 years of experience spanning enterprise infrastructure, information security, penetration testing, and Red Team operations, Timothy brings a practitioner's perspective to every course. His teaching reflects the realities of offensive security consulting, where web applications, cloud environments, and enterprise networks must be assessed methodically, findings must withstand scrutiny, and recommendations must translate into meaningful security improvements.
Timothy McKenzie provides in-depth detail in SEC542, as well as his own experiences and anecdotes, and the labs present great examples of the topics covered and what to do when tools fail.
[Tim] continues to keep me engaged and teaches at a great pace with great explanations. I also benefit from hearing his real life "war stories" about where he has found examples of vulnerabilities and the impact they could have for a company/victim.
Very clear, funny, professional... 10/10
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
This session walks through a modern web app pentest workflow using OWASP tools, Burp MCP, DefectDojo, and AI-assisted reporting to accelerate recon, scanning, and triage.

The demo will move through reconnaissance, vulnerability scanning, Burp Suite integration, data import into DefectDojo, and AI-assisted report writing—providing a complete, modern pentesting workflow.

Large Language Models (LLMs) such as ChatGPT, Claude, and Grok have become very powerful. This talk is full of live demonstrations of the kinds of things information security professionals can do with the LLMs. Examples include analyzing and manipulating shell code, writing exfiltration code, analyzing logs, and more.

Defenders must be constantly vigilant in their efforts to protect their organization's environment. Through practice, the defenders can be sharpened by red and purple team exercises. This presentation will explore some cassstudies where exercise improved the organization's security posture.

Review relevant educational resources made with contribution from this instructor.