SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Learn to identify and respond to enterprise-class incidents. Deepen your threat hunting abilities using enterprise-class tools and digging into analysis methodologies to understand attacker movement.
Conduct detailed, in-depth analysis on raw data from Mac and iOS cases. Gain confidence in your forensic analysis and incident response skills with hands-on labs.
Learn the advanced incident response and threat hunting skills you need to identify, counter, and recover from a wide range of threats within enterprise networks.
Cloud forensics is evolving. FOR509 equips examiners to embrace new evidence sources in enterprise cloud environments instead of forcing outdated on-premise methods.
Learn the skills you need to identify, analyze, and respond to attacks on Linux platforms and how to use threat hunting techniques to find stealthy attackers who can bypass existing controls.
FOR563 teaches DFIR professionals to harness private, local AI using Large Language Models (LLMs) for secure, hands-on investigation and analysis at scale.
Deepen your advanced network forensics experience, including threat hunting, analysis, and incident response. Explore the tools, technology, and processes needed to integrate network evidence sources.
SANS DFIR Europe Summit and Training 2026 delivers cutting-edge, hands-on cybersecurity training led by top digital forensics and incident response experts. Join us live in beautiful Prague or attend virtually from anywhere.
This paper examines where incident response automation can be used to empower your teams and bring...
A review of Rapid7 UserInsight by SANS senior analyst Jerry Shenk. It discusses a tool that...