SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsEffective Cyber Defense enables organizations to anticipate, withstand, and recover from cyber-attacks through proactive monitoring, threat detection, and incident response. It combines security operations, automation, and resilient architecture to reduce risk and minimize attack impact.

Cyber threats are constant—and defenders must be faster, smarter, and more proactive than their adversaries. At SANS, we train cybersecurity teams to detect, respond to, and outmaneuver attacks using real-world tactics, automation, and resilient infrastructure. Our hands-on cyber defense courses equip professionals with the skills and confidence to minimize risk and build lasting defense strategies in a dynamic threat landscape.
Skillfully and confidently monitor, detect, and respond to cyber threats.
Build resilient systems with security-first design principles that withstand modern attacks.
Streamline detection and response with automation techniques that enhance efficiency and precision.
As usual, SANS courses give incredible insight into the reality of the threats that are present in the cyber world. I have a better understanding of each threat, and the means to mitigate those threats.



















SANS Faculty Fellow Mark Baggett authored SEC573 and SEC673, leads as CTO of the SANS Internet Storm Center, and empowers defenders to automate security through practical, real-world application.
Learn more

Eric Conrad, a SANS Faculty Fellow and course author, has 28 years of information security experience. Eric is the CTO of Backshore Communications and his specialties include Intrusion Detection, Threat Hunting, and Penetration Testing.
Learn more

Rich Greene, SANS Senior Solutions Engineer and SEC301 author, brings 20+ years of cyber operations and teaching experience to the classroom. With 15+ GIAC certifications and a passion for mentorship, he equips defenders with real-world confidence and skill.
Learn more

David Hoelzer has fundamentally advanced cybersecurity by pioneering the GIAC Security Expert (GSE) certification, leading AI-driven threat detection initiatives, and developing MAVIS, an open-source ML tool enhancing code review processes.
Learn more

John is a Senior SANS Instructor and SOC consultant, author of SEC450 and LDR551. With deep SOC leadership experience, GIAC certifications, and hands-on labs, he equips cyber defenders with the skills to hunt, detect, and lead resilient operations.
Learn more

Seth, SANS Faculty Fellow and author of SEC411, LDR414, and SEC511, combines cutting-edge consulting and education to equip defenders worldwide. Founder of Context Security and GSE #28, he brings clarity, humor, and purpose to cybersecurity training.
Learn moreIn this webinar, experts from SANS and Cisco will explore the hybrid mesh firewall approach—what it is, why it’s critical today, and effective deployment at scale.

This session explores the strategic shift toward unified DFIR platforms that merge forensic-grade investigation capabilities with incident response. Attendees will gain insight into how integrating evidence collection, artifact triage, endpoint isolation, and threat remediation into a single workflow reduces tool fatigue, shortens dwell time, and improves regulatory compliance.

As adversaries harness AI to deploy polymorphic malware, agentic automation, and high-speed deception, defenders must respond with intelligent, explainable, and resilient threat intelligence systems.

As adversaries harness AI to deploy polymorphic malware, agentic automation, and high-speed deception, defenders must respond with intelligent, explainable, and resilient threat intelligence systems.

Join Rocky Rosas, VP of Sales Engineering at Securonix, for a practical 30-minute session on how Securonix DPM Flex transforms the economics of security telemetry and helps organizations regain control of their data strategy.

Join this SANS webcast to discover how to build a modern, AI-driven SOC powered by Cortex XSIAM—the industry’s leading AI-powered security operations platform.

Security teams are under increasing pressure to detect, respond, and adapt at the speed of today’s evolving threats. The SANS 2026 SOC, SIEM, SOAR Forum brings together practitioners, architects, and leaders to share real-world experiences, lessons learned, and proven practices for advancing Security Operations.

Overview Identity has become the new battleground. From SaaS to cloud to legacy Active Directory, it is now the central control point—and attackers know it.

Join us for an exclusive virtual event as we unveil the results of a comprehensive nationwide survey of cybersecurity leaders and IT strategists across government.

Over the past few years, the cyber threat landscape has been defined by supply chain compromises, the targeting of cloud and SaaS environments, and the growing use of AI by both defenders and adversaries.

SANS 2026 Demo Day showcases the latest innovations, tools, and techniques shaping the future of cybersecurity across defense, detection, automation, and cloud security

The SANS 2026 Government Forum, presented in partnership with Carahsoft, brings together federal, state, and local government cybersecurity professionals to explore the evolving threat landscape and the solutions shaping secure, mission-ready environments.

Cloud sprawl, misconfigurations, shadow IT, third-party risk, and identity-driven threats—exposure management is now a defining challenge in cybersecurity. As digital environments expand, so does the complexity of defending them.

The Ransomware Solutions Track brings together practitioners, researchers, and technology innovators to showcase actionable strategies that strengthen resilience against the world’s most disruptive cyber threat.

SANS Fall Cyber Solutions Fest 2026: Emerging Technologies Track explores the cutting edge of security innovation as organizations race to secure increasingly complex digital ecosystems.

The SANS Fall Cyber Solutions Fest 2026: Identity Security and Zero Trust Track delivers a deep technical examination of identity as the modern attack surface.

The SANS Fall Cyber Solutions Fest 2026 SOC Track brings together frontline defenders, analysts, engineers, and SOC leaders to dissect the evolving threat landscape and the technologies reshaping modern security operations.

Now in its third year, this independent, vendor-neutral survey captures both a snapshot and a trendline—offering critical insights into what’s working, what’s lagging, and where the industry is heading. Join us as we break down the results and uncover how real-world teams are cutting through noise to focus on signals that matter.



Join us for this expert-led webcast to explore how to implement and evolve a Defense-in-Depth (DiD) strategy tailored to your organization’s risk profile, infrastructure, and cloud environment.
