SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
In an era of relentless and increasingly stealthy cyber threats, security operations centers (SOCs) are under pressure to investigate and respond faster than ever without sacrificing accuracy or defensibility. The traditional separation between digital forensics and incident response (DFIR) no longer fits the scale or speed of modern attacks.
This session explores the strategic shift toward unified DFIR platforms that merge forensic-grade investigation capabilities with incident response. Attendees will gain insight into how integrating evidence collection, artifact triage, endpoint isolation, and threat remediation into a single workflow reduces tool fatigue, shortens dwell time, and improves regulatory compliance.
We’ll highlight practical applications of this approach in scenarios ranging from insider threats and ransomware to advanced persistent threats (APTs) and lateral movement detection. Along the way, you'll learn how your SOC team can evolve your playbooks to focus on resilience, not just response.
Join us to understand why unifying forensic depth and incident agility isn't just a technical upgrade - it's a strategic imperative for any security leader aiming to future-proof their cyber defense posture.


Carl Bolterstein is a Director of Product Management within OpenText’s Cybersecurity business unit. Carl has over a decade of cybersecurity engineering experience and leads the product management efforts for the OpenText Digital Forensics and Incident Response portfolio, as well as OpenText’s network detection and response (NDR) platform.
Read more about Carl Bolterstein