SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
The vast majority of web traffic is encrypted via HTTPS/TLS. That includes most malware command-and-control (C2) channels. This makes traditional signature-based network detection ineffective.
Most organizations now rely primarily on Endpoint Detection & Response (EDR) solutions to detect malware, and have little to no Network Detection and Response (NDR) capabilities.
This talk will explore network-based solutions that scale well and complement endpoint-based solutions. This includes detecting malware via DNS analysis, x.509 certificate analysis, and JA3 and JA4+ network fingerprinting.


Eric Conrad, a SANS Faculty Fellow and course author, has 28 years of information security experience. Eric is the CTO of Backshore Communications and his specialties include Intrusion Detection, Threat Hunting, and Penetration Testing.
Read more about Eric Conrad