SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Endpoint Detection and Response (EDR) has become the backbone of modern security programs—and for good reason. It delivers deep visibility into managed devices and has significantly improved detection outcomes. But there’s a growing problem most organizations haven’t fully accounted for: a massive and expanding portion of enterprise traffic never touches those endpoints at all.
In this webcast, we’ll examine the blind spots created by an endpoint-only security strategy and explore how attackers are actively exploiting them. We’ll break down why this gap matters operationally—not just from a risk perspective, but in terms of cost and efficiency. When threats are stopped upstream at the network layer, they never become incidents. When they reach the endpoint, even if detected, they trigger alerts, investigations, and remediation workflows that consume valuable SOC resources.
Join us as Principal Instructor Aaron Cure walks through a practical, phased approach to adopting Secure Web Gateway (SWG) capabilities—from basic URL filtering to TLS inspection, inline DLP, and broader Security Service Edge (SSE) integration. If your organization has invested heavily in endpoint security but lacks visibility into what’s happening across the network, this session will help you understand what you’re missing—and how to close the gap.


Aaron is a Senior Security Consultant at Cypress Data Defense and teaches SANS SEC542: Web App Penetration Testing and Ethical Hacking, and SEC588: Cloud Penetration Testing.
Read more about Aaron Cure