SEC504: Hacker Tools, Techniques, and Incident Handling

Unlock industry insights and hands-on learning with upcoming SANS webcasts and workshops. View archived webcasts by using status filter below or Click Here.
As cyber threats grow in complexity and frequency, organizations' strategies for detection and response must continuously evolve. The SANS 2025 Detection and Response Survey webcast will delve into the current state of cybersecurity operations, questioning whether the heavy emphasis on endpoint detection is creating new blind spots. By concentrating primarily on endpoints, organizations may narrow their scope and overlook threats emerging from other areas.
Since 2017, the SANS ICS/OT Cybersecurity Survey has been a foundational benchmark for critical infrastructure asset owners and operators. Each year, SANS explores the growing trends in cyber threats, vulnerabilities, and risks across industrial environments, including actionable recommendations for how organizations can improve their security posture.
Artificial Intelligence is no longer just a futuristic concept—it's a powerful driver of innovation across industries. In this webcast, we explore the latest breakthroughs in AI, including advancements in machine learning, generative models, and intelligent automation. Join leading experts as they discuss how AI is transforming business operations, enhancing decision-making, and creating new opportunities for growth.Attendees will gain insights into:Emerging trends and technologies shaping the AI landscapeReal-world applications and case studies from diverse sectorsBest practices for integrating AI into existing systemsEthical considerations and responsible AI developmentWhether you're a business leader, developer, or researcher, this session offers practical knowledge and strategic perspectives to help you navigate the rapidly evolving world of AI.
Moving from clicking alerts to actively hunting threats takes planning, the right data, and the right tools. In 2025, with AI and automation everywhere, it’s more important than ever to stay ahead of attackers, arming yourself with clear intelligence, full visibility, and smart processes to catch problems before they become crises.Attackers are now making effective use of AI too, creating fake identities, automated phishing, and constantly changing malware. Still, behind every tool is still a real person (or group) with goals. Organizations need to have a balance of automated analysis with human judgment so you can spot true threats in the noise.There’s no shortage of threat intelligence sources either: open source, commercial, vendor, and community. Yet many teams struggle to turn intelligence into real defense. In this track, you’ll learn to plug intelligence directly into your security tools, while equipping humans to do better analysis: enriching alerts instantly, mapping threats to the MITRE ATT&CK framework, and sharpening your hunting approach based on what adversaries actually do.Key Takeaways for 2025:Plan regular, data-driven hunt campaigns instead of one-off investigationsEmbed threat intelligence into SIEM, SOAR, XDR, and NDR workflowsUse AI to speed up indicator triage and add context fastCombine automated analytics with focused human-led huntsFocus on high-quality intelligence that fits your environmentWhat to Expect:Smart Alert Enrichment: Automatically add useful context to indicators without flooding your team.Next-Gen XDR & MDR: Learn how managed services and orchestration speed up hunts.Live CTI Demos: See real examples of turning raw threat feeds into detection rules.Automated Hunting Playbooks: Create repeatable tasks across XDR, NDR, and cloud logs.Actionable Intelligence Guides: Pick the best data sources and turn them into playbooks your team will use.Join Ismael Valenzuela, author and SANS senior instructor, as we explore the most successful strategies and opportunities for implementing these tactics in your organization.Full Fall Cyber Solutions Fest Track List:Emerging Technologies Track | Nov 4Cloud Identity and Access Management Track | Nov 5SOC Track | Nov 5Threat Track | Nov 6AI Track | Nov 6
This focused track explores the ever-evolving world of Cloud IAM, diving into modern strategies, common missteps, and emerging tools designed to help organizations reclaim control over sprawling identities and creeping permissions.
When performing effectively, security operations is ongoing visibility into information assets and threats to them. Poise with a nuanced understanding of risk and capacity to act.Explore the balance of people, process, and technology in the always insightful SOC Track. We'll surely address what AI is and isn't doing to enhance operations; cover threat intelligence; staffing; capabilities of the SOC; and discuss the ongoing challenge of scarce resources.Join us to hear how others are succeeding and failing to maintain an operational balance between competing internal priorities and threats which seem to relentlessly improve.
Join us for the Emerging Technologies Track at SANS Fall Cyber Solutions Fest 2025! If you’re interested in learning about the latest advancements in cybersecurity, this is the perfect opportunity for you.Engage with industry leaders as they present innovative tools and solutions designed to enhance your organization’s security posture. This one-day track will feature a diverse array of use cases, demonstrations, and insights aimed at empowering cybersecurity professionals to elevate their skills and strategies.
Moving red and blue teams out of their silos means building a continuous feedback loop that translates adversarial knowledge into actionable defensive countermeasures and real fixes. At the Solutions Summit for Hack & Defend 2025, we’ll present state of the art solutions that can help you to achieve this. Furthermore, with AI and automation everywhere, it’s easy to get buried in data. In this forum, we will show you solutions that can. help you speed up triage and investigations, while keeping human judgment in the loop.Key Points for 2025:Fast Turnaround: Move test findings into rules and controls without delayPurple-Team Drills: Run joint red/blue exercises to spot and close gapsAutomated Validation: Replay attacks and check defenses at scaleRisk-First Focus: Use simple threat models to target your highest-impact pathsAI with Purpose: Enrich alerts automatically, but keep analysts in controlJoin me, Ismael Valenzuela, author of SEC530, Defensible Security Architecture and Engineering and co-author of SEC568: Product Security Penetration Testing, and SANS senior instructor, as we turn offensive insights into stronger defenses at Hack & Defend 2025.
In an era where digital footprints expand faster than security teams can track, managing the attack surface is no longer a reactive task, it’s a continuous battle. Organizations face an evolving threat landscape driven by shadow IT, cloud sprawl, third-party risks, and zero-day vulnerabilities. Yet, many security teams struggle to gain full visibility into their external exposure, let alone remediate risks before adversaries exploit them.
Join top SANS instructors as they share their personal journeys into cybersecurity—how they got started, what shaped their careers, and the lessons they’ve learned along the way. From first steps into the industry to becoming recognized experts, their stories offer inspiration and practical guidance for anyone looking to launch or grow a career in cyber. Moderated by Karen Wetzel from NICE, this session will also connect their experiences to roles within the NICE Workforce Framework, spotlighting some of the most dynamic opportunities across both public and private sectors. Whether you're just beginning your career or planning your next move, you'll walk away with actionable tips and a clearer picture of how to navigate your own path in the cybersecurity field.
Securing the cloud isn’t easy. Thales Group reported that the percentage of corporate data stored in the cloud has doubled from 2015 (30%) to 2022 (60%). Meanwhile, the 2023 Unit 42 Attack Surface Threat Report, published by a threat research branch of Palo Alto Networks, reported that “80% of security exposures were observed in cloud environments.” Because this percentage is significantly larger than the percentage of data in the cloud, this implies that the cloud is somehow uniquely vulnerable, or that the cloud is uniquely challenging for security teams.Enter the SANS CloudSecNext Summit Solutions Track 2025. This event will provide you with practical solutions to these challenges from some of the world’s leading experts. We will deliver the latest tools, techniques, and procedures for cloud, multicloud, and hybrid environments. We hope you will be able to take what you learn in this event to make your cloud environments as secure, if not more secure, than your infrastructure on-premises.
We are lucky in Infosec. It may not be an easy field to get into, but once you’re in infosec, there is plenty of work available and many work models.