SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Unlock industry insights and hands-on learning with upcoming SANS webcasts and workshops. View archived webcasts by using status filter below or Click Here.
As adversaries harness AI to deploy polymorphic malware, agentic automation, and high-speed deception, defenders must respond with intelligent, explainable, and resilient threat intelligence systems.

This session explores the strategic shift toward unified DFIR platforms that merge forensic-grade investigation capabilities with incident response. Attendees will gain insight into how integrating evidence collection, artifact triage, endpoint isolation, and threat remediation into a single workflow reduces tool fatigue, shortens dwell time, and improves regulatory compliance.

This webcast will explore where conventional DLP programs fall short in the age of AI, including lack of context, overwhelming alert fatigue, and ineffective measurement.

Modern security leaders must deal with an endless barrage of changes to the business, technology, and threat landscape. This requires a combination of technical knowledge, understanding of risk, and the ability to lead teams in times of intense pressure.

Modern security leaders must deal with an endless barrage of changes to the business, technology, and threat landscape. This requires a combination of technical knowledge, understanding of risk, and the ability to lead teams in times of intense pressure.

The Model Context Protocol (MCP) is becoming increasingly important in enabling and expanding the capabilities of agents.

The SANS 2026 Kubernetes and CNAPP Forum is a focused, one-day event designed for security professionals, DevOps teams, and cloud architects seeking to secure modern, containerized applications.

Mike Hoffman will explain how Dispel’s OT-first remote access platform implements 5CC-aligned safeguards—covering architecture, deployment patterns, connection models, and operational controls. You’ll see how moving-target defense, disposable sessions, vaulted credentials, granular auditing, and compliance artifacts can reduce dwell time and simplify investigations—while preserving operator productivity.

This talk is about how to bootstrap almost anything, whether it’s a company, an open source project, a personal pursuit, a charity, a conference, or just about anything else.

In this webinar, experts from SANS and Cisco will explore the hybrid mesh firewall approach—what it is, why it’s critical today, and effective deployment at scale.

Join the renowned investigators of Baker221b and step into the role of a digital detective.

This isn't your typical "don't pay ransoms" talk. We'll explore the harsh realities where business continuity and regulatory pressure create impossible choices, providing practical frameworks for decision-making under duress, technical protocols for verifying attacker claims, and strategies for maintaining leverage when all seems lost.
