Erik Van Buggenhout
Senior InstructorCo-Founder & Partner at NVISO
Specialities
Offensive Operations
Experience SANS training through course previews.
Learn MoreLet us help.
Contact usConnect, learn, and share with other cybersecurity professionals
Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders
Become a member for instant access to our free resources.
Sign UpMission-focused cybersecurity training for government, defense, and education
Explore industry-specific programming and customized training solutions
Sponsor a SANS event or research paper
We're here to help.
Contact UsOffensive Operations
Erik Van Buggenhout is a co-founder of NVISO, a Belgian cybersecurity firm, as well as a SANS Senior Instructor and lead author of SEC599: Defeating Advanced Adversaries - Purple Team Tactics & Kill Chain Defenses and SEC699: Advanced Purple Teaming - Adversary Emulation & Detection Engineering, as well as coauthor of SEC560: Enterprise Penetration Testing. Prior to NVISO, Erik spent five years at a Big 4 firm, where he evolved into a subject matter expert for the EMEA region. He has been involved with SANS since 2009: first as a Mentor, then working his way to Community Instructor in 2012, becoming a Certified Instructor in 2016 and a Senior Instructor in 2020.
Fantastic job! Humor and attitude was fun and engaging. Erik was always prepared and knew the material very well.
Erik is great. He continues to keep the course interesting and engaging with his hilarious jokes.
[Erik] is very engaged and knowledgeable.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
As a follow-up of our previous workshop, we will continue building our purple team stack by emulating a number of different techniques and looking at different options for detection. In this particular workshop we will focus on the following topics:Stealing Credentials from LSASSCOM Object HijackingOffice Persistence We will introduce the topics using a short lecture and afterwards get our hands dirty with lab exercises! Prerequisites: Familiarity with Linux and Windows is mandatory System Requirements: Prior to the workshop participants should prepare the following -Download and install the workshop VM: https://sansurl.com/purple-team-stack-workshop-vmInstalled 64-bit host operating systems (Windows is recommended)Download and install VM Workstation Pro 15.5 or higher, VMware Fusion 11.5 or higher, or VMware Workstation Player 15.5 or higher versions on your system prior to the start of the workshopAdobe Acrobat or other PDF readerImportant! An AWS account is required to do hands-on exercises during the workshop. The AWS account must be created prior to the workshop.A credit card should be linked to the AWS account that was created. Estimated usage costs for the AWS account during the workshop are a maximum of $10. For detailed instructions on these preparation steps, please refer to the following URL: https://sansurl.com/purple-team-stack-workshop-readme * Please note that this WILL NOT be recorded. Due to the nature of these workshops, many have a capacity limit and will not be made available for archive. To help us offer this opportunity to as many people as possible, we are asking that you please only register if you plan to attend live.
Join SANS Purple Team courses author and Senior Instructor, Erik Van Buggenhout, and SANS Purple Team Ambassador and Principal Instructor, Jorge Orchilles, as they walk you through the new, innovative, and interactive Purple Team Poster.
Join Stephen Sims and Erik Van Buggenhout as they present, "The Always- On Purple Team: An Automated CI/CD for Detection Engineering", which they previously introduced at RSA Conference 2024. During this webcast, they will share tips on building the always-on purple team!
We are excited to invite you to an exclusive webcast where we'll unveil the latest updates to the SEC699 SANS Purple Teaming course. This session will provide an in-depth look at the enhancements we've made to ensure that our course remains at the forefront of cybersecurity training.
What? A webcast in 2025 about phishing...haven’t we sorted that stuff yet? Almost! :)
The landscape of Security Operations is changing rapidly, and automation is leading the charge. In the second episode of the “Purple Team Power Hour”, we’ll explore how security teams are moving beyond static, pre-built playbooks toward dynamic, AI-driven solutions that can adapt to evolving threats in real time.
Annual penetration testing is no longer enough to keep pace with modern threats.
Review relevant educational resources made with contribution from this instructor.