SEC504: Hacker Tools, Techniques, and Incident Handling

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usConnect, learn, and share with other cybersecurity professionals
Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders
Become a member for instant access to our free resources.
Sign UpMission-focused cybersecurity training for government, defense, and education
Explore industry-specific programming and customized training solutions
Sponsor a SANS event or research paper
We're here to help.
Contact UsJohn Pescatore joined SANS as Director of Emerging Security Trends in January 2013 with 35 years of experience in computer, network and information security. He was Gartner’s Lead Security Analyst for 13 years, working with global 5000 corporations and major technology and service providers. Prior to joining Gartner Inc. in 1999, Pescatore was Senior Consultant for Entrust Technologies and Trusted Information Systems. Prior to that, Pescatore spent 11 years with GTE developing secure computing systems. Pescatore began his career at the National Security Agency, where he designed secure voice systems and at the United States Secret Service, where he developed secure communications and surveillance systems. He holds a BSEE from the University of Connecticut and is an NSA Certified Cryptologic Engineer.
Explore content featuring this instructor’s insights and expertise.
Year after year successful phishing attacks on end users and system administrators are found to be the factor that enables over 80% damaging security incidents. This points out the need for two key security initiatives: replacing reusable passwords with multifactor authentication and making users less likely to fall for fraudulent messages.
The Domain Name System (DNS) is essentially the central nervous system of the internet—everyone needs it to work because without DNS services, digital business would come to a halt. Cybercriminals know this, too, and use DNS services to launch their attacks while they simultaneously attack the DNS services of their targets.
Many companies test to see if malicious actors can gain access into their environment or steal their valuable information, however, most security professionals don’t know if they would be able to detect adversaries once they are already inside. In fact, only 20% of common attack behaviors are caught by out-of-the-box EDR, MSSP and SEIM solutions.
As business applications have moved from monolithic blocks of code to distributed collaborations across multiple services, new forms of vulnerabilities have emerged and attackers have taken advantage of them. To explore this topic, SANS conducted a survey to collect information around industry practices in application security, focusing on Application Programming Interface (API) security awareness, processes, and controls.
Successful phishing attacks on end users and system administrators continue to be the factor that enables nearly 80% of damaging security incidents. Many companies are spending on user awareness and education programs but find it is hard to sustain initial gains in phishing awareness, recognition, and resilience and are lacking the data needed to develop and track meaningful awareness metrics.
In July 2023, SANS partnered with Carahsoft for the 2023 Government Security Solutions Forum, where cybersecurity preparedness went back to basics. In this webcast, SANS Director of Emerging Security Trends John Pescatore will review the top trends that emerged during the forum. John also uncovers how organizations can prepare for the National Cybersecurity Strategy Implementation Plan, or NCSIP, released by the White House in March 2023. His focus on preparation aims squarely at technology:• What technologies and capabilities exist for me to begin considering?• How do EO 14028 and NCSIP tie into each other?• What technologies put me ahead of the curve?Register for this webcast now, and be among the first to receive the associated white paper written by SANS Certified Instructor Matt Bromiley.
In today's hostile digital landscape, government agencies face a relentless barrage of cyber threats. Furthermore, agencies face a continuing stream of legislative, executive, and oversight recommendations, constantly keeping teams and technologies on their toes. This SANS Solutions Forum equips public sector cybersecurity teams with the essential knowledge to address these challenges and modern threats head-on.
Review relevant educational resources made with contribution from this instructor.