Phil Hagen
FellowPrincipal Information Security Researcher at Red Canary
Specialities
Digital Forensics and Incident Response
Experience SANS training through course previews.
Learn MoreLet us help.
Contact usConnect, learn, and share with other cybersecurity professionals
Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders
Become a member for instant access to our free resources.
Sign UpMission-focused cybersecurity training for government, defense, and education
Explore industry-specific programming and customized training solutions
Sponsor a SANS event or research paper
We're here to help.
Contact UsDigital Forensics and Incident Response
Phil has covered deep technical tasks, managed an entire computer forensic services portfolio, and handled executive responsibilities. He's supported systems that demanded 24x7x365 functionality, managed a team of 85 computer forensic professionals in the national security sector, and provided forensic consulting services for law enforcement, government, and commercial clients. He is also the course lead and author of FOR572: Advanced Network Forensics and Analysis and the DFIR strategist at Red Canary, where he supports the firm's community engagement team.
Even by SANS standards, Phil clearly 'goes the extra mile' in depth of information, especially on exercises.
I really like how Phil incorporates real-life examples into the material. It really helps me visualize it!
As a long-time, enterprise network defender, I can say that Phils knowledge is excellent and this class should be manditory training for all blue training.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
SOF-ELK® (Security Operations and Forensics ELK) is a public, fully-configured, appliance-like distribution consisting of components from the Elastic Stack as well a hundreds of parsers and numerous dashboard for various log formats commonly encountered in incident response and security operations work.
SOF-ELK® (Security Operations and Forensics ELK)は、Elastic Stackのコンポーネントと、インシデントレスポンスやセキュリティ運用業務で必要とされることの多い様々なログフォーマット用の数百のパーサーと数多くのダッシュボードから構成されており、すぐに利用できるように事前に設定されたアプライアンスのようなディストリビューションとして公開されています。
Review relevant educational resources made with contribution from this instructor.