Rob Lee
FellowChief of Research and Head of Faculty at SANS Institute
Specialities
Digital Forensics and Incident Response
Experience SANS training through course previews.
Learn MoreLet us help.
Contact usConnect, learn, and share with other cybersecurity professionals
Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders
Become a member for instant access to our free resources.
Sign UpMission-focused cybersecurity training for government, defense, and education
Explore industry-specific programming and customized training solutions
Sponsor a SANS event or research paper
We're here to help.
Contact UsRob Lee is the Chief of Research and Head of Faculty at SANS Institute and runs his own consulting business specializing in information security, incident response, threat hunting, and digital forensics. With more than 20 years of experience in digital forensics, vulnerability and exploit discovery, intrusion detection/prevention, and incident response, he is known as “The Godfather of DFIR”. Rob co-authored the book Know Your Enemy, 2nd Edition, and is course co-author of FOR500: Windows Forensic Analysis and FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics.
Extremely relevant! I feel as though Rob is truly invested in my success.
Rob is awesome! I really enjoy how he throws in some real-world encounters.
Incredibly technical content paired with Rob's fantastic delivery helps to make the learning quite easy and enjoyable.
Explore content featuring this instructor’s insights and expertise.
2月22日(火)に米国国土安全保障省は、あらゆる組織がロシアからのサイバーリスクにさらされていると警告しました。この警告は、ロシアによるウクライナの侵攻がエスカレートしていることを受けて発表されたもので、サイバー攻撃だけではなく地上での攻撃も含まれます
This urgent webcast will give an overview of current Russian Threat Actor capabilities, discuss critical infrastructure attacks on Ukraine, and possible escalation spillover into the EU and/or the United States.
Call for Presentations Now Open | Deadline: Monday, May 1Learn More and Submit Your Proposal“Can we use AI in our workplace?” — This question is being asked of every CISO and technical leader worldwide. The answers are not easy.
Confused by all the hype with AI? Not sure what the difference is between a LLM, GenAI or Deep Learning? Do you want to make the most of this exciting new technology but not sure where to start or the issues involved? Learn the fundamentals of Artificial Intelligence, Generative AI and Prompt Engineering and how exponentially increase your impact.
The SANS Faculty, experts and practitioners in cybersecurity, have been working to build and enhance the AI-driven cybersecurity landscape. In this forum, you will get a unique opportunity to hear firsthand accounts of how they utilize the power of Artificial Intelligence and Machine Learning to make significant advancements in cybersecurity.
What are the things that security leaders in healthcare organizations or security practitioners in the medical domain should think about from the perspective of AI in medical diagnostics?
We are thrilled to announce an exclusive fireside chat featuring Morgan M. Adamski, Executive Director of USCYBERCOM, and Rob Lee, Chief of Research and Head of Faculty.What to Expect:Insightful Discussions: Morgan Adamski will share USCYBERCOM’s strategic priorities, upcoming initiatives, and the evolving cyber threat landscape. Topics will include enhancing defensive capabilities, leveraging emerging technologies like AI and quantum computing, and strengthening public-private partnerships.Interactive Engagement: Attendees will have the opportunity to participate in live polls, offering their perspectives on key cybersecurity challenges and priorities. Whether you’re joining us in person or online, your voice will help shape the conversation.Q&A Session: We will gather questions from all participants and facilitate an upvoting process to highlight the most pressing topics. This ensures that the discussion addresses the areas you care about most, from workforce development and diversity in cybersecurity teams to international cooperation and cyber resilience strategies.Collaborative Insights: Rob Lee will provide his expertise on integrating cutting-edge research and curriculum development to support the cybersecurity workforce, complementing Morgan Adamski’s operational insights.Why Attend?Stay Informed: Gain firsthand knowledge of USCYBERCOM’s initiatives and how they align with national security objectives.Contribute Your Voice: Engage directly with leaders in the cybersecurity field and influence the topics that matter to you.Network and Learn: Connect with fellow cybersecurity professionals, researchers, and enthusiasts to share ideas and best practices.Don’t miss this unique opportunity to engage with top cybersecurity leaders and contribute to meaningful discussions that shape the future of cyber defense. Mark your calendars and join us for a session that promises to be both informative and interactive!
Join us for an exclusive fireside chat featuring Amazon Web Services' Chief Information Security Officer, Chris Betz, in conversation with renowned digital forensics expert and SANS Institute's Chief of Research, Rob T. Lee. Both veterans of the U.S. Air Force, Betz and Lee will share their journeys from military service to leadership roles in cybersecurity. They will discuss the challenges of securing one of the world's largest technology companies, the evolving threat landscape, and lessons learned from their experiences in both government and private sectors. Betz, who joined AWS in August 2023 after holding CISO roles at other major companies, and Lee, with over 25 years of experience in digital forensics and incident response, will offer candid perspectives on the future of cybersecurity. This conversation promises strategic insights and personal anecdotes from two practitioners who have operated at the highest levels of both military and corporate cybersecurity.
Join us for a research-driven webcast that unveils and explores the key findings of the 2025 Cybersecurity Workforce Research Report by SANS | GIAC. This comprehensive, global study delivers unparalleled insights into the cybersecurity talent landscape, highlighting the essential strategies for building and maintaining high-performing teams.
This focused track explores the ever-evolving world of Cloud IAM, diving into modern strategies, common missteps, and emerging tools designed to help organizations reclaim control over sprawling identities and creeping permissions.
Review relevant educational resources made with contribution from this instructor.