Stephen Sims
FellowResearch Fellow
Specialities
Offensive Operations
Experience SANS training through course previews.
Learn MoreLet us help.
Contact usConnect, learn, and share with other cybersecurity professionals
Engage, challenge, and network with fellow CISOs in this exclusive community of security leaders
Become a member for instant access to our free resources.
Sign UpMission-focused cybersecurity training for government, defense, and education
Explore industry-specific programming and customized training solutions
Sponsor a SANS event or research paper
We're here to help.
Contact UsOffensive Operations
Stephen Sims began working on computers at a young age with a fellow enthusiast: his father. Amazed by how easy it was to change an application's intended behavior, Stephen was quickly hooked. Today, he's an industry expert with over 20 years of experience in information technology and security. He's authored SANS most advanced course, SEC760: Advanced Exploit Development for Penetration Testers, was the 9th person in the world to earn the GIAC Security Expert certification (GSE), and co-author of the Gray Hat Hacking book series, as well as a keynote speaker who's appeared at RSA USA and APJ, DEF CON, OWASP AppSec, BSides events and more. On top of all this, Stephen is Curriculum Lead for SANS Offensive Operations.
Looking at everything I have learned from Stephen, I definitely feel I have gained an edge when it comes to the augmentation of my pentest skills. He made the impossible understandable and I am grateful for that.
Cryptography is such a complex topic, and Stephen does an excellent job of explaining these complex topics and making it easier to understand.
Steve Sims has real-world experience and fantastic skills in explaining the problem in different ways.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
Red Teamなどで働く攻撃技術の専門家の方であっても、既知の脆弱性を利用して侵入を行った経験はあるものの、自身で脆弱性の発見に取り組んだことのある方はそれほど多くありません。Jim ShewmakerとStephen Simsはファジングのコンセプトと具体的な手法について解説し、最新のファジング技術のデモを行います。何をファジングするべきか、どのような種類があるのか、どのようにそのバグを悪用するのかなどの質問を1時間のセッションでカバーしていきます。
A lot of offensive security professionals have experience weaponizing simple vulnerabilities, but may not have worked much with bug discovery. Join Jim Shewmaker and Stephen Sims as they talk through fuzzing concepts and methodology, and then jump into a demonstration on setting up a modern fuzzing harness. What should you fuzz for? What types of fuzzing is there? How do you know if a bug is weaponizable? We’ll aim to answer these questions and more in this one hour session.
Join us for an interactive SANS Day where cybersecurity experts and enthusiasts come together to explore the latest trends, challenges, and innovations in the field. This event promises a full day of insightful presentations, hands-on experiences, and valuable networking opportunities, and is designed for professionals at all levels. You will have the opportunity to engage with SANS Instructors and hear their insights on cybersecurity threats, customer landscape, AI, and how you can continue to development and advance in your career path. This is a must attend event for anyone passionate about staying ahead in the rapidly evolving world of cybersecurity. Don't miss out on the chance to learn, engage, connect, and grow in your cybersecurity journey!
Join us for an interactive SANS Day where cybersecurity experts and enthusiasts come together to explore the latest trends, challenges, and innovations in the field. This event promises a full day of insightful presentations, hands-on experiences, and valuable networking opportunities, and is designed for professionals at all levels. You will have the opportunity to engage with SANS Instructors and hear their insights on cybersecurity threats, customer landscape, AI, and how you can continue to development and advance in your career path. This is a must attend event for anyone passionate about staying ahead in the rapidly evolving world of cybersecurity. Don't miss out on the chance to learn, engage, connect, and grow in your cybersecurity journey!
Join Stephen Sims and Erik Van Buggenhout as they present, "The Always- On Purple Team: An Automated CI/CD for Detection Engineering", which they previously introduced at RSA Conference 2024. During this webcast, they will share tips on building the always-on purple team!
We are excited to invite you to an exclusive webcast where we'll unveil the latest updates to the SEC699 SANS Purple Teaming course. This session will provide an in-depth look at the enhancements we've made to ensure that our course remains at the forefront of cybersecurity training.
Join me in this talk where we will utilize an AI Chatbot to aid us in vulnerability discover and exploitation.
Annual penetration testing is no longer enough to keep pace with modern threats.
Identity Governance and Administration Powered by Risk Context – A Crucial Next Step in Enterprise Security