SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Where AI Actually Helps in DFIR and Where It Still Lies to You
Artificial intelligence is now appearing in both sides of modern incidents: from adversary tradecraft attributed to state-backed actors experimenting with AI-assisted operations, to responder tooling embedded directly into investigation workflows. This session aims to examine where AI is genuinely adding value in DFIR today, including triage assistance, query generation, and analyst acceleration in platforms such as the AI-enabled SANS SIFT Workstation. We’ll contrast those gains with areas where AI remains unreliable, misleading, or actively dangerous if trusted without verification. Presented by Seth Enoka
Securing ICS/OT: What are We Doing?
For many organisations, securing ICS/OT has become a top priority causing a flurry of activity to build up defences in preparation for the next attack. But what is the activity organisations are doing and are they contributing towards safe and reliable operations. This talk explores the benefits and tribulations surrounding these activities along with real-world experiences of self-inflicted pain and blind ignorance that leads to near misses and direct impacts.


Seth is a DFIR practitioner, investigator, and instructor specializing in developing and leading digital forensics and incident response capability across complex and high-consequence environments.
Learn more

Jason Dely brings over 20 years of experience and a diverse industrial control system background to SANS and the industrial control system (ICS) community.
Learn more