SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Learn how to use SOF-ELK®, a free and open-source Elastic Stack distribution tailored for security and DFIR. This hands-on workshop includes the latest 2025 updates and guides you through loading logs, analyzing data via Kibana, and building visualizations to support real-world investigations.
Join Eric Zimmerman for a hands-on dive into EZ Tools, the widely used open-source suite for Windows forensics. Learn how to leverage tools like KAPE, RECmd, and ShellBags Explorer to collect, parse, and analyze evidence efficiently. This session includes the latest expert tips on integrating new features into your investigative workflow.
Get hands-on with ArtEx, a powerful tool for researching and testing forensic artifacts with speed and precision. Learn how to navigate file systems, analyze serialized data, and explore key structures across multiple sources. This session includes what you need to integrate ArtEx into your workflow for artifact validation and investigative support.
Explore the LEAPPs suite for fast, structured parsing of mobile and cloud artifacts. This hands-on session covers expanded support for Google Takeout, vehicle data, and more to help streamline triage and improve investigation accuracy.
Get hands-on with the SANS Investigative Forensic Toolkit (SIFT), a powerful open-source workstation built to support in-depth forensic analysis. SIFT integrates several open-source tools to help you examine compromised systems, extract key artifacts, and reconstruct attacker timelines. This session walks you through practical, repeatable workflows you can apply directly to real-world investigations.
This hands-on workshop explores the core capabilities of Velociraptor, a powerful open-source DFIR tool for scalable endpoint visibility, live forensics, and threat hunting. Through guided exercises, you’ll learn how to deploy and configure Velociraptor, query endpoint data, and conduct targeted hunts across multiple systems. The session focuses on integrating Velociraptor into real-world investigative workflows, helping you build confidence in live response, artifact collection, and analysis at scale.
This wrap up workshop explores how integrating practical AI capabilities into the SIFT Workstation can speed up DFIR triage by surfacing anomalies, summarizing logs, and assisting with repetitive analysis tasks. Learn how local, auditable AI tools—designed for investigators, not data scientists—can act like a smart assistant to help cut through noise without replacing human judgment. AI won't solve forensics. But it can make it suck less.
Kick off your SANS DFIRCON Miami 2025 experience at the Welcome Reception. Be part of this kickoff event and join the industry’s most powerful gathering of cybersecurity professionals. Share stories, make connections, and learn how to make the most of your week in Miami, FL. Come join your instructors and fellow students for a fun, relaxed evening. Beverages (adult and otherwise) and small bites will be included.
Eric shares the power of open-source development, how community collaboration drives innovation, and the value of creating tools that help defenders stay ahead. This session includes the live reveal of the winning EZ Tool Challenge submission — a new tool built and launched live at DFIRCON.
Come join us for a casual networking event for SANS alumni and current attendees.
In this hands-on, instructor-led case simulation, attendees will act as members of an incident response team investigating a multi-phase intrusion into an international consulting firm’s network. The investigation begins after suspicious outbound traffic is detected from a financial analyst’s workstation. Early indicators suggest unauthorized access to sensitive internal repositories.
Come join us for a casual networking event for SANS alumni and current attendees.
The investigation continues with deeper analysis of attacker movement, persistence mechanisms, and exfiltration methods. Participants will complete their response strategy and strengthen their investigation workflow.
Registration: All students who register for a 4-6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About DFIR NetWars: Focused on digital forensics, incident response, threat hunting, and malware analysis, this tool-agnostic approach covers everything from low-level artifacts to high-level behavioral observations.
Registration: All students who register for a 4-6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About DFIR NetWars: Focused on digital forensics, incident response, threat hunting, and malware analysis, this tool-agnostic approach covers everything from low-level artifacts to high-level behavioral observations.