Skip to content
Hacker Techniques Incident Handling

Hacker Techniques Incident Handling

www.sans.org September 18, 2026

In-Person, Virtual or Self-Paced Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

Essential Skill Level Course material is for individuals with an understanding of IT or cyber security concepts

Course material is for individuals with an understanding of IT or cyber security concepts

44 Hands-On Lab(s) Apply what you learn with hands-on exercises and labs

Apply what you learn with hands-on exercises and labs

Master real-world incident response through hands-on labs, AI-powered analysis, and attacker mindset training. AI doesn't change the need for expertise—it raises the bar for what expertise looks like.

2025 Course Update Summary

The latest SEC504 update redefines the industry’s flagship incident handling and offensive operations course for the AI-driven age, integrating artificial intelligence throughout the labs and workbook.

For a detailed breakdown of what's new and how these updates can strengthen your team, download the flyer .

Respond effectively to incidents to limit damage

Evaluate breach evidence to determine compromise scope

Identify shadow cloud systems and other potential threats

Use attack tools to assess cloud and on-premises exposure

Apply defenses to enhance security and stop attacks

Develop threat intelligence by analyzing attacker tactics

Accelerating analysis tasks using AI systems

Adopt a dynamic and holistic incident response strategy

Strengthen cloud security posture

Leverage automation and AI to accelerate response

Understand and counter advanced attacker tactics

Protect critical assets with proactive defense strategies

Enhance threat detection with multi-layered analysis

How SEC504 Prepares You for GCIH

SEC504 is built around the exam objectives that make up the GCIH certification:

Section 1, Incident Response and Cyber Investigations builds skills tested under Incident Response and Cyber Investigation, Network and Log Investigations, and Malware and AI Assisted Investigations.

Section 2, Scanning and Enumeration Attacks aligns with Scanning and Mapping, SMB Security, and Detecting Exploitation and Covert Communications Tools.

Section 3, Password Attacks and Exploit Frameworks aligns with Understanding Passwords, Attacking Passwords, and Securing Credentials and Data in the Cloud.

Section 4, Web Application Attacks aligns with Exploiting Insecure Web Application References, Web Application Injection Attacks, and Web Application API Attacks.

Section 5, Post-Exploitation and AI Attacks aligns with Endpoint Attack and Pivoting, Detecting Evasive and Post-Exploitation Techniques, and Integrating LLMs with Offensive Operations.

Across all six sections, 44 hands-on labs and a capstone Capture the Flag event give you the chance to apply each skill against Windows, Linux, and cloud targets before you sit the exam.

Read the full GCIH certification overview.

Explore the course syllabus below to view the full range of topics covered in SEC504: Hacker Tools, Techniques, and Incident Handling.

Section 1 Incident Response and Cyber Investigations

The first section covers building an incident response process using the Dynamic Approach to Incident Response (DAIR) to verify, scope, contain, and remediate threats. Through hands-on labs and real-world examples, you’ll apply this method with tools like PowerShell and learn to accelerate analysis while using generative AI without compromising accuracy.

Network Investigations

Malware Investigations

Accelerating Incident Response with AI

Live Windows Investigation

Network Investigation with NDR

Writing IR Playbooks with AI

WordPress Log Assessment

Section 2 Scanning and Enumeration Attacks

This section explores attacker reconnaissance techniques, including network scanning, and target enumeration to identify security gaps. You’ll apply these tactics on Windows, Linux, Azure, and AWS targets, then analyze logs and evidence to detect attacks in real time.

Network and Host Scanning with Nmap

Cloud Spotlight: Cloud Scanning

Server Message Block (SMB) Security

Defense Spotlight: Hayabusa and Sigma Rules

Attacker Network Access Manipulation

Host Discovery and Assessment with Nmap

Shadow Cloud Asset Discovery with Masscan

Windows Server Message Block (SMB) Security Investigation

Windows Password Spray Attack Detection

The Many Uses of Netcat

Section 3 Password Attacks and Exploit Frameworks

This section covers key techniques for password compromises against on-premises and cloud systems, using tools like Legba, Hashcat, and Metasploit to simulate attacks and strengthen defenses. The insights gained help enhance practical defenses and inform incident response strategies.

Microsoft 365 Attacks

Understanding Password Hashes

Using Legba for Password Guessing and Spray Attacks

Bypassing Microsoft 365 authentication defenses with Amazon AWS

Password Cracking with Hashcat

Metasploit Attack and Analysis

Section 4 Web Application Attacks

In this course section we’ll focus on exploiting the many vulnerabilities in web applications including internal and public-facing systems, from on-premises targets to cloud and Software as a Service (SaaS) platforms.

Forced Browsing and IDOR

Cross-Site Scripting (XSS)

Exploiting API Systems

Forced Browsing and Insecure Direct Object Resource (IDOR) Attack

Command Injection Attack

Cross-Site Scripting Attack

Section 5 Post-Exploitation and AI Attacks

This section covers advanced post-exploitation and AI attacks, teaching how attackers bypass protections, establish persistence, exploit AI vulnerabilities, and exfiltrate data from internal networks and vulnerable cloud deployments. You’ll build analysis skills to detect and respond to these threats and apply them in real-world scenarios.

Endpoint Security Bypass

Pivoting and Lateral Movement

Establishing Persistence

Endpoint Protection Bypass: Bypassing Application Allow Lists

Pivoting and Lateral Movement with Command & Control Frameworks

Exploiting Windows as A Network Insider with Responder

Establishing Persistence with Metasploit

AI Prompt Injection Attacks

Section 6 Capture-the-Flag Event

Our Capture-the-Flag event is a full day of hands-on activity that has you working as a consultant for ISS Playlist, a fictitious company that has recently been compromised.

Things You Need To Know

Important! Bring your own system configured according to these instructions!

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.

It is critical that you back-up your system before class. It is also strongly advised that you do not bring a system storing any sensitive data.

64-bit Intel i5/i7 2.0+ GHz processor

CRITICAL NOTE: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot be used for this course.

Your system's processor must be a 64-bit Intel i5 or i7 2.0 GHz processor or higher. To verify on Windows 10 and 11, press Windows key + "I" to open Settings, then click "System", then " ". Your processor information will be listed near the bottom of the page. To verify on a Mac, click the Apple logo at the top left-hand corner of your display and then click " this Mac".

Intel's VT (VT-x) hardware virtualization technology must be enabled in your system's BIOS or UEFI settings. You must be able to access your system's BIOS to enable this setting in order to complete lab exercises. If your BIOS is password-protected, you must have the password. This is absolutely required.

16 GB RAM is the minimum requirement. To verify on Windows 10 and 11, press Windows key + "I" to open Settings, then click "System", then " ". Your RAM information will be toward the bottom of the page. To verify on a Mac, click the Apple logo at the top left-hand corner of your display and then click " this Mac".

Hard Drive Free Space

100 GB of FREE space on the hard drive is critical to host the VMs and additional files we distribute. SSD drives are also highly recommended, as they allow virtual machines to run much faster than mechanical hard drives.

Your system must be running either the latest version of Windows 10 and 11, macOS 10.15.x or later, or Linux that also can install and run VMware virtualization products described below.

Additional Software Requirements

VMware Player Install

Download and install VMware Workstation Pro 17+ (for Windows hosts), or VMWare Fusion Pro 13+ (for macOS hosts) prior to class beginning. Workstation Pro and Fusion Pro are now available free for personal use from the VMware website. Licensed commercial subscriptions to these products can also be used.

Other virtualization products, such as Hyper-V and VirtualBox, are not supported and will not work with the course material.

Your course media will now be delivered via download. The media files for class can be large, some in the 40 - 50 GB range. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as you get the link. You will need your course media immediately on the first day of class. Waiting until the night before the class starts to begin your download has a high probability of failure.

If you have additional questions the laptop specifications, please customer service .

SEC504 training is recommended for a diverse range of individuals, including:

Leaders of incident response teams

System administrators who are on the front lines defending their systems and responding to attacks

Other security personnel who are first responders when systems come under attack

General security practitioners and security architects who want to design, build, and operate their systems to prevent, detect, and respond to attacks

The GIAC Incident Handler (GCIH) certification validates a practitioner's ability to detect, respond, and resolve computer security incidents using a wide range of essential security skills. GCIH certification holders have the knowledge needed to manage security incidents by understanding common attack techniques, vectors and tools, as well as defend against and respond to such attacks when they occur.

Incident Handling and Computer Crime Investigation

Computer and Network Hacker Exploits

Hacker Tools (Nmap, Metasploit and Netcat)

More Certification Details

Unlimited, perpetual access to hands-on lab exercises

Printed and digital course books with a hands-on workbook

MP3 audio files of the full course

Video walkthroughs for all labs

Visual maps to simplify complex material

Digital index for quick reference

Bonus content and essential cheat sheets

The SEC504: Hacker Tools, Techniques, Exploits, and Incident Handling course has specific prerequisites to ensure that participants can fully engage with the material. Recommended prerequisites include:

Basic Knowledge of Networking Concepts: Familiarity with TCP/IP, DNS, and other core networking concepts is essential, as the course involves detailed network traffic analysis.

Understanding of Operating Systems: Proficiency in both Windows and Linux environments is beneficial, as exercises and labs often involve navigating and analyzing systems on these platforms.

Foundational Cybersecurity Knowledge: A general understanding of cybersecurity principles, common threats, and basic defensive strategies will help participants grasp attack and defense techniques.

Experience with Command Line Interfaces: Comfort with command line usage in both Windows and Linux environments, as several tools and techniques covered in the course require CLI proficiency.

If you are new to these concepts, SEC401: Security Essentials - Network, Endpoint, and Cloud covers many of these foundational skills and provides an excellent starting point before advancing to SEC504. While these skills are recommended, SEC504 training is designed to accommodate varying levels of experience by providing hands-on labs and detailed instruction. Those with foundational IT and security knowledge will gain the most value from this course.

SEC504 training is part of the Core Techniques Learning Path, which aims to equip security professionals with crucial information, skills, and strategies for protecting, maintaining, and securing systems. It is also part of the Offensive Operations Learning Path, which includes skills and focus areas like penetration testing, red team, and purple team.

In the context of SEC504: Hacker Tools, Techniques, Exploits, and Incident Handling, incident handling refers to the structured approach for detecting, responding to, and managing cybersecurity incidents like data breaches, malware infections, or unauthorized access attempts. The goal of incident handling is to quickly identify and contain a security incident, mitigate its impact, and restore normal operations as efficiently as possible.

Why Incident Handling Is Important

Minimizes Damage and Reduces Recovery Time: Effective incident handling ensures that attacks are quickly identified, contained, and managed, which can significantly reduce the damage to an organization and shorten the time needed to recover.

Preserves Organizational Reputation: Prompt and structured handling of incidents demonstrates professionalism and control, helping to maintain customer and stakeholder trust even in the face of a security breach.

Improves Cyber Resilience: Incident handling processes are critical for building resilience. By learning from each incident, organizations can continuously enhance their defenses and reduce vulnerabilities.

Ensures Compliance and Regulatory Adherence: Many industries require structured incident response protocols to comply with regulations (e.g., GDPR, HIPAA). Effective incident handling helps meet these compliance standards and avoid potential fines or penalties.

Supports Forensic Analysis and Evidence Gathering: A strong incident handling process enables organizations to gather and preserve evidence for further investigation, which can be essential for legal action, compliance reporting, or root cause analysis.

The SEC504 course covers these processes extensively, training participants to handle incidents systematically and confidently. This prepares cybersecurity professionals to protect their organizations and rapidly recover from incidents, aligning with SANS's mission to empower practical, high-stakes cybersecurity expertise.

Completing the SEC504 course can significantly boost your cybersecurity career, especially in roles focused on threat detection and incident response:

Increased Employability: The demand for skilled incident handlers is growing. SEC504 training equips you with practical skills, making you a strong candidate for cybersecurity roles.

Career Advancement: The course provides essential skills for moving from entry-level to advanced roles, such as Incident Responder, Security Analyst, or SOC Manager.

Certification Pathway: SEC504 training prepares you for the GIAC Certified Incident Handler (GCIH) certification, which can further validate your expertise and support career growth.

Real-World Application: Hands-on labs allow you to apply skills immediately, enhancing your effectiveness in current or future roles.

Industry Recognition: SANS courses are globally respected. SEC504 training, along with GCIH certification, demonstrates your commitment to high standards in cybersecurity.

Overall, SEC504 training builds essential skills, provides recognized certification pathways, and strengthens your profile for advanced cybersecurity roles.

This role uses cybersecurity tools to protect information, systems and networks from cyber threats. Find the SANS courses that map to the Protection SCyWF Work Role.

Technology Portfolio Management (OPM 804)

Responsible for managing a portfolio of technology investments that align with the overall needs of mission and enterprise priorities.

Threat Analysis (OPM 141)

Responsible for collecting, processing, analyzing, and disseminating cybersecurity threat assessments. Develops cybersecurity indicators to maintain awareness of the status of the highly dynamic operating environment.

Cybersecurity Curriculum Development (OPM 711)

Responsible for developing, planning, coordinating, and evaluating cybersecurity awareness, training, or education content, methods, and techniques based on instructional needs and requirements.

Vulnerability Assessment Analyst (DCWF 541)

Assesses systems and networks to ensure compliance with policies and identify vulnerabilities in support of secure and resilient operations.

Cyber Incident Responder Training, Salary, and Career Path

Monitor the organisation’s cybersecurity state, handle incidents during cyber-attacks and assure the continued operations of ICT systems.

Systems Security Management (OPM 722)

Responsible for managing the cybersecurity of a program, organization, system, or enclave.

Information Systems Security Developer (DCWF 631)

Designs and evaluates information system security throughout the software lifecycle to ensure confidentiality, integrity, and availability.

Course Schedule and Pricing

Location & instructor Virtual (OnDemand) Instructed by Joshua Wright Date & Time Course price $8,780 USD *Prices exclude applicable local taxes Registration Options Self-Paced

Location & instructor SANS Amsterdam September 2026 Amsterdam, NL & Virtual (live) Instructed by Chris Dale Date & Time Course price €8,230 EUR *Prices exclude applicable local taxes Registration Options In-Person Virtual

SANS Amsterdam September 2026

Amsterdam, NL & Virtual (live)

Location & instructor SANS Singapore Offensive Ops September 2026 Singapore, SG Instructed by Ron Hamann Date & Time Course price S$11,390 SGD *Prices exclude applicable local taxes Registration Options Join In-Person Waitlist

SANS Singapore Offensive Ops September 2026

Location & instructor SANS Network Security 2026 Las Vegas, NV, US & Virtual (live) Instructed by Joshua Wright Date & Time Course price $8,780 USD *Prices exclude applicable local taxes Registration Options In-Person Virtual

SANS Network Security 2026

Las Vegas, NV, US & Virtual (live)

Location & instructor SANS Paris September 2026 Paris, FR Instructed by Jeroen Hoof Date & Time Course price €8,230 EUR *Prices exclude applicable local taxes Registration Options In-Person

SANS Paris September 2026

Location & instructor SANS DC Metro September 2026 Bethesda, MD, US & Virtual (live) Instructed by Kevin Tyers Date & Time Course price $8,780 USD *Prices exclude applicable local taxes Registration Options In-Person Virtual

SANS DC Metro September 2026

Bethesda, MD, US & Virtual (live)

Location & instructor SANS October Singapore 2026 Singapore, SG & Virtual (live) Instructed by Anurag Khanna Date & Time Course price S$11,390 SGD *Prices exclude applicable local taxes Registration Options In-Person Virtual

SANS October Singapore 2026

Singapore, SG & Virtual (live)

Location & instructor SANS Cyber Safari 2026 Riyadh, SA & Virtual (live) Instructed by Mick Douglas Date & Time Course price $8,900 USD *Prices exclude applicable local taxes Registration Options In-Person Virtual

SANS Cyber Safari 2026

Riyadh, SA & Virtual (live)

Location & instructor SANS Manchester October 2026 Manchester, GB Instructed by Dave Shackleford Date & Time Course price £7,160 GBP *Prices exclude applicable taxes | EUR price available during checkout Registration Options In-Person

SANS Manchester October 2026

Location & instructor SANS Miami 2026 Coral Gables, FL, US & Virtual (live) Instructed by Jorge Orchilles Date & Time Course price $8,780 USD *Prices exclude applicable local taxes Registration Options In-Person Virtual

Coral Gables, FL, US & Virtual (live)

Benefits of Learning with SANS

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources