In-Person, Virtual or Self-Paced Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months
Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months
Essential Skill Level Course material is for individuals with an understanding of IT or cyber security concepts
Course material is for individuals with an understanding of IT or cyber security concepts
44 Hands-On Lab(s) Apply what you learn with hands-on exercises and labs
Apply what you learn with hands-on exercises and labs
Master real-world incident response through hands-on labs, AI-powered analysis, and attacker mindset training. AI doesn't change the need for expertise—it raises the bar for what expertise looks like.
2025 Course Update Summary
The latest SEC504 update redefines the industry’s flagship incident handling and offensive operations course for the AI-driven age, integrating artificial intelligence throughout the labs and workbook.
For a detailed breakdown of what's new and how these updates can strengthen your team, download the flyer .
Respond effectively to incidents to limit damage
Evaluate breach evidence to determine compromise scope
Identify shadow cloud systems and other potential threats
Use attack tools to assess cloud and on-premises exposure
Apply defenses to enhance security and stop attacks
Develop threat intelligence by analyzing attacker tactics
Accelerating analysis tasks using AI systems
Adopt a dynamic and holistic incident response strategy
Strengthen cloud security posture
Leverage automation and AI to accelerate response
Understand and counter advanced attacker tactics
Protect critical assets with proactive defense strategies
Enhance threat detection with multi-layered analysis
How SEC504 Prepares You for GCIH
SEC504 is built around the exam objectives that make up the GCIH certification:
Section 1, Incident Response and Cyber Investigations builds skills tested under Incident Response and Cyber Investigation, Network and Log Investigations, and Malware and AI Assisted Investigations.
Section 2, Scanning and Enumeration Attacks aligns with Scanning and Mapping, SMB Security, and Detecting Exploitation and Covert Communications Tools.
Section 3, Password Attacks and Exploit Frameworks aligns with Understanding Passwords, Attacking Passwords, and Securing Credentials and Data in the Cloud.
Section 4, Web Application Attacks aligns with Exploiting Insecure Web Application References, Web Application Injection Attacks, and Web Application API Attacks.
Section 5, Post-Exploitation and AI Attacks aligns with Endpoint Attack and Pivoting, Detecting Evasive and Post-Exploitation Techniques, and Integrating LLMs with Offensive Operations.
Across all six sections, 44 hands-on labs and a capstone Capture the Flag event give you the chance to apply each skill against Windows, Linux, and cloud targets before you sit the exam.
Read the full GCIH certification overview.
Explore the course syllabus below to view the full range of topics covered in SEC504: Hacker Tools, Techniques, and Incident Handling.
Section 1 Incident Response and Cyber Investigations
The first section covers building an incident response process using the Dynamic Approach to Incident Response (DAIR) to verify, scope, contain, and remediate threats. Through hands-on labs and real-world examples, you’ll apply this method with tools like PowerShell and learn to accelerate analysis while using generative AI without compromising accuracy.
Network Investigations
Malware Investigations
Accelerating Incident Response with AI
Live Windows Investigation
Network Investigation with NDR
Writing IR Playbooks with AI
WordPress Log Assessment
Section 2 Scanning and Enumeration Attacks
This section explores attacker reconnaissance techniques, including network scanning, and target enumeration to identify security gaps. You’ll apply these tactics on Windows, Linux, Azure, and AWS targets, then analyze logs and evidence to detect attacks in real time.
Network and Host Scanning with Nmap
Cloud Spotlight: Cloud Scanning
Server Message Block (SMB) Security
Defense Spotlight: Hayabusa and Sigma Rules
Attacker Network Access Manipulation
Host Discovery and Assessment with Nmap
Shadow Cloud Asset Discovery with Masscan
Windows Server Message Block (SMB) Security Investigation
Windows Password Spray Attack Detection
The Many Uses of Netcat
Section 3 Password Attacks and Exploit Frameworks
This section covers key techniques for password compromises against on-premises and cloud systems, using tools like Legba, Hashcat, and Metasploit to simulate attacks and strengthen defenses. The insights gained help enhance practical defenses and inform incident response strategies.
Microsoft 365 Attacks
Understanding Password Hashes
Using Legba for Password Guessing and Spray Attacks
Bypassing Microsoft 365 authentication defenses with Amazon AWS
Password Cracking with Hashcat
Metasploit Attack and Analysis
Section 4 Web Application Attacks
In this course section we’ll focus on exploiting the many vulnerabilities in web applications including internal and public-facing systems, from on-premises targets to cloud and Software as a Service (SaaS) platforms.
Forced Browsing and IDOR
Cross-Site Scripting (XSS)
Exploiting API Systems
Forced Browsing and Insecure Direct Object Resource (IDOR) Attack
Command Injection Attack
Cross-Site Scripting Attack
Section 5 Post-Exploitation and AI Attacks
This section covers advanced post-exploitation and AI attacks, teaching how attackers bypass protections, establish persistence, exploit AI vulnerabilities, and exfiltrate data from internal networks and vulnerable cloud deployments. You’ll build analysis skills to detect and respond to these threats and apply them in real-world scenarios.
Endpoint Security Bypass
Pivoting and Lateral Movement
Establishing Persistence
Endpoint Protection Bypass: Bypassing Application Allow Lists
Pivoting and Lateral Movement with Command & Control Frameworks
Exploiting Windows as A Network Insider with Responder
Establishing Persistence with Metasploit
AI Prompt Injection Attacks
Section 6 Capture-the-Flag Event
Our Capture-the-Flag event is a full day of hands-on activity that has you working as a consultant for ISS Playlist, a fictitious company that has recently been compromised.
Things You Need To Know
Important! Bring your own system configured according to these instructions!
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.
It is critical that you back-up your system before class. It is also strongly advised that you do not bring a system storing any sensitive data.
64-bit Intel i5/i7 2.0+ GHz processor
CRITICAL NOTE: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot be used for this course.
Your system's processor must be a 64-bit Intel i5 or i7 2.0 GHz processor or higher. To verify on Windows 10 and 11, press Windows key + "I" to open Settings, then click "System", then " ". Your processor information will be listed near the bottom of the page. To verify on a Mac, click the Apple logo at the top left-hand corner of your display and then click " this Mac".
Intel's VT (VT-x) hardware virtualization technology must be enabled in your system's BIOS or UEFI settings. You must be able to access your system's BIOS to enable this setting in order to complete lab exercises. If your BIOS is password-protected, you must have the password. This is absolutely required.
16 GB RAM is the minimum requirement. To verify on Windows 10 and 11, press Windows key + "I" to open Settings, then click "System", then " ". Your RAM information will be toward the bottom of the page. To verify on a Mac, click the Apple logo at the top left-hand corner of your display and then click " this Mac".
Hard Drive Free Space
100 GB of FREE space on the hard drive is critical to host the VMs and additional files we distribute. SSD drives are also highly recommended, as they allow virtual machines to run much faster than mechanical hard drives.
Your system must be running either the latest version of Windows 10 and 11, macOS 10.15.x or later, or Linux that also can install and run VMware virtualization products described below.
Additional Software Requirements
VMware Player Install
Download and install VMware Workstation Pro 17+ (for Windows hosts), or VMWare Fusion Pro 13+ (for macOS hosts) prior to class beginning. Workstation Pro and Fusion Pro are now available free for personal use from the VMware website. Licensed commercial subscriptions to these products can also be used.
Other virtualization products, such as Hyper-V and VirtualBox, are not supported and will not work with the course material.
Your course media will now be delivered via download. The media files for class can be large, some in the 40 - 50 GB range. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as you get the link. You will need your course media immediately on the first day of class. Waiting until the night before the class starts to begin your download has a high probability of failure.
If you have additional questions the laptop specifications, please customer service .
SEC504 training is recommended for a diverse range of individuals, including:
Leaders of incident response teams
System administrators who are on the front lines defending their systems and responding to attacks
Other security personnel who are first responders when systems come under attack
General security practitioners and security architects who want to design, build, and operate their systems to prevent, detect, and respond to attacks
The GIAC Incident Handler (GCIH) certification validates a practitioner's ability to detect, respond, and resolve computer security incidents using a wide range of essential security skills. GCIH certification holders have the knowledge needed to manage security incidents by understanding common attack techniques, vectors and tools, as well as defend against and respond to such attacks when they occur.
Incident Handling and Computer Crime Investigation
Computer and Network Hacker Exploits
Hacker Tools (Nmap, Metasploit and Netcat)
More Certification Details
Unlimited, perpetual access to hands-on lab exercises
Printed and digital course books with a hands-on workbook
MP3 audio files of the full course
Video walkthroughs for all labs
Visual maps to simplify complex material
Digital index for quick reference
Bonus content and essential cheat sheets
The SEC504: Hacker Tools, Techniques, Exploits, and Incident Handling course has specific prerequisites to ensure that participants can fully engage with the material. Recommended prerequisites include:
Basic Knowledge of Networking Concepts: Familiarity with TCP/IP, DNS, and other core networking concepts is essential, as the course involves detailed network traffic analysis.
Understanding of Operating Systems: Proficiency in both Windows and Linux environments is beneficial, as exercises and labs often involve navigating and analyzing systems on these platforms.
Foundational Cybersecurity Knowledge: A general understanding of cybersecurity principles, common threats, and basic defensive strategies will help participants grasp attack and defense techniques.
Experience with Command Line Interfaces: Comfort with command line usage in both Windows and Linux environments, as several tools and techniques covered in the course require CLI proficiency.
If you are new to these concepts, SEC401: Security Essentials - Network, Endpoint, and Cloud covers many of these foundational skills and provides an excellent starting point before advancing to SEC504. While these skills are recommended, SEC504 training is designed to accommodate varying levels of experience by providing hands-on labs and detailed instruction. Those with foundational IT and security knowledge will gain the most value from this course.
SEC504 training is part of the Core Techniques Learning Path, which aims to equip security professionals with crucial information, skills, and strategies for protecting, maintaining, and securing systems. It is also part of the Offensive Operations Learning Path, which includes skills and focus areas like penetration testing, red team, and purple team.
In the context of SEC504: Hacker Tools, Techniques, Exploits, and Incident Handling, incident handling refers to the structured approach for detecting, responding to, and managing cybersecurity incidents like data breaches, malware infections, or unauthorized access attempts. The goal of incident handling is to quickly identify and contain a security incident, mitigate its impact, and restore normal operations as efficiently as possible.
Why Incident Handling Is Important
Minimizes Damage and Reduces Recovery Time: Effective incident handling ensures that attacks are quickly identified, contained, and managed, which can significantly reduce the damage to an organization and shorten the time needed to recover.
Preserves Organizational Reputation: Prompt and structured handling of incidents demonstrates professionalism and control, helping to maintain customer and stakeholder trust even in the face of a security breach.
Improves Cyber Resilience: Incident handling processes are critical for building resilience. By learning from each incident, organizations can continuously enhance their defenses and reduce vulnerabilities.
Ensures Compliance and Regulatory Adherence: Many industries require structured incident response protocols to comply with regulations (e.g., GDPR, HIPAA). Effective incident handling helps meet these compliance standards and avoid potential fines or penalties.
Supports Forensic Analysis and Evidence Gathering: A strong incident handling process enables organizations to gather and preserve evidence for further investigation, which can be essential for legal action, compliance reporting, or root cause analysis.
The SEC504 course covers these processes extensively, training participants to handle incidents systematically and confidently. This prepares cybersecurity professionals to protect their organizations and rapidly recover from incidents, aligning with SANS's mission to empower practical, high-stakes cybersecurity expertise.
Completing the SEC504 course can significantly boost your cybersecurity career, especially in roles focused on threat detection and incident response:
Increased Employability: The demand for skilled incident handlers is growing. SEC504 training equips you with practical skills, making you a strong candidate for cybersecurity roles.
Career Advancement: The course provides essential skills for moving from entry-level to advanced roles, such as Incident Responder, Security Analyst, or SOC Manager.
Certification Pathway: SEC504 training prepares you for the GIAC Certified Incident Handler (GCIH) certification, which can further validate your expertise and support career growth.
Real-World Application: Hands-on labs allow you to apply skills immediately, enhancing your effectiveness in current or future roles.
Industry Recognition: SANS courses are globally respected. SEC504 training, along with GCIH certification, demonstrates your commitment to high standards in cybersecurity.
Overall, SEC504 training builds essential skills, provides recognized certification pathways, and strengthens your profile for advanced cybersecurity roles.
This role uses cybersecurity tools to protect information, systems and networks from cyber threats. Find the SANS courses that map to the Protection SCyWF Work Role.
Technology Portfolio Management (OPM 804)
Responsible for managing a portfolio of technology investments that align with the overall needs of mission and enterprise priorities.
Threat Analysis (OPM 141)
Responsible for collecting, processing, analyzing, and disseminating cybersecurity threat assessments. Develops cybersecurity indicators to maintain awareness of the status of the highly dynamic operating environment.
Cybersecurity Curriculum Development (OPM 711)
Responsible for developing, planning, coordinating, and evaluating cybersecurity awareness, training, or education content, methods, and techniques based on instructional needs and requirements.
Vulnerability Assessment Analyst (DCWF 541)
Assesses systems and networks to ensure compliance with policies and identify vulnerabilities in support of secure and resilient operations.
Cyber Incident Responder Training, Salary, and Career Path
Monitor the organisation’s cybersecurity state, handle incidents during cyber-attacks and assure the continued operations of ICT systems.
Systems Security Management (OPM 722)
Responsible for managing the cybersecurity of a program, organization, system, or enclave.
Information Systems Security Developer (DCWF 631)
Designs and evaluates information system security throughout the software lifecycle to ensure confidentiality, integrity, and availability.
Course Schedule and Pricing
Location & instructor Virtual (OnDemand) Instructed by Joshua Wright Date & Time Course price $8,780 USD *Prices exclude applicable local taxes Registration Options Self-Paced
Location & instructor SANS Amsterdam September 2026 Amsterdam, NL & Virtual (live) Instructed by Chris Dale Date & Time Course price €8,230 EUR *Prices exclude applicable local taxes Registration Options In-Person Virtual
SANS Amsterdam September 2026
Amsterdam, NL & Virtual (live)
Location & instructor SANS Singapore Offensive Ops September 2026 Singapore, SG Instructed by Ron Hamann Date & Time Course price S$11,390 SGD *Prices exclude applicable local taxes Registration Options Join In-Person Waitlist
SANS Singapore Offensive Ops September 2026
Location & instructor SANS Network Security 2026 Las Vegas, NV, US & Virtual (live) Instructed by Joshua Wright Date & Time Course price $8,780 USD *Prices exclude applicable local taxes Registration Options In-Person Virtual
SANS Network Security 2026
Las Vegas, NV, US & Virtual (live)
Location & instructor SANS Paris September 2026 Paris, FR Instructed by Jeroen Hoof Date & Time Course price €8,230 EUR *Prices exclude applicable local taxes Registration Options In-Person
SANS Paris September 2026
Location & instructor SANS DC Metro September 2026 Bethesda, MD, US & Virtual (live) Instructed by Kevin Tyers Date & Time Course price $8,780 USD *Prices exclude applicable local taxes Registration Options In-Person Virtual
SANS DC Metro September 2026
Bethesda, MD, US & Virtual (live)
Location & instructor SANS October Singapore 2026 Singapore, SG & Virtual (live) Instructed by Anurag Khanna Date & Time Course price S$11,390 SGD *Prices exclude applicable local taxes Registration Options In-Person Virtual
SANS October Singapore 2026
Singapore, SG & Virtual (live)
Location & instructor SANS Cyber Safari 2026 Riyadh, SA & Virtual (live) Instructed by Mick Douglas Date & Time Course price $8,900 USD *Prices exclude applicable local taxes Registration Options In-Person Virtual
SANS Cyber Safari 2026
Riyadh, SA & Virtual (live)
Location & instructor SANS Manchester October 2026 Manchester, GB Instructed by Dave Shackleford Date & Time Course price £7,160 GBP *Prices exclude applicable taxes | EUR price available during checkout Registration Options In-Person
SANS Manchester October 2026
Location & instructor SANS Miami 2026 Coral Gables, FL, US & Virtual (live) Instructed by Jorge Orchilles Date & Time Course price $8,780 USD *Prices exclude applicable local taxes Registration Options In-Person Virtual
Coral Gables, FL, US & Virtual (live)
Benefits of Learning with SANS
Get feedback from the world’s best cybersecurity experts and instructors
Choose how you want to learn - online, on demand, or at our live in-person training events
Get access to our range of industry-leading courses and resources
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
