I got the opportunity to attend SANS SEC504 training.

The course is aimed at people who handle incidents. It's equally useful for anyone doing deeper analysis, as it covers the entire problem comprehensively from start to finish. After the shock of ENSA, I was expecting a lot of materials. It wasn't a box set, but 5 ring-bound books is quite a lot of reading and information. Since I already have some experience, part of the course was revision. But you still keep finding more and more things that will make your work easier or help you in other ways. If I repeated the course I'd undoubtedly discover something completely new again.

I can absolutely recommend this course to anyone who wants to improve. In the practical sections you get to try out countless techniques for analysing a problem, what steps to take in the event of a threat, and just how easy it is to take control of a poorly secured computer.

Other Related Posts:

.conf18

Conference and training from the perspective of a new Splunk user

I had the chance to attend the Power User Bootcamp training at the Splunk .conf18 conference in Orlando. It was a real experience — both in terms of how such a massive event was organised, the breadth of topics covered, and the op...

5th Oct 2018