SANS Institute

SANS Institute

Company-Unified Profile
0 followers

Expert cybersecurity training/webinars across blue team, cloud, DFIR, and governance

Cybersecurity Standards Scorecard (2025 Edition)
VideoMar 3, 2026

Cybersecurity Standards Scorecard (2025 Edition)

The webcast, hosted by veteran SANS instructor James Troll, introduces the 2025 edition of the Cybersecurity Standards Scorecard – an annual research effort that catalogues and evaluates the growing universe of cyber‑security frameworks. Troll notes that the SANS database now...

By SANS Institute
Blue Team | Intelligence-Driven Defense for the Real World
VideoFeb 17, 2026

Blue Team | Intelligence-Driven Defense for the Real World

The video outlines an intelligence‑driven approach to blue‑team operations, arguing that modern cyber‑threat intelligence (CTI) must evolve from static reports into an operational pipeline that turns external threat feeds and internal telemetry into concrete defensive actions. The speaker, who credits...

By SANS Institute
Red Team | Weaponizing LLM Fine-Tuning for Stealthy C2
VideoFeb 17, 2026

Red Team | Weaponizing LLM Fine-Tuning for Stealthy C2

Researchers from Palo Alto Networks' Cortex team demonstrated how attackers can weaponize fine-tuning of large language models to build stealthy command-and-control channels that live inside popular AI models. They show attackers already using LLMs for reconnaissance, social engineering and coding,...

By SANS Institute
Blue Team | From Exploit to Risk: Scaling Purple Team Insights
VideoFeb 17, 2026

Blue Team | From Exploit to Risk: Scaling Purple Team Insights

Anthony Switzer argues for “first-principle purple teaming,” a methodology that converts red-team and pentest findings into actionable business risk and mission impact. He stresses translating technical detections (e.g., Active Directory exploits, MITRE mappings) into language executives and auditors understand, and...

By SANS Institute
Blue Team | Hunting Cloud Persistence Without Malware
VideoFeb 17, 2026

Blue Team | Hunting Cloud Persistence Without Malware

The talk explains how modern attackers achieve long-term cloud persistence without malware by abusing legitimate cloud-native features—OAuth app consent, stolen or replayed tokens, mismanaged service principal credentials, long-lived API keys, mailbox rules and automated connectors. These malicious activities blend into...

By SANS Institute