๐Ÿง I'll be teaching SANS FOR577: Linux Incident Response & Threat Hunting in Virginia Beach, VA โ€” August 24, 2026.

Linux is everywhere. Your cloud infrastructure, your containers, your routers, your endpoints. Attackers have known this for years โ€” and Linux-targeted intrusions are rising fast. Yet most IR teams are still primarily trained on Windows.

FOR577 changes that.

What we cover:
๐Ÿ” Threat hunting on Linux systems
๐Ÿง  Memory forensics
๐Ÿ“‹ Log analysis and timeline reconstruction
โšก Live response under pressure
๐Ÿ•ต๏ธ Tracking real-world APT intrusions on Linux platforms

This isn't a survey course. We get deep into the artifacts, the techniques, and the mindset you need to find attackers hiding in Linux environments.

๐ŸŽค Free SANS @night Talk โ€” August 26 @ 6:00 PM
**"Extending Protocol-SIFT to Linux"**

Protocol-SIFT has been getting a lot of attention in the DFIR community lately โ€” but the first release was 100% focused on Windows investigations. In this talk, we'll look at what it takes to extend Protocol-SIFT to cover Linux investigations. Free to attend for all on-site SANS students.

๐Ÿ’ฐ Early Bird Discount: Save $500
Use code EarlyBirdNA โ€” must be paid by July 9, 2026. Don't wait on this one.

๐Ÿ“ Hilton Virginia Beach Oceanfront, Virginia Beach, VA
๐Ÿ“… Course: August 24, 2026
๐ŸŽค @night Talk: August 26 @ 6:00 PM

๐Ÿ”— Register here: https://www.sans.org/cyber-security-training-events/virginia-beach-2026

#DFIR #SANS #FOR577 #LinuxForensics #IncidentResponse #ThreatHunting #InfoSec #ProtocolSIFT #Linux #Cybersecurity #DigitalForensics

SANS Virginia Beach 2026

Achieve the expertise you need to succeed in days, not months. Immerse yourself in a week of elite training designed for all skill-levels at SANS Virginia Beach 2025. From hands-on labs to cutting-edge techniques taught by industry-leading instructors, you'll gain the skills to excel and the certifications to prove it.

SANS Institute

๐Ÿง Teaching FOR577: Linux Incident Response & Threat Hunting at SANS Austin, June 22โ€“27!

Learn to hunt threats on Linux, dig deep into artifacts, and walk away prepped for your GIAC GLIR cert. Evenings bring CORE NetWars, SANS@Night talks, great networking, and legendary Austin BBQ. ๐Ÿ–๐ŸŽธ

๐Ÿ’ฐ Early-bird pricing ends May 7th โ€” register now and lock in your savings!

๐Ÿ‘‰ https://www.sans.org/cyber-security-training-events/austin-2026 #SANS #FOR577 #DFIR #Linux #ThreatHunting

Hunting Linux threats in sunny San Diego? ๐ŸŒด๐Ÿš Iโ€™m running #FOR577 LINUX Incident Response & Threat Hunting at #SANSSecWest 2026 in May with โ€” hands-on labs, real-world IR, and threat hunting to level up your Linux DFIR game on the worldโ€™s favorite server OS. https://www.sans.org/cyber-security-training-events/security-west-2026
There are 2 more days to get the early-bird discount for one of my all-time favorite conferences, #SANS #DFIRCON in Miami in Nov. There are a bunch of hands-on workshops for in-person attendees on Sun, 16 Nov, DFIR Netwars, DFIR Bites, and networking opportunities in the evenings during the week, and I'll be sharing tools (including one I just released this week), tips, tricks, and lessons learned from my more than 40 years of Unix/Linux in #FOR577 (my last run of 2025). @sansforensics The registration link is easier to find on the FOR577 page than the DFIRCON page, sorry. https://www.sans.org/cyber-security-courses/linux-threat-hunting-incident-response
Join me in one of my favorite places for the updated FOR577. Now, with more BTRFS, more rootkits, and more Linux attacks. #FOR577 #SANSSecWest
I just posted a Handler's Diary, I've released a python script to find Linux files with the immutable bit set. #FOR577 @sans_isc #SANSDFIR https://isc.sans.edu/diary/New+tool+immutablepy/31598/
I dropped a quick little tool today after some discussion on class today of the /proc filesystem and network connections #dfir #for577 https://isc.sans.edu/diary/New%20tool%3A%20le-hex-to-ip.py/30284