Learn Python in depth and gain essential skills for customizing and developing your own information security tools. This course empowers security professionals to automate tasks, craft custom tools for forensics, network defense, and penetration testing, and respond swiftly to emerging threats. Build solutions for AI, data science, cloud security, and more.
Automate security tasks with Python programming skills built specifically for security practitioners. Write tools that enhance penetration testing, forensics, and incident response without becoming a full-time developer.
Security work demands automation, but most programming courses ignore security use cases. SEC573 teaches Python through security-relevant exercises that produce immediately useful tools.
Build practical security tools:
Fundamentals for Security
Master Python basics through security examples
Parse logs, packets, and forensic artifacts
Interact with security APIs and services
Handle binary data and network protocols
Offensive Automation
Develop custom reconnaissance tools
Build exploitation assistants and payloads
Automate lateral movement techniques
Create custom C2 capabilities
Defensive Automation
Parse and analyze security logs at scale
Build automated triage and analysis tools
Create custom detection signatures
Integrate with SIEM and SOAR platforms
Write clean, maintainable code following security best practices. Understand how attackers use Python so you can detect and defend against their tools.
Hands-on labs build progressively toward a complete security toolkit you take home and continue developing.
Earn GIAC GPYC certification (exam sold separately). 36 CPE credits across 6 intensive days.
Highlights
Leverage Python to perform routine tasks quickly and efficiently. Automate log analysis and packet analysis with file operations, regular expressions, and analysis modules to find evil. Develop forensics tools to carve binary data and extract new artifacts. Read data from databases and the Windows Registry.
128 hands-on labs covering Python fundamentals, data structures, debugging in VS Code, file operations, log parsing, packet analysis, disk and memory forensics, web requests, network sockets, and offensive automation techniques.
Certification: Prepares for Python Coder (GPYC). Ideal for security professionals, forensic analysts, network defenders, and penetration testers seeking automation skills. 36 CPEs across 6 days.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing uses one pricing dimension: a per-seat license for the SEC573 course. You pay for each seat, so cost scales with the number of people you enroll. There are no separate tiers or size options. To add more learners, you buy more seats. The seat covers access to this six-day course, which includes hands-on labs on Python, AI agents, and security automation. Choose the seat quantity that matches your team's needs.
Top-of-mind questions for buyers
What does one seat cover, and how many people can use it?
One seat is a single license for one learner. It cannot be shared. Each person you enroll in the SEC573 course needs their own seat. The seat covers this six-day course with 128 hands-on labs on Python, AI agents, and security automation, plus preparation for the GPYC certification.
Does one seat include the GIAC certification attempt or extended online access?
The seat covers the course itself. A GIAC certification attempt and extra online course access are described as separate add-ons on the seller site. Confirm with the vendor whether these are included with your Marketplace seat or purchased separately.
How does cost change if I need to train more people later?
Cost scales directly with seat count. Each additional learner requires buying another seat. There are no tiers or bulk size options in this listing, so adding people means adding seats one for one. Enroll the exact number of people you need.
www.sans.org
Helpful?
Vendor refund policy
Refunds available within 30 days if course not accessed.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Protect your dynamic cloud environments with consistent security, superior visibility, and advanced threat defense such as application visibility and control, deep packet inspection, IPS, malware defense, and URL filtering - powered by Cisco Talos® Threat Intelligence. Achieve deeper visibility into QUIC and TLS 1.3 traffic without breaking Layer 7 policies.
Protect your dynamic cloud environments with consistent security, superior visibility, and advanced threat defense such as application visibility and control, deep packet inspection, IPS, malware defense, and URL filtering - powered by Cisco Talos® Threat Intelligence. Achieve deeper visibility into QUIC and TLS 1.3 traffic without breaking Layer 7 policies.
Infoblox Threat Defense delivers preemptive DNS security to stop malware, ransomware, command-and-control (C2) communications, and DNS-based data exfiltration before they impact users or cloud workloads. It enriches SIEM, SOAR, and SOC operations with threat intelligence and automation.
Cloud Defense offers a revolutionary solution to discovering and protecting sensitive data in public cloud from modern ransomware and exfiltration attacks.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.