Horizon3.ai

Events We Are Sponsoring

- What Mythos changes, and what it does not change
- Why AI-driven vulnerability discovery increases prioritization challenges
- The difference between vulnerable and exploitable risk
- How attackers use attack paths and identity weaknesses
- Practical approaches to improving cyber resilience

Threat hunting is no longer just a niche skill—it’s a critical pillar of modern defense. Now in its second decade, the 2026 SANS Threat Hunting Survey delivers a comprehensive, vendor-neutral look at how organizations around the world are adapting their hunting strategies to match the speed, complexity, and stealth of today’s threats. This year’s report explores the maturation of threat hunting in the face of faster, stealthier adversaries. From credential abuse and malware-free intrusions to the hunt for lateral movement in cloud environments, defenders are evolving—and this survey shows how. Join us for an exclusive look at the key findings from the latest research, and discover how threat hunters are staying proactive, practical, and one step ahead.
What You’ll Learn
- Top Threats: How teams are detecting malware-free intrusions, credential abuse, and lateral movement
- Cloud Hunting: Progress and pain points in multi-cloud environments
- AI in Hunting: Where AI helps, where it doesn’t, and what’s actually working
- Hunt Maturity: Benchmarks on tools, training, and metrics
- Lessons Learned: What works, what doesn’t, and how to stay ahead
Why Register? By registering, you’ll gain:
- Actionable benchmarks to measure your organization against industry peers.
- Practical strategies you can take back to your team immediately.
- 3 CPE credits for attending.
- Access to attend both live or the recorded session on your own time.
- Exclusive access to the full 2026 Threat Hunting Survey Insights report

All of DFIR. One Event.
Digital Forensics | Incident Response | Ransomware | Threat Hunting
The SANS DFIR Summit & Training is back—in a new city, a new season, and with our most in-depth program yet.
This year, the Summit has expanded to tackle today’s most challenging DFIR topics—from core digital forensics and incident response to focused deep dives in threat hunting and ransomware—through expert-led talks, open-source tool sessions, and more hands-on opportunities than ever before.
If staying sharp on the latest research, tools, and investigative tradecraft matters to you, this is where you need to be.
Summit: Oct 15-16 | Training: Oct 17-22

SANS 2026 DFIR Summit Solutions Track delivers a deep technical exploration of the tools, methodologies, and operational models driving next-generation digital forensics and incident response. Sessions focus on advanced evidence acquisition, host and network artifact analysis, memory forensics, cloud-native IR workflows, and the application of machine learning to accelerate triage and attribution.
Attendees will learn how to operationalize automation, standardize investigative pipelines, and integrate DFIR technologies into high-scale, distributed environments to improve precision, reduce dwell time, and harden enterprise response capabilities.
What to Expect
- Technical walkthroughs of emerging DFIR tooling—including endpoint telemetry pipelines, memory forensics frameworks, malware analysis sandboxes, and automated evidence extraction workflows.
- Deep-dive case studies detailing attacker tradecraft, artifact correlation strategies, cross-host timeline reconstruction, and cloud IR techniques across AWS, Azure, and GCP.
- Practical guidance and reference architectures for building scalable DFIR environments with automated triage, standardized enrichment, and integrated SOAR/EDR workflows.
Who Should Attend
- DFIR practitioners, digital forensic examiners, threat hunters, and reverse engineers seeking advanced, tool-focused investigative techniques.
- Incident response leads and SOC engineers responsible for building automated triage pipelines, forensic readiness strategies, and high-throughput investigation environments.
- Security architects and platform engineers integrating DFIR telemetry, EDR/XDR data, and cloud-native artifacts into centralized analysis and response systems.
- Organizations evaluating next-gen DFIR platforms, scaling IR operations, or adopting automation and ML-driven investigative workflows.