Training

What is BSides Oklahoma Training?
Take your cybersecurity skills to the next level with BSides Oklahoma’s immersive training sessions. Held over two days prior to our primary conference, these sessions offer in-depth learning experiences tailored to professionals at every stage of their cybersecurity journey.
With options for one-day, two-day, and half-day classes, our training program is designed to provide the flexibility you need to fit your schedule, while delivering top-tier content from industry leaders and experts.
Attendees can also earn continuing education credits, making it an ideal opportunity to advance your professional credentials.
2026 Training Classes
Check-in for trainings opens at 8:30am and classes begin at 9:00am.

AI Security Summit
Thursday, April 9
Join us for a full day of focused content on AI and Cybersecurity!
Active Directory Attack Fundamentals
Tuesday, April 7
This course gives a practical look at how Active Directory is commonly assessed during real-world security testing. It starts with a straightforward breakdown of what Active Directory is, why it continues to be a high-value target, and how design decisions made years ago still create risk in modern environments. From there, the focus shifts to how those weaknesses are actually identified and abused during an assessment.
The class blends live walkthroughs with hands-on work. Students observe an end-to-end attack scenario and then apply the same approach in their own lab environment, moving from initial access into analyzing privilege relationships and attack paths within Active Directory. The course uses modern tooling and workflows that reflect how networks are tested today, with an emphasis on understanding how access is gained, expanded, and evaluated, rather than treating attacks as isolated tricks or checklist items.
Building and using tabletops for IT Security professionals
Tuesday, April 7
Tabletop exercises are a valuable tool for organizations to prepare for cyber incidents and ensure that their incident response (IR) plans and playbooks are effective. In this one-day workshop, you will learn the basics of planning, developing, conducting and evaluating tabletop exercises as well as gain hands-on experience in their creation and facilitation. By the end of the workshop, you will have the knowledge and skills necessary to conduct effective tabletop exercises that can help your organization prepare for cyber incidents and maintain their IR plans and playbooks.
The Converged Frontier: Cloud, OT, and ICS Forensics Workshop
Tuesday, April 7
The air-gap is a myth, and the cloud is now the de facto control plane for our critical infrastructure. In this 8-hour intensive workshop, students will deep-dive into the high-stakes convergence of Cloud Architecture, Operational Technology (OT), Industrial Control Systems (ICS), and IoT Forensics. This workshop is designed for senior analysts and incident responders who must defend the bridge between the digital and physical worlds.
Using a live AWS Cyber Range, students will engage in hands-on labs simulating a sophisticated multi-stage campaign. We will track a simulated threat actor as they move from a cloud-native identity compromise (IAM/ECS) into the “Shadow IT” of IoT gateways and across the sensitive boundaries of OT/ICS environments. Students will learn to reconstruct the kill chain across the management plane and the wire, identifying the “Truth” before physical impact occurs.
Responding to an Incident and Beyond: IR Training
Wednesday, April 8
This course introduces the essential skills for properly preserving, collecting, and handling evidence, followed by effective preliminary triage and analysis and learn how to protect evidence integrity, document findings, and quickly assess materials to guide further investigative steps.
Enterprise Network Configuration Auditing
Wednesday, April 8
This is the class you tell your boss is about auditing. In reality, we will use red team tools like NetExec, BloodHound, Certipy and C2 frameworks to learn how attackers map and attack a network. You’ll walk away knowing how to “audit” your own network before someone else does.
This course is designed for administrators who want to understand how their networks are actually assessed and abused, without breaking production. Through hands-on labs, students learn how common red team tools are used to enumerate environments, audit access, and map real attack paths that exist due to configuration and trust, not exploits.
Network Forensics for Incident Response
Wednesday, April 8
This 7-hour hands-on course equips participants with practical skills in network forensics using firewall logs and SIEM systems during ongoing threat hunting and post-incident investigations. Designed for mixed experience levels, the class covers logging fundamentals (syslog enablement and centralization risks), the critical advantages of SIEM over standalone syslog servers (including resilience against compromise), and vendor-specific log analysis. Through live demonstrations and guided labs, attendees will learn to identify indicators of compromise (IOCs), attribute activity to threat actors and detect data exfiltration. The course concludes with actionable remediation strategies, such as implementing targeted security rules to prevent recurrence.
Securing Agentic AI Systems
Wednesday, April 8
This hands-on workshop equips security practitioners of all levels with practical skills to secure AI agents, MCP servers, and LangChain applications through effective logging, anomaly detection, and incident response. Beginning with foundational AI/ML concepts for non-developers, participants will learn to identify attack vectors unique to agentic systems—including prompt injection, tool abuse, and supply chain compromises. Through instructor-led exercises in pre-configured lab environments, attendees will implement comprehensive logging strategies, establish behavioral baselines, deploy canary tokens for detection, and conduct live incident investigations of simulated AI agent compromises. Using only open-source tools (ELK stack, Ollama, Wazuh), participants will gain immediately applicable techniques for detecting anomalous agent behavior, hunting threats in production environments, and building cost-effective detection systems that achieve excellent signal-to-noise ratios. The workshop emphasizes practical “quick wins” that security teams can deploy Monday morning, with all lab environments, configurations, and playbooks provided for continued learning. No coding experience required—all exercises are browser-based and instructor-guided.























