SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.
Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.
Mandatory System Hardware Requirements
Additional optional components for this course:
Mandatory Host Configuration And Software Requirements
Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.
Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.
If you have additional questions about the laptop specifications, please contact customer service.
SEC760 training is recommended for a diverse range of individuals, including:
It is mandatory that students have previous exploit-writing experience using techniques such as those covered in SANS SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking. This includes experience with stack-based buffer overflows on both Linux and Windows, as well as experience defeating modern exploit mitigation controls such as Data Execution Prevention, Address Space Layout Randomization, canaries, and SafeSEH. Experience with or an understanding of fuzzing tools such as AFL, the Sulley Fuzzing Framework, and Peach is required. Programming experience is important, preferably with C/C++. At a minimum, scripting experience in a language such as Python, Perl, Ruby, or LUA is mandatory. Prior experience with Python is strongly recommended. Programming fundamentals such as functions, pointers, calling conventions, structures, polymorphism, and classes will be assumed knowledge. Experience with reverse-engineering vulnerable code is also required, as is the ability to read x86/x64 disassembly from within a debugger or disassembler. ARM and MIPS is not covered in this course. Experience with both Linux and Windows navigation is required. If you do not meet these requirements you may not be able to keep up with the pace of the course.
Courses that lead in to SEC760:
Courses that are prerequisites for SEC760:
Equivalent courses from Offensive Security or other training providers
SEC760 is a challenging course covering topics such as writing IDA Python scripts, Linux heap overflows, Chrome V8 exploitation, patch diffing, memory corruption exploitation, Windows Kernel debugging and exploitation, and much more. Please see the course syllabus for a detailed listing, and be sure to look at the recommended prerequisites and laptop requirements. You are expected to already know how to write exploits for Windows and Linux applications, bypass exploit mitigation controls such as DEP and ASLR, and utilize return-oriented programming (ROP).
SANS gets a lot of questions about this course. Am I ready for SEC760? Should I take SEC660 first? I have taken SEC660, but am I definitely ready for SEC760? I have taken SEC560, so can I jump right to SEC760 if I only want the exploit development material? I have not taken any SANS pen testing courses, so which one should I start with? I have taken a course through Offensive Security or Corelan, is the material the same?
There is no "one size fits all" reply to these questions, as everyone has a different level of experience. Our recommendation is to thoroughly read through the course syllabus and prerequisite statements for any course you are considering.
SANS has prepared a 10 question exam that will help you determine if you are better suited for SEC660 or SEC760. Remember that this is purely from an exploit development perspective. SEC660 includes two sections of material on introduction to exploit development and bypassing exploit mitigation controls. Much of the other material in SEC660 is on a wide range of advanced penetration testing topics such as network device exploitation (routers, switches, network access control), pen testing cryptographic implementations, fuzzing, Python, network booting attacks, and escaping Linux and Windows restricted environments. Many SEC760 students have taken training from Offensive Security, Exodus Intelligence, Corelan, and others. Though there will certainly be overlap in some sections, there are many unique sections without overlap and students often say the courses complement one another.
SEC760 training is one of the most advanced courses that SANS offers, and it falls within the Offensive Operations curriculum. Many students take SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking or FOR610: Reverse-Engineering Malware prior to taking this course, although SEC660 is the only true prerequisite.
Other Offensive Operations training courses include those focused on specialized penetration testing, red team, and purple team.
Exploit development is the process of identifying vulnerabilities in software or systems and crafting code—called "exploits"—that can leverage those weaknesses to gain unintended access, execute commands, or otherwise bypass intended security controls. This practice lies at the core of offensive security and red teaming.
In the context of advanced cybersecurity defense and adversary emulation, exploit development is vital. It helps security professionals:
SANS SEC760: Advanced Exploit Development for Penetration Testers empowers learners to go beyond off-the-shelf tools. It provides the expertise needed to write custom exploits, understand complex attack chains, and ultimately improve an organization’s defensive posture by thinking like a determined attacker.
This is not just about offense—it is about building the highest level of defensive awareness.
Mastering exploit development can be a career-defining advantage in today’s cybersecurity landscape. It signals that you are not just following tools—you understand how they are built and how attackers think. Here is how SEC760 advances your career:

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources