Group Purchasing
Group Purchasing
AI SKILLSMAJOR UPDATES

SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking

SEC660Offensive Operations, Artificial Intelligence
  • 6 Days (Instructor-Led)
  • 46 Hours (Self-Paced)
Course authored by:
James ShewmakerStephen Sims
James Shewmaker & Stephen Sims
SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking
Course authored by:
James ShewmakerStephen Sims
James Shewmaker & Stephen Sims
  • GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
  • 46 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 30 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Master advanced pen testing, exploit writing, escaping restricted desktops, post-exploitation, fuzzing, crypto attacks, and Windows/Linux exploitation, using AI to assist with tasks like exploit development.

Course Overview

Learn advanced penetration testing skills and explore sophisticated attack vectors and exploit development. This course spans network infrastructure attacks, cryptographic implementation testing, product security testing, advanced post-exploitation techniques, and custom exploit writing for both Windows and Linux environments, using AI to assist. Hands-on labs provide practical experience with fuzzing, return-oriented programming, exploit mitigation bypasses, and real-world application exploitation.

2026 Course Update Summary

The latest SEC660 update modernizes the advanced penetration testing course. Students now learn how to incorporate AI into exploit research, vulnerability analysis, scripting, and bug discovery while developing advanced offensive skills across network attacks, product security testing, exploit development, and post-exploitation.

For a detailed breakdown of what's new and how these updates can strengthen you or your team, download the flyer.

Expert-Level Security Assessment: Advanced Methods in Penetration Testing

SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking is designed as a logical progression point for those who have completed SANS SEC560: Enterprise Penetration Testing, or for those with existing penetration testing experience. Students with the prerequisite knowledge to take this course will walk through dozens of real-world attacks used by the most seasoned penetration testers. The methodology of a given attack is discussed, followed by exercises in a hands-on lab to consolidate advanced concepts and facilitate the immediate application of techniques in the workplace. Each day of the course includes a two-hour evening boot camp to drive home additional mastery of the techniques discussed. A sample of topics covered includes attacks against network access control (NAC) and virtual local area network (VLAN) manipulation, network device exploitation, breaking out of Linux and Windows restricted environments, Linux privilege escalation and exploit-writing, testing cryptographic implementations, fuzzing, defeating modern OS controls such as address space layout randomization (ASLR) and data execution prevention (DEP), return-oriented programming (ROP), Windows exploit-writing, and much more, using AI to assist!

Attackers are becoming more clever and their attacks more complex. To keep up with the latest attack methods, you need a strong desire to learn, the support of others, and the opportunity to practice and build experience. This course provides attendees with in-depth knowledge of the most prominent and powerful attack vectors and furnishes an environment to perform these attacks in numerous hands-on scenarios. The course goes far beyond simple scanning for low-hanging fruit and shows penetration testers how to model the abilities of an advanced attacker to find significant flaws in a target environment and demonstrate the business risk associated with these flaws.

SEC660 starts off by introducing advanced penetration concepts and providing an overview to prepare students for what lies ahead. The focus of section one is on network attacks, especially the areas often left untouched by testers. Topics include accessing, manipulating, and exploiting the network. Covered attacks include NAC, VLANs, OSPF, ARP, IPv6, TLS/SSL, MFA bypass, and others. Section two starts with a technical module on performing penetration testing against various cryptographic implementations, then turns to PowerShell and post-exploitation, escaping Linux restricted environments and Windows restricted desktop environments. Day three jumps into product security penetration testing, Scapy for packet crafting, network and application fuzzing, and code coverage techniques. Sections four and five are spent exploiting programs on the Linux and Windows operating systems. You will learn to identify privileged programs, redirect the execution of code, reverse-engineer programs to locate vulnerable code, obtain code execution for administrative shell access, and defeat modern operating system controls such as ASLR, canaries, and DEP using ROP and other techniques. Local and remote exploits, as well as client-side exploitation techniques, are covered. You will learn how to leverage AI to assist in bug hunting, running your own local LLM. The final course section is devoted to numerous penetration testing challenges that require students to solve complex problems and capture flags.

Among the biggest benefits of SEC660 is the expert-level hands-on guidance provided through the labs and the additional time allotted each evening to reinforce daytime material and master the exercises.

Hands-On Training

  • Exploit routing protocol implementations such as OSPF.
  • Bypass NAC and captive portal implementations.
  • Bypass MFA protection
  • Perform MitM attacks to remove SSL.
  • Perform IPv6 attacks.
  • Exploit poor cryptographic implementations using CBC bit flipping attacks and hash length extension attacks.
  • Exploit virtualization implementations.
  • Write Python scripts to automate testing.
  • Write fuzzers to trigger bugs in software.
  • Reverse-engineer applications to locate code paths and identify potential exploitable bugs.
  • Debug Linux applications.
  • Debug Windows applications.
  • Write exploits against buffer overflow vulnerabilities.
  • Leverage a local LLM to assist with bug discovery and PoC generation.
  • Bypass exploit mitigations such as ASLR, DEP, stack canaries, SafeSEH, etc.
  • Use ROP to bypass or disable security controls.

Author Statement

"When conducting an in-depth penetration test, we are often faced with situations that require unique or complex solutions to successfully pull off an attack, mimicking the activities of increasingly sophisticated real-world attackers. Without the skills to identify and implement those solutions, you may miss a major vulnerability or not properly assess its business impact. Target system personnel are relying on you to tell them whether an environment is secure. Attackers are almost always one step ahead and are relying on our nature to become complacent, even with regard to the very controls we worked so hard to deploy. They now have AI to assist with their efforts. This course was written to keep you from making mistakes others have made, teach you cutting-edge tricks to thoroughly evaluate a target, and provide you with the skills to jump into exploit development."

- Stephen Sims

What You’ll Learn

  • Advanced network attack methodologies
  • Custom exploit development techniques, using AI to assist
  • Exploit mitigation bypass strategies
  • Modern fuzzing implementations
  • Post-exploitation advancement tactics
  • Return-oriented programming mastery
  • Cryptographic weakness assessment

Business Takeaways

  • Network access control evasion
  • Using AI to assist with bug hunting
  • Advanced IPv6 security implications
  • TLS/SSL security and MFA considerations
  • Assessment of cryptographic implementations
  • Routing and switching attack vectors
  • Escaping restricted desktops and post-exploitation

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking.

Section 1Network Attacks for Penetration Testers

Relationships between networked devices present unique attack vectors. In the first section, security professionals explore access manipulation, protocol exploitation, and device compromise across the LAN. Vulnerabilities can be patched, but relationships can be manipulated, making these skills crucial for comprehensive security testing.

Topics covered

  • Network access control evasion
  • Custom protocol manipulation methods
  • Advanced IPv6 security implications
  • TLS/SSL security considerations
  • OSPF routing attack vectors

Labs

  • Captive Portal Bypass
  • Credential Theft
  • IPv4, IPv6, and Route MitM Attacks
  • Transport Tampering
  • MFA Bypass Attacks

Overview

Section one serves as an advanced network attack module, building on knowledge gained from SEC560: Enterprise Penetration Testing. The focus will be on obtaining access to the network; manipulating the network to gain an attack position for eavesdropping and attacks, and for exploiting network devices; leveraging weaknesses in network infrastructure; and taking advantage of client frailty.

Full Lab Details

  • Identify and bypass multiple checks by a NAC/Captive Portal system
  • Obtain a middle position between two targets to abuse their relationship and inject content into plain HTTP and encrypted HTTPS traffic
  • Identify and work around networking restrictions like IPv4 firewalls by using autoconfigured IPv6
  • Abuse router-related protocols to divert traffic into an MiTM situation
  • Bypass Multi-Factor Authentication and coerce a browser to visit a malicious site

Full Topic Details

  • Bypassing network access/admission control (NAC)
  • Impersonating devices with admission control policy exceptions
  • Custom network protocol manipulation with Ettercap and custom filters
  • Overcoming TLS/SSL transport encryption security with SSL-stripping
  • Multiple techniques for performing network-based tampering
  • IPv6 for penetration testers
  • Exploiting OSPF authentication to inject malicious routing updates
  • Bypass Multi-Factor Authentication (MFA) for credential stealing

Section 2Crypto and Post-Exploitation

In this section, security professionals explore cryptographic exploitation and post-compromise techniques in restricted environments. Topics include cipher operations, implementation flaws, privilege escalation, and lateral movement.

Topics covered

  • Cryptographic implementation testing
  • Identify patterns in standard and custom encryption
  • CBC vulnerability exploitation
  • Hash-length extension attacks
  • Endpoint restriction bypasses

Labs

  • Detecting Cryptography Implementations
  • CBC Bitflipping Attacks
  • Hash Extension Attacks
  • Kiosk Escape
  • Docker Escape

Overview

Whether the initial foothold is access to a special purpose device, appliance, desktop, or server, escalation and restriction bypass is a practical part of penetration testing modern environments. We begin by building some fundamental knowledge on how ciphers operate, without getting bogged down in complex mathematics. Then we move on to techniques for identifying, assessing, and attacking real-world crypto implementations. We finish the module with lab exercises that allow students to practice their newfound crypto attack skill set against reproduced real-world application vulnerabilities.

The section continues with advanced techniques but focuses more on post-exploitation tasks. We leverage an initial foothold to further exploit the rest of the network. We abuse allowed features to escape restricted environments. First, we will build up knowledge of local restrictions on hosts. Once we establish a set of possible restrictions, we leverage that knowledge to circumvent them. We will cover the core components that restrict the desktop and a variety of escape possibilities. The Kiosk escape exercise is a perfect, real-world demonstration of the risks of relying on obfuscation and deny controls to thwart attacks.

As a major factor in post-exploitation, we cover both exploiting administrators' use of attack tools, many of which are PowerShell-based. We'll use specialized and alternative tools to escalate privileges, pivot, and deliver additional payloads.

Whether hosted on Linux or Windows, applications packaged in the form of Docker images are an additional consideration when identifying candidates for escalation or other abuse. The Docker escape exercise combines remote compromise, securing a better foothold, escalation, and finally escape to run privileged code outside the container on the host.

The section ends with a challenging boot camp exercise against a full network environment comprised of a variety of modern, representative, and fully patched systems with no obvious remote vulnerabilities.

Full Lab Details

  • Identify obscured/proprietary and known patterns of data/encryption
  • Create a forgery of an encrypted message with CBC Bit flipping attack
  • Extend a valid hash to match forged injected data message
  • Escape and escalate from a hardened kiosk Windows desktop
  • Attack, Escape, and Escalate from a Docker image used for routing and network-related monitoring
  • Combine escape and escalation techniques to escape, escalate, pivot, and steal sensitive information by abusing a Data Loss Prevention system

Full Topic Details

  • Pen testing cryptographic implementations
  • Exploiting CBC bit flipping vulnerabilities
  • Exploiting hash-length extension vulnerabilities
  • PowerShell as a victim
  • PowerShell as an attacker
  • Post Exploitation with PowerShell and alternatives
  • Escaping Software Restrictions on Windows
  • Escaping Software Restrictions in Linux and Docker
  • Two-hour Capture the Flag exercise against an enterprise Data Loss Prevention solution

Section 3Product Security Testing and Fuzzing

In section three, security professionals focus on modern product security testing, protocol manipulation, and fuzzing. Topics include custom fuzzing grammars, network protocols, file formats, and code coverage analysis for testing effectiveness.

Topics covered

  • Protocol state manipulation
  • Automated fuzzing optimization
  • Product security testing
  • Code coverage measurement
  • Wireless data leakage testing

Labs

  • Custom packet manipulation
  • Framework-based fuzzing
  • Binary instrumentation techniques
  • Source code analysis methods
  • AFL++ implementation strategies

Overview

We start by discussing product security testing and how products often use open-source software that can sometimes be involved in software supply chain attacks. We look at product security testing in the AI era. Before we get into fuzzing, we take a look at leveraging Scapy for custom network targeting and protocol manipulation. Using Scapy, we examine techniques for transmitting and receiving network traffic beyond what canned tools can accomplish, including IPv6.

Next, we take a look at dynamic analysis and fuzz testing. We leverage fuzzing to target both common network protocols and popular file formats for bug discovery. We use hands-on exercises to develop custom protocol fuzzing grammars to discover bugs in popular software.

Finally, we carefully discuss the concept of code coverage and how it goes hand-in-hand with fuzzing. We will conduct a lab using the DynamRIO instruction manipulation library, IDA Pro to demonstrate the techniques discussed, and using AFL++ for source code-assisted fuzzing.

Full Lab Details

  • Use the Scapy packet fuzzing framework to create custom packets to use for exploitation
  • Leverage fuzzers to identify vulnerabilities in open-source and commercial programs
  • Utilize fuzzing frameworks to build intelligent mutation fuzzers
  • Use code coverage tools to aid in fuzzing both closed-source and open-source applications
  • Utilize DynamoRIO and custom fuzzing tools to instrument closed-source binaries
  • Use IDA Pro to work on reversing vulnerable programs
  • Use AFLplusplus to instrument open-source programs for maximum code coverage

Full Topic Details

  • Manipulating stateful protocols with Scapy
  • Using Scapy to create a custom wireless data leakage tool
  • Product security testing in the AI era
  • Using BooFuzz for quick protocol mutation fuzzing
  • Optimizing your fuzzing time with smart target selection
  • Automating target monitoring while fuzzing with BooFuzz
  • Source code-assisted binary fuzzing and code coverage measurement using AFL++
  • Block-based code coverage techniques using DynamoRIO

Section 4Exploiting Linux for Penetration Testers

Linux exploitation is increasingly relevant in the era of AI-assisted vulnerability research. In this section, professionals explore memory management, privilege escalation, SUID exploits, and advanced bypass techniques like ROP and ASLR evasion. You will use a local LLM to assist in bug discovery and exploitation.

Topics covered

  • Stack memory management
  • AI-assisted bug discovery
  • 32-bit and 64-bit exploitation
  • Defeating exploit mitigations
  • Return-oriented programming

Labs

  • Linux buffer overflow exploitation
  • Return-to-libc implementation
  • Stack canary analysis
  • ASLR bypass techniques
  • 64-bit binary exploitation

Overview

Section four begins by walking through processor architecture from an exploitation perspective, as well as introducing x86 and x86-64 assembler and linking and loading. These topics are important for anyone performing penetration testing at an advanced level, working with exploits. Processor registers are directly manipulated by testers and must be intimately understood. Disassembly is a critical piece of testing and will be used throughout the remainder of the course.

We will take a look at the Linux OS from an exploitation perspective and discuss privilege escalation. We continue by describing how to look for SUID programs and other likely points of vulnerabilities and misconfigurations. The material will focus on techniques that are critical to performing penetration testing on Linux applications.

We then go heavily into stack overflows on Linux to gain privilege escalation and code execution. We will first cover using a debugger to expose internal program secrets. Then we will go over redirection of program execution and, finally, code execution. Techniques such as return to buffer and return to C library (ret2libc) will be covered, as well as an introduction to return-oriented programming.

The remainder of the section takes students through techniques used to defeat or bypass OS protections such as stack canaries and address space layout randomization (ASLR). The goal of this section is to expose students to common obstacles on modern Linux-based systems. AI is used to assist in bug discovery and PoC generation.

Full Lab Details

  • Identifying and exploiting memory corruption vulnerabilities in Linux programs
  • Utilizing a technique known as ret2libc to avoid Data Execution Prevention (DEP)
  • Analyzing stack canaries and looking for opportunities to repair them for successful exploitation
  • Exploiting binaries with Address Space Layout Randomization (ASLR) enabled
  • Exploiting 64-bit binaries
  • Leveraging a local LLM to assist in analysis
  • Extended hours exercises allowing you to continue using the techniques covered in class to exploit additional programs

Full Topic Details

  • Stack memory management and allocation on the Linux OS
  • Disassembling a binary and analyzing x86/x86-64 assembly code
  • Performing symbol resolution on the Linux OS
  • Identifying vulnerable programs using AI
  • Code execution redirection
  • Identifying and analyzing stack-based overflows on the Linux OS
  • Performing return-to-libc (ret2libc) attacks on the stack
  • Return-oriented programming
  • Defeating stack protection on the Linux OS
  • Defeating ASLR on the Linux OS

Section 5Exploiting Windows for Penetration Testers

Windows systems remain prevalent in enterprise environments, necessitating a deep understanding of Windows-specific security features. In this section, practitioners examine process structures, exception handling, and API interactions. Content covers stack-based attacks, DEP bypass, and ROP chains, with special attention given to client-side exploitation.

Topics covered

  • Windows OS protection analysis
  • Stack exploitation fundamentals
  • ROP chain construction
  • Client-side attack vectors
  • Shellcode development

Labs

  • Windows 11 vulnerability analysis
  • SafeSEH bypass implementation
  • ROP chain development
  • DEP mitigation techniques
  • Commercial application testing

Overview

Section five starts off covering the OS security features (ASLR, DEP, etc.) added to the Windows OS over the years, as well as Windows-specific structures, such as the process environment block (PEB), structured exception handling (SEH), thread information block (TIB), and the Windows application programming interfaces (API). Differences between Linux and Windows will be covered. These topics are critical in assessing Windows-based applications. We will also take a deep dive into the many exploit mitigations available on the Windows OS and applications, both mandatory and optional.

We then focus on stack-based attacks against programs running on the Windows OS. After finding a vulnerability in an application, the student will work with Immunity Debugger to turn the bug into an opportunity for code execution and privilege escalation. Advanced stack-based techniques, such as disabling data execution prevention (DEP) are covered. Client-side exploitation will be introduced, as it is a highly common area of attack.

We continue with the topic of return-oriented programming (ROP), demonstrating the technique against a vulnerable application, while looking at defeating hardware DEP and address space layout randomization (ASLR) on Windows 11.

Finally, we will take a quick look at shellcode and the differences between shellcode on Linux and Windows, followed by a ROP challenge.

Full Lab Details

  • Identify vulnerabilities and exploit commercial applications on the Windows 11 OS
  • Identify exploitable stack overflow conditions
  • Use techniques to evade exploit mitigations, such as SafeSEH
  • Utilize Return Oriented Programming (ROP) to work around the DEP mitigation on Windows
  • Write your own ROP chain with the help of tooling, and learn to debug ROP chains to ensure their success

Full Topic Details

  • The state of Windows OS protections on the Windows OS
  • Understanding common Windows constructs
  • Stack exploitation on Windows
  • Defeating OS protections added to Windows
  • Advanced stack-smashing on Windows
  • Using ROP
  • Building ROP chains to defeat DEP and bypass ASLR
  • Windows 11 exploitation
  • Client-side exploitation
  • Windows Shellcode

Section 6Capture The Flag!

Students face escalating difficulties across Linux and Windows systems, shellcode challenges, crypto challenges, and much more. The scoring system provides immediate feedback on successful exploitation, with point values reflecting real-world complexity and impact.

Topics covered

  • Multi-vector attack planning
  • Escalation path identification
  • Network attack implementation
  • System compromise techniques
  • Post-exploitation methods

Labs

  • Local privilege escalation
  • Remote system exploitation
  • Network infrastructure attacks
  • Protocol manipulation scenarios
  • Cryptographic attacks

Overview

This section will serve as a real-world challenge for students by requiring them to utilize skills they have learned throughout the course, think outside the box, and solve a range of problems from simple to complex. A web server scoring system and Capture the Flag engine will be provided to score students as they capture flags. More difficult challenges will be worth more points. In this offensive exercise, challenges range from local privilege escalation to remote exploitation on both Linux and Windows systems, as well as networking attacks and other challenges related to the course material.

Things You Need To Know

Important! Bring your own system configured according to these instructions.

We ask that you do 5 things to prepare prior to class start. This early preparation will allow you to get the most out of your training. One of those five steps is ensuring that you bring a properly configured system to class. This document details the required system hardware and software configuration for your class. You can also watch a series of short videos on these topics.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.

It is critical that you back up your system before class. It is also strongly advised that you do not bring a system storing any sensitive data.

  • 64-bit Intel i5/i7 2.0+ GHz processor or newer
  • Enabled "Intel-VT"
  • 32 GB RAM minimum (Needed to run a local LLM. 16 GB RAM may impact labs.)
  • 120 GB Free Hard Drive Space (100 GB min)
  • Windows 11 24H2+, macOS 10.15.x or later, or Linux that also can install and run VMware virtualization products described below.
  • VMware Workstation Pro 17.5.2+, or Fusion 13.5.2+ (You will need to run 4 VMs)
  • Local account with local administrative privileges
  • Ability to disable your enterprise VPN client temporarily for some exercises
  • Ability to disable your anti-virus tools temporarily for some exercises

Your course media will now be delivered via download. The media files for class can be large, some in the 40 - 50 GB range. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as you get the link. You will need your course media immediately on the first day of class. Waiting until the night before the class starts to begin your download has a high probability of failure.

SANS has begun providing printed materials in PDF form. Additionally, certain classes are using an electronic workbook in addition to the PDFs. The number of classes using eWorkbooks will grow quickly. In this new environment, we have found that a second monitor and/or a tablet device can be useful by keeping the class materials visible while the instructor is presenting or while you are working on lab exercises.

If you have additional questions about the laptop specifications, please contact customer service.

SEC660 training is recommended for a diverse range of individuals, including:

  • Network and Systems Penetration Testers: SEC660 provides penetration testers with the training they need to perform advanced testing against known or unknown applications, services, and network systems. And the course gives students the expertise to perform complex attacks and develop their own exploits for existing and new frameworks.
  • Incident Handlers: SEC660 gives incident handlers the knowledge they need to understand advanced threats, as handlers are often tasked with determining the threat level associated with an attack. The ability to understand advanced attack techniques and analyze exploit code can help a handler identify, detect, and respond to an incident.
  • Application Developers: SEC660 teaches developers the ramifications of poor coding. Often, a developer or code reviewer is required to clearly demonstrate the threat and impact of a coding error. This course provides developers with the knowledge to create proof-of-concept exploit code and document their findings.
  • IDS Engineers: SEC660 teaches IDS professionals how to analyze exploit code and identify weaknesses. This knowledge can be used to write better IDS signatures and understand the impact of an alert.

The GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) certification validates a practitioner's ability to find and mitigate significant security flaws in systems and networks. GXPN certification holders have the skills to conduct advanced penetration tests and model the behavior of attackers to improve system security, and the knowledge to demonstrate the business risk associated with these behaviors.

  • Network-based attacks
  • Cryptography-based attacks
  • Escalation and client-side attacks
  • Handling restricted environments
  • Scapy, fuzzing, and source code analysis
  • Shellcode and memory basics
  • Windows and Linux stack overflows
  • Defeating advanced stack protections on Windows and Linux

More Certification Details

  • Access to the in-class Virtual Training Lab for over 30 in-depth labs.
  • A course USB with many tools used for all in-house labs.
  • Virtual machines full of penetration testing tools and specimens specially calibrated and tested to work with all our labs and optimized for use in your own penetration tests.
  • Access to recorded course audio to help hammer home important network penetration testing lessons.

This is a fast-paced, advanced course that requires a strong desire to learn advanced penetration testing and custom exploitation techniques. The following SANS courses are recommended either prior to or as a companion to taking this course:

Experience with programming in any language is highly recommended. At a minimum, students are advised to read up on basic programming concepts. Python is the primary language used during class exercises, while programs written in C and C++ code are the primary languages being reversed and exploited. The basics of programming will not be covered in this course, although there is an introductory module on Python.

You should also be well versed with the fundamentals of penetration testing prior to taking this course. Familiarity with Linux and Windows is mandatory. A solid understanding of TCP/IP and networking concepts is required.

This course is appropriate for alumni of the following courses:

SEC660 is also great preparation for students planning on taking SEC760: Advanced Exploit Development for Penetration Testers.

The SEC660 course is part of the Offensive Operations curriculum learning path, and it falls under the more advanced, specialized courses that are focused on certain offensive techniques. Other areas of focus within this learning path include cloud pen testing, red team, and purple team.

Ethical hacking is the authorized practice of testing and securing computer systems, networks, and applications by identifying and exploiting vulnerabilities before malicious attackers can. Ethical hackers—also known as penetration testers or security researchers—simulate real-world cyber threats to help organizations strengthen their defenses.

Ethical hacking is critical in today’s cybersecurity landscape because it helps organizations proactively identify and fix vulnerabilities before malicious attackers can exploit them. With cyber threats becoming more sophisticated, businesses, governments, and individuals rely on ethical hackers to strengthen their security posture and protect sensitive data.

The SEC660 course is not entry-level—it’s built for penetration testers, exploit developers, and Red Team professionals looking to refine their offensive security expertise.

  • Become an elite penetration tester or Red Teamer with skills that go beyond standard ethical hacking.
  • Earn the GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) certification—highly respected in the cybersecurity industry.
  • Qualify for advanced security roles, such as Red Team Lead, Exploit Developer, or Offensive Security Engineer.
  • Increase your earning potential—top penetration testers and Red Teamers command six-figure salaries.

Relevant Job Roles

Vulnerability Researcher & Exploit Developer

Offensive Operations

In this role, you will work to find 0-days (unknown vulnerabilities) in a wide range of applications and devices used by organizations and consumers. Find vulnerabilities before the adversaries!

Explore learning path

Vulnerability Assessment

SCyWF: Protection And Defense

This role tests IT systems and networks and assesses their threats and vulnerabilities. Find the SANS courses that map to the Vulnerability Assessment SCyWF Work Role.

Explore learning path

Vulnerability Assessment (VUAS)

Skills Framework for the Information Age

Identification and classification of vulnerabilities across systems, applications, and networks. Findings are used to guide patching, mitigation, and security control enhancements.

Explore learning path

Vulnerability Analysis (OPM 541)

NICE: Protection and Defense

Responsible for assessing systems and networks to identify deviations from acceptable configurations, enclave policy, or local policy. Measure effectiveness of defense-in-depth architecture against known vulnerabilities.

Explore learning path

Application Pen Tester

Offensive Operations

Application penetration testers probe the security integrity of a company’s applications and defenses by evaluating the attack surface of all in-scope vulnerable web-based services, clientside applications, servers-side processes, and more. Mimicking a malicious attacker, app pen testers work to bypass security barriers in order to gain access to sensitive information or enter a company’s internal systems through techniques such as pivoting or lateral movement.

Explore learning path

Cyber Operations Planner (DCWF 332)

DoD 8140: Cyber Effects

Coordinates cyber operations plans, working with analysts and operators to support targeting and synchronization of actions in cyberspace.

Explore learning path

Penetration Tester

European Cybersecurity Skills Framework

Assess the effectiveness of security controls, reveals and utilise cybersecurity vulnerabilities, assessing their criticality if exploited by threat actors.

Explore learning path

Penetration Testing (PENT)

Skills Framework for the Information Age

Performance of authorised tests to identify vulnerabilities in networks, applications, and systems. Findings support remediation planning and risk reduction across the enterprise.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 12

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources