SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
We ask that you do 5 things to prepare prior to class start. This early preparation will allow you to get the most out of your training. One of those five steps is ensuring that you bring a properly configured system to class. This document details the required system hardware and software configuration for your class. You can also watch a series of short videos on these topics.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.
It is critical that you back up your system before class. It is also strongly advised that you do not bring a system storing any sensitive data.
Your course media will now be delivered via download. The media files for class can be large, some in the 40 - 50 GB range. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as you get the link. You will need your course media immediately on the first day of class. Waiting until the night before the class starts to begin your download has a high probability of failure.
SANS has begun providing printed materials in PDF form. Additionally, certain classes are using an electronic workbook in addition to the PDFs. The number of classes using eWorkbooks will grow quickly. In this new environment, we have found that a second monitor and/or a tablet device can be useful by keeping the class materials visible while the instructor is presenting or while you are working on lab exercises.
If you have additional questions about the laptop specifications, please contact customer service.
SEC660 training is recommended for a diverse range of individuals, including:
The GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) certification validates a practitioner's ability to find and mitigate significant security flaws in systems and networks. GXPN certification holders have the skills to conduct advanced penetration tests and model the behavior of attackers to improve system security, and the knowledge to demonstrate the business risk associated with these behaviors.
This is a fast-paced, advanced course that requires a strong desire to learn advanced penetration testing and custom exploitation techniques. The following SANS courses are recommended either prior to or as a companion to taking this course:
Experience with programming in any language is highly recommended. At a minimum, students are advised to read up on basic programming concepts. Python is the primary language used during class exercises, while programs written in C and C++ code are the primary languages being reversed and exploited. The basics of programming will not be covered in this course, although there is an introductory module on Python.
You should also be well versed with the fundamentals of penetration testing prior to taking this course. Familiarity with Linux and Windows is mandatory. A solid understanding of TCP/IP and networking concepts is required.
This course is appropriate for alumni of the following courses:
SEC660 is also great preparation for students planning on taking SEC760: Advanced Exploit Development for Penetration Testers.
The SEC660 course is part of the Offensive Operations curriculum learning path, and it falls under the more advanced, specialized courses that are focused on certain offensive techniques. Other areas of focus within this learning path include cloud pen testing, red team, and purple team.
Ethical hacking is the authorized practice of testing and securing computer systems, networks, and applications by identifying and exploiting vulnerabilities before malicious attackers can. Ethical hackers—also known as penetration testers or security researchers—simulate real-world cyber threats to help organizations strengthen their defenses.
Ethical hacking is critical in today’s cybersecurity landscape because it helps organizations proactively identify and fix vulnerabilities before malicious attackers can exploit them. With cyber threats becoming more sophisticated, businesses, governments, and individuals rely on ethical hackers to strengthen their security posture and protect sensitive data.
The SEC660 course is not entry-level—it’s built for penetration testers, exploit developers, and Red Team professionals looking to refine their offensive security expertise.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources