SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.
Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.
Mandatory System Hardware Requirements
Mandatory Host Configuration And Software Requirements
Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.
Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.
If you have additional questions about the laptop specifications, please contact customer service.
SEC555 training is recommended for a diverse range of individuals, including:
The GIAC Certified Detection Analyst (GCDA) certification validates a practitioners understanding of how to collect, analyze, and tactically use modern network, endpoint, and cloud data sources to detect malicious or unauthorized activity.
A basic understanding of:
Nice-to-haves:
The SEC555 course is a part of the “Advanced Cyber Defense” Learning Path, which aims to train security professionals for platform-focused network monitoring. The SEC555 course is a part of the “Advanced Cyber Defense” Learning Path, which aims to train security professionals for platform-focused network monitoring.
Depending on your current or desired future role, one of these courses is a great next step in your cybersecurity journey:
Security Analyst/Intrusion Detection:
Security Engineer:
Cloud Security Analyst:
SOC Leadership
Detection engineering and SIEM analytics are key pillars of modern cybersecurity.
Detection engineering is the practice of proactively designing, implementing, and refining security measures to identify threats before they cause damage. It includes creating precise detection rules, optimizing how log data is collected and analyzed, and building systems that enhance visibility into potential attacks.
SIEM (Security Information and Event Management) analytics involves collecting, correlating, and analyzing log data from various sources to detect unusual patterns and support real-time threat response.
Together, these practices empower security teams to move from reactive to proactive defense. They allow organizations to uncover hidden threats, improve response times, and reduce business risk. In today’s fast-evolving threat landscape, detection engineering and SIEM analytics are essential for staying ahead of adversaries and protecting critical assets. Their integration is what enables the development of resilient, scalable, and intelligent security operations.
SEC555: Detection Engineering and SIEM Analytics can significantly benefit your cybersecurity career by enhancing your ability to identify and respond to security threats. It will deepen your understanding of how to configure and optimize SIEM systems to detect suspicious activities, ensuring that you can efficiently monitor and manage security incidents in real-time. The course will also teach you how to develop custom detection rules, correlate events, and analyze large volumes of security data.
Mastering these skills can help you play a pivotal role in an organization's security operations, proactively preventing breaches. It can also open up opportunities in threat hunting, incident response, and security operations centers (SOCs). With the growing importance of threat detection in cybersecurity, this expertise will make you a more valuable asset in securing modern IT environments.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources