Group Purchasing
Group Purchasing

What Is the GXPN Certification?

The GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) certification validates a practitioner's ability to pinpoint and mitigate significant security flaws in systems and networks. GXPN holders are qualified to conduct advanced penetration tests that improve system security by modeling attacker behavior, and to demonstrate the business risk posed by the threats they uncover.

By the numbers

3 hrs

Exam duration

60

Questions

67%

Min. passing score

What GXPN Covers

GXPN's 14 published exam objectives group into 5 practical domains that map to SEC660's course sections.

Network Access and Manipulation

Covers Establishing Network Access, Infrastructure Manipulation and Exploitation, and Traffic Interception and Manipulation.

Cryptographic Attacks and Endpoint Escalation

Covers Practical Cryptography and Endpoint Control Evasions and Escalation.

Fuzzing and Product Security Testing

Covers Product Security Testing and Fuzzing Foundations, Source Code Based Fuzzing Techniques, and Practical Scripting for Offensive Operations.

Linux Exploitation and Memory Protections

Covers Linux Execution, Memory, and Shellcode Foundations, Bypassing Linux Exploit Mitigations, and Return Oriented Stack-Based Exploits.

Windows Exploitation and Memory Protections

Covers Windows Execution and Memory Foundations, Windows Overflows and Execution Control, and Bypassing Windows Memory Protections.

Prepare With This Course

SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking

How SEC660 Prepares You for GXPN

SEC660 is built around the exam objectives that make up the GXPN certification: 

  • Section 1, Network Attacks for Penetration Testers builds skills tested under Establishing Network Access, Infrastructure Manipulation and Exploitation, and Traffic Interception and Manipulation.
  • Section 2, Crypto and Post-Exploitation aligns with Practical Cryptography and Endpoint Control Evasions and Escalation.
  • Section 3, Product Security Testing and Fuzzing builds skills tested under Product Security Testing and Fuzzing Foundations, Source Code Based Fuzzing Techniques, and Practical Scripting for Offensive Operations.
  • Section 4, Exploiting Linux for Penetration Testers aligns with Linux Execution, Memory, and Shellcode Foundations, Bypassing Linux Exploit Mitigations, and Return Oriented Stack-Based Exploits.
  • Section 5, Exploiting Windows for Penetration Testers builds skills tested under Windows Execution and Memory Foundations, Windows Overflows and Execution Control, and Bypassing Windows Memory Protections.
  • Section 6, Capture The Flag applies all of the above in a live, scored challenge against Linux and Windows targets.

Across all six sections, 30 hands-on labs and a capstone Capture the Flag challenge give you the chance to apply each skill against realistic Linux and Windows targets before you sit the exam. 

Read the full GXPN certification overview 

SEC660 Course Authors

Who Should Pursue GXPN

Network Penetration Testers

Systems Penetration Testers

Incident Handlers

Application Developers

IDS Engineers

Frequently Asked Questions

GXPN proves that a practitioner can pinpoint and mitigate significant security flaws in systems and networks. Holders are qualified to conduct advanced penetration tests that model the behavior of real attackers, and to explain the business risk those attacks represent, covering everything from network-based and cryptographic attacks to memory-level exploitation on both Windows and Linux. 

The GXPN exam is a single proctored test: 60 questions in 3 hours, with a minimum passing score of 67%. GIAC periodically reviews and may update these specifications, so candidates should confirm the exact format and passing score for their specific attempt in the Certification Information section of their GIAC account before test day. 

GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page. 

GXPN fits network and systems penetration testers, incident handlers, application developers, and IDS engineers, along with any security professional responsible for assessing networks, systems, and applications to find exploitable vulnerabilities. It's built for practitioners who already have penetration testing experience and want to move into exploit development and advanced attack simulation. 

SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking is the SANS course built for GXPN. Across 6 sections and 30 hands-on labs, it covers the same ground the exam tests: network-based attacks, cryptographic implementation flaws, fuzzing and product security testing, and custom exploit development against both Linux and Windows targets, closing with a capstone Capture the Flag challenge. 

Ready to earn your GXPN certification?

Add the GXPN exam attempt when you register for SEC660.

Already trained? Register for the exam directly through GIAC here.

GXPN Certification | GIAC Exploit Researcher & Pen Tester | SANS Institute