SEC536: Adversarial AI - Penetration Testing AI Systems


GXPN proves that a practitioner can pinpoint and mitigate significant security flaws in systems and networks. Holders are qualified to conduct advanced penetration tests that model the behavior of real attackers, and to explain the business risk those attacks represent, covering everything from network-based and cryptographic attacks to memory-level exploitation on both Windows and Linux.
The GXPN exam is a single proctored test: 60 questions in 3 hours, with a minimum passing score of 67%. GIAC periodically reviews and may update these specifications, so candidates should confirm the exact format and passing score for their specific attempt in the Certification Information section of their GIAC account before test day.
GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page.
GXPN fits network and systems penetration testers, incident handlers, application developers, and IDS engineers, along with any security professional responsible for assessing networks, systems, and applications to find exploitable vulnerabilities. It's built for practitioners who already have penetration testing experience and want to move into exploit development and advanced attack simulation.
SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking is the SANS course built for GXPN. Across 6 sections and 30 hands-on labs, it covers the same ground the exam tests: network-based attacks, cryptographic implementation flaws, fuzzing and product security testing, and custom exploit development against both Linux and Windows targets, closing with a capstone Capture the Flag challenge.