SEC536: Adversarial AI - Penetration Testing AI Systems


GLIR validates a practitioner’s knowledge of Linux incident response and threat hunting. Certification holders are qualified to conduct system triage, perform evidence collection, and analyze incidents to identify an attack’s initial entry point and its movement across Linux systems.
GIAC lists the GLIR exam as one proctored exam with 82 questions, a 3-hour time limit, and a minimum passing score of 66%. GIAC periodically reviews exam specifications, so check the Certification Information section of your GIAC account for the format that applies to your attempt.
GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page.
GIAC lists GLIR for incident response team members, threat hunters, SOC analysts, experienced digital forensic analysts, federal agents and law enforcement, and red team members, penetration testers, and exploit developers.
FOR577: LINUX Incident Response and Threat Hunting maps to the GLIR exam objectives across six sections, with 29 hands-on labs and a capstone APT Incident Response Challenge, using the SANS SIFT Workstation. It provides great training if you’re thinking of pursuing GLIR, though SANS training is not required for GIAC certification. See FOR577.