SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions!
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.
It is critical that you back-up your system before class. It is also strongly advised that you do not bring a system storing any sensitive data.
CPU
BIOS
RAM
Hard Drive Free Space
Operating System
Additional Software Requirements
VMware Player Install:
Your course media will now be delivered via download. The media files for class can be large, some in the 40 - 50 GB range. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as you get the link. You will need your course media immediately on the first day of class. Waiting until the night before the class starts to begin your download has a high probability of failure.
If you have additional questions about the laptop specifications, please contact customer service.
Visit this site: AI Disciplines In Offensive Operations.
SEC537 is designed for security practitioners who want to both use AI throughout offensive operations and assess the security of modern AI systems. This course is recommended for:
Both courses in this bundle offer a GIAC certification: GOAA for SEC535, and GAIPT for SEC536. You might select to take both, just one, or none.
The GIAC Offensive AI Analyst (GOAA) certification validates ability to apply practical, real-world offensive artificial intelligence techniques to modern cybersecurity challenges. Certified professionals prove their proficiency in applying advanced tactics such as deepfake-enabled phishing, automated vulnerability discovery, and AI-driven attack simulations to emulate sophisticated adversaries.
The GIAC AI Penetration Tester (GAIPT) certification validates a practitioner's hands-on AI penetration testing skills for assessing and exploiting vulnerabilities in enterprise AI systems.
Students should have a solid understanding of cybersecurity fundamentals, including enterprise security architecture, web applications, and application security concepts. Experience working with HTTP APIs is recommended. A basic familiarity with AI and machine learning concepts will help students understand the technologies being assessed, but prior AI experience is not required. Python knowledge is useful for customizing offensive tooling during selected labs but is not a prerequisite.
Start with SEC504: Hacker Tools, Techniques, and Incident Handling to build a strong offensive security foundation. Continue with SEC560: Enterprise Penetration Testing to master modern penetration testing methodology and the full attack lifecycle. From there, deepen your offensive expertise with SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking, expand into SEC699: Advanced Purple Teaming, Adversary Emulation & Detection Engineering, or complement your offensive skills with FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics.
AI for Offensive Security covers two related disciplines. Offensive AI applies AI to established attack workflows, including reconnaissance, vulnerability research, social engineering, exploit development, and malware creation. Adversarial AI treats AI applications as targets, testing LLMs, RAG pipelines, agents, models, APIs, and MCP servers for weaknesses such as prompt injection, data exposure, excessive agency, model manipulation, and tool abuse.
Both disciplines now matter because AI is changing the operator and the target at the same time. Threat actors are using AI across cyber operations, while organizations are connecting AI systems to sensitive data, tools, and business processes. Traditional penetration testing remains necessary, but it was not designed to fully assess how models interpret instructions, retrieve data, use tools, or act through connected systems.
It can help differentiate you by building hands-on skills in two specialized areas: using AI across offensive operations and testing AI systems as attack surfaces. These capabilities support career growth across penetration testing, red teaming, application security, AI security, and consulting.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources