SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in the hands-on labs. Please arrive with a system meeting all of the specified requirements.
Back up your system before class. Better yet, use a system without any sensitive or critical data. SANS is not responsible for your system or data.
Mandatory System Hardware Requirements
Mandatory Host Configuration and Software Requirements
Your course media is delivered by download. The media files for class can be large. Start your course media downloads as soon as you receive the link. You will need the course files immediately on the first day of class.
Your course materials include setup instructions that detail the Docker-based workflow you must complete before class.
Your class uses an electronic workbook for its lab instructions. A second monitor or tablet can be useful for keeping class materials visible while you work on labs.
If you have questions about the laptop specifications, please contact customer service.
SEC543 is part of the SANS Offensive Operations learning path, designed to equip penetration testers and red team professionals with modern, AI-augmented techniques for vulnerability discovery and exploitation.
The Offensive Ops learning path develops deep technical expertise in areas such as penetration testing, exploit development, red team operations, and advanced attack techniques. Students progress from foundational offensive security concepts to sophisticated tradecraft used in real-world adversary simulations.
Depending on your current role or future goals, the following courses are natural complements to SEC543 within the Offensive Operations:
AI-assisted penetration testing uses large language models and AI coding agents to augment human security expertise. Rather than replacing pen testers, AI serves as a force multiplier by handling the time-consuming work of reading unfamiliar code, identifying patterns across large codebases, and generating custom tools, while the human operator provides security intuition, directs the analysis, and verifies results. This approach matters because modern applications increasingly rely on complex business logic that automated vulnerability scanners cannot evaluate. Logic flaws, broken access controls, and subtle authorization failures require the kind of semantic understanding that AI models can provide when properly directed. SEC543 teaches the methodology for doing this effectively and safely.
AI is rapidly transforming penetration testing. Security professionals who can effectively direct AI coding agents for source code analysis will find more vulnerabilities, deliver higher-quality assessments, and work more efficiently than those relying solely on traditional tools. SEC543 gives you a repeatable, immediately applicable methodology that differentiates your skillset in a competitive market, whether you work as an in-house pen tester, a security consultant, or an independent researcher.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources