SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.
Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.
Mandatory FOR563 System Hardware Requirements
Mandatory FOR563 Host Configuration and Software Requirements
FOR563 training is recommended for a diverse range of individuals, including:
There are no formal prerequisites for FOR563, and the course is designed to be accessible to a wide range of DFIR and security professionals. Prior experience in digital forensics or incident response is not required. While some comfort with reading simple Python code and basic command-line usage can be helpful, many of the tools used in the course offer intuitive graphical interfaces, and all code examples are well-explained and beginner-friendly. The techniques taught are broadly applicable across DFIR, threat hunting, cybersecurity automation, and other domains involving structured data analysis.
Local Large Language Models (LLMs) are important in cybersecurity because they enable organizations to leverage AI capabilities such as threat detection, log analysis, and automation, while maintaining full control over sensitive data. Unlike public LLMs, local deployments keep information private, align with regulatory frameworks (like NIST CSF and NERC CIP), and reduce risk by eliminating exposure to third-party APIs.
This course addresses challenges like context limitations and model fine-tuning through four technical labs, empowering students to automate investigations and tailor AI tools without compromising sensitive data. FOR563 bridges the gap between cutting-edge AI and secure forensic workflows, giving teams the confidence to integrate AI into their operations, privately and effectively.
In a time where cybersecurity teams are increasingly exploring AI to improve investigation speed and accuracy, FOR563 positions you at the forefront of this transformation. This one-day, hands-on course is tailored specifically for DFIR professionals who want to integrate Artificial Intelligence into their workflows without exposing sensitive data to third-party platforms. By focusing on LLMs, FOR563 teaches you how to securely harness the power of AI to automate, accelerate, and scale your forensic and incident response capabilities. These skills are not only highly relevant but also immediately applicable, making you a more agile and impactful analyst in a rapidly evolving threat landscape.
Through this course, you'll learn to:

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources