SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Apply your credits to renew your certifications
Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months
Course material is geared for cyber security professionals with hands-on experience
Apply what you learn with hands-on exercises and labs
Attackers move across cloud platforms, SaaS providers, and AI agents faster than logging can keep up. Learn to scope, contain, and act using incomplete evidence.
This course has been valuable to me because it helped connect the risk and remediation work I do with the technical testing activities that often produce those findings. I work in IT risk, so I am often looking at vulnerabilities, controls, remediation plans and business impact.
One enterprise investigation connects visibility, detection, hardening, incident response, and malware analysis. More than 25 integrated labs require you to follow suspicious activity through records held by systems and providers. You use these records to establish scope, test controls, and decide whether escalation, containment, or recovery is justified.
Business Takeaways


SANS Principal Instructor Ross Bergman brings nearly four decades of hands-on and leadership experience. SANS Senior Instructor Dave Shackleford has advised hundreds of organizations on cloud, network, and security architecture.
Read more about Ross Bergman

Cybersecurity leader Dave Shackleford combines decades of enterprise defense, cloud security, and hands-on consulting experience to help students master real-world security operations and modern threat defense.
Read more about Dave ShacklefordExplore the course syllabus below to view the full range of topics covered in SEC501: Applied Cyber Defense.
A persistent anomaly begins with records of network availability, privileged access, and DNS activity that do not establish a common cause. Compare what network devices generate with what receiving systems retain, then test how device time, administrative access, network trust, and decoy activity affect a later investigation.
Trace an alert to the packet, protocol record, flow data, or host event that produced it. Reconstruct suspicious activity, test detection logic against captured traffic, and determine whether the combined records justify escalation or a change in incident scope.
Find the systems and services that respond now, compare them with the inventory, and validate which exposures can extend access. Test how credentials and command-and-control channels cross expected boundaries, then verify a controlled configuration change against each managed system.
Incident response begins before every record is available and often before scope is established. Recover host artifacts, test the claims in a handoff, reconstruct ransomware activity, and decide which systems or accounts require collection, containment, or recovery.
Connect a suspicious file with the incident around it. Use file properties, host changes, network requests, and program logic to refine detection and scope, identify failed controls, and make containment and recovery decisions that the available records support across the enterprise.
The final Applied Cyber Defense capstone draws on all five technical sections through independent challenges. Working individually or with a team, you must recover exact answers from the available artifacts and decide which challenge warrants the next block of time.
This role uses cybersecurity tools to protect information, systems and networks from cyber threats. Find the SANS courses that map to the Protection SCyWF Work Role.
Explore learning pathAssesses systems and networks to ensure compliance with policies and identify vulnerabilities in support of secure and resilient operations.
Explore learning pathResponsible for planning, implementing, and operating network services and systems, including hardware and virtual environments.
Explore learning pathImplements and maintains network services, including hardware and virtual systems, ensuring operational support for infrastructure platforms.
Explore learning pathThis role uses monitoring and analysis tools to identify and analyze events and to detect incidents. Find the SANS courses that map to the Defense SCyWF Work Role.
Explore learning pathResponsible for developing and conducting cybersecurity awareness, training, or education.
Explore learning pathImplementation and oversight of security measures to protect organisational data, systems, and operations. Responsibilities include risk assessments, policy enforcement, and compliance with regulatory standards.
Explore learning pathMonitoring and response to security incidents in live environments. Analysts detect anomalies, triage alerts, and coordinate defensive actions to maintain organisational security posture.
Explore learning pathEnroll your team as a group or arrange a private session for your organization. We’ll help you choose the format that fits your goals.
The disciplines/skills taught in SEC501 were exactly what my career and team needed to mature our SOC. Bryce Galbraith was an amazing, extremely knowledgeable instructor who kept all of the material interesting and fun.
I would recommend SEC501 as a strong foundation to any security practitioner role. It is broad but assumes a reasonable level of technical proficiency that is refreshing.
SEC501 offers a great explanation of Net Defense best practices that often get overlooked.
A must for cyber security professionals!

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources