SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Apply your credits to renew your certifications
Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months
Course material is geared for cyber security professionals with hands-on experience
Apply what you learn with hands-on exercises and labs
Develop the leadership skills and practical frameworks to command significant cyber incidents with confidence, from the first hour of chaos to the final hand-back.
Great insights, examples and relevant tools. I applied the 3rd party incident tool within minutes to an ongoing 3rd party incident. So I can't dream of a more relevant and useful course than this.
When a major cyber incident hits, technical teams need more than good tools. They need someone who can take charge, manage the information, direct the effort, and keep the organisation moving. Cyber Incident Management puts you in that role. This course focuses on the critical non-technical challenges facing leaders under pressure: building and running a response team, distilling technical findings into executive briefings, managing communications across legal, HR, comms and external parties, and driving decisions when the facts are incomplete and the clock is running, while preparing you for the GCIL certification exam.
Every lab is built on a single, continuous real-world scenario, Submarine Studios, a software and games company under attack by external threat actors. That scenario runs across all five sections, so each skill you develop connects directly to the one before it. By the end of the course you will have worked through a full incident lifecycle, from initial triage to post-incident review, using the tools and frameworks you take home.
You cannot predict when a major incident will arrive. You can decide in advance how ready you will be when it does. In the aftermath, when the IR team is working through logs, images, and malware at pace, the incident management function is what keeps everything else from unravelling. Communications need to go out. Executives need briefing. Legal and regulatory timelines start running the moment the incident is declared. Third parties need managing. And the team itself needs direction, welfare oversight, and a battle rhythm it can sustain.
This course equips you to lead that function, whether you are stepping into it as a newly appointed incident commander, a senior manager pulled into a response, a technical specialist given wider responsibilities, or a legal, HR, or communications professional who needs to understand what will be expected of you when an incident escalates.
Cyber Incident Management sits above Digital Forensics and Incident Response (DFIR) and takes over when incidents grow beyond what a SOC or IR team can manage on their own. These are the high-impact events that demand coordination across the business with external advisors, regulators, customers, and the media, while the technical investigation continues in parallel. LDR553 is built around exactly those scenarios, with GenAI woven throughout as a practical support tool rather than a theoretical add-on.
The course is built around the Cyber Incident Management Toolkit (CIMTK): a set of frameworks, trackers, and simple reference cards that work during an incident, in the room, not just on a shelf. You will use CIMTK throughout the labs, and you take every component with you at the end of the week. The toolkit includes the AIM-RADAR workbook and many of the CIMTK framework card set covering RAPID, 3-Whats, CURTAIN, CORDS, and TRACE.
"I have spent over 16 years in incident response and incident management, and the gap I kept seeing was not technical, it was the person standing at the front of the room trying to hold it all together without a framework, without sleep, and without a clear picture of what mattered next. This course exists to fix that. It is built on real incidents, run against a real scenario, and designed to give you something you can actually use the week you get back."
– Steve Armstrong-Godwin
LDR553 is built around the exam objectives that make up the GCIL certification:
Across all five sections, 27 hands-on labs and a capstone exercise built on the continuous Submarine Studios scenario give you the chance to apply each skill in a live incident scenario before you sit the exam.


Steve Armstrong-Godwin brings 30+ years in incident management and response across defence, consulting, multinational business, financial services, gaming, and national military cyber operations.
Read more about Steve Armstrong-GodwinExplore the course syllabus below to view the full range of topics covered in LDR553: Cyber Incident Management.
Section 1 builds your foundation as an Incident Commander. You will establish a common language, define objectives, stand up your team, and start tracking the incident using the CIMTK toolkit, including The Grid, AIM-RADAR, and your first purpose-built GenAI tool.
Overview
In Section 1 we focus on understanding the incident, gathering information, and establishing the language the whole team will use. We review common terms, abbreviations, and incident types so that when we talk to different functions (IR, legal, HR, comms) we mean the same things. From there we categorise the incident using the RAPID framework and define what the Incident Management group is trying to achieve, so that focus is set early and maintained as complexity grows.
The centerpiece of this phase is the CIMTK, specifically The Grid: a structured set of questions and initial tasks that gets the team moving in the right direction from the first hour. Identifying and allocating tasks early allows concurrent activity across support teams: IR, IT, Legal, HR, and the IM function itself. We then use Commander's Intent to brief those teams clearly, communicating short and medium-term goals without creating information dependency.
We move into platform and tooling considerations. Where the team operates from matters, especially when attackers may have visibility of your response infrastructure. Team composition follows: who you need, where they sit, how big the group should be, and how to make it work when it is a mix of internal staff, retained advisors, and external specialists.
We close Section 1 by adding GenAI to the bench. Throughout the course, GenAI is used as a practical support tool: drafting briefs, parsing incoming information, stress-testing decisions. In this section students build their first purpose-built GPT for use in the labs ahead.
Exercises
Topics
Section 2 is built around communications with executives, the public, and the wider organization. You will learn to brief clearly under pressure using the 3-Whats framework, draft public statements, coordinate remediation across systems and data, and conduct root cause analysis. The section closes with incident reporting and planning for closure.
Overview
Section 2 opens with executive briefings. Using the 3-Whats structure (What Happened, What Is Happening Now, What Is Happening Next) we give the IC a repeatable format for briefing the board and leadership team at any stage of the incident, with any level of completeness. The format works when facts are still emerging and when the exec audience is impatient.
We move into public communications, both pre-emptive and reactive. Students work through when and how to get ahead of a story versus when to respond, what goes into a public statement, and how to manage the tone and legal exposure of external communications. Lab 2.2 works through both approaches against the Submarine Studios scenario.
Briefing the wider organization presents different challenges: the audience is larger, the information needs to be controlled, and the message must hold up across different functions simultaneously. Lab 2.3 covers how to construct and deliver that briefing without inadvertently spreading panic or leaking details to the wrong audience.
The remediation section covers categorizing the damage, mapping the work, prioritizing actions, and ensuring nothing is missed. Attention goes to secrets within stolen data and compromised systems (credentials, API keys, certificates) and the downstream implications these carry for future operations.
We close with root cause analysis and incident reporting. A strong IR report is necessary but not sufficient for IM purposes; the IC needs to understand what additional material is required, how to get input from teams under pressure, and how to manage access and control over sensitive documentation. Lab 2.4 examines examples of poor root cause analysis meetings. As an outsider, the student spots the dysfunction more easily than those sitting in it and is better placed to avoid the same traps when running their own RCA. Lab 2.5 covers remediation prioritization across systems and data, to give the student a glimpse of how a remediation rebuild plan looks and demonstrates how you can build one when you lack project management support.
GenAI in Section 2 focuses on producing briefs, reformatting unstructured text, and cross-checking communications before release, pressure-testing your own output before it goes to the exec. As always these are supportive functions that the AI is performing and not replacing any staff member or IC task.
Exercises
Topics
Section 3 develops the capabilities that support major incidents: training IR and IM teams, integrating Cyber Threat Intelligence into response operations, and conducting a deep investigation into a key supplier that is compromised. The section closes with bug bounty and vulnerability reporting programs.
Overview
Section 3 opens with team development. We examine what good training looks like for IR and IM functions: not frequency compliance, but targeted development against specific capability gaps. Students work through exercise selection (Lab 3.1) and plan a hot seat exercise (Lab 3.2), with guidance on how to build exercises that challenge teams without overwhelming them. This is one of the most important sections of the course; no other zero-cost change will improve your organization's IM capabilities more than running good exercises.
Cyber Threat Intelligence is talked up far more than it is used well during real incidents. In this section we address why that is, and how to fix it. We cover the intelligence cycle from a practitioner perspective: what CTI can produce for an IM team, how to generate Priority Intelligence Requirements, and how to maintain CTI access during a fast-moving incident. Lab 3.3 has the student develop a request for CTI Support for threat actor profiles relevant to the Submarine Studios scenario and then leveraging OpenCTI they see how it looks in a live platform as they compare it with a written report from an Intel vendor.
The third-party compromise module runs across two long labs and is the most substantial element of the section. Starting with an optional pre-class lab reviewing real third-party incident reports, students then work through the full lifecycle of a supply chain incident using the CURTAIN framework. It runs as seven parallel swim lanes rather than a sequential checklist, coordinated by the IC and worked while the supplier is still telling you almost nothing. Lab 3.4 covers reviewing a third-party notification and building a Supplier Assurance Question Set (SAQS), the structured set of questions you put to a vendor when information is scarce. Lab 3.5 turns to the communications that run alongside the investigation: the vendor call, the internal team brief, and the executive update.
The section closes with bug bounty and vulnerability reporting programs: understanding how researchers and third parties approach you, what their motivations are, and how to manage those relationships without losing control of the narrative or the timeline. The incident management function is involved from the first report. What looks like a routine vulnerability disclosure can, once investigated, reveal a significant compromise that has been running undetected for months, and judging when a disclosure becomes an incident is an IM decision rather than a technical one.
Exercises
Topics
Section 4 examines the attack types an Incident Commander is most likely to face: credential theft and identity compromise, Business Email Compromise, cloud-based attacks, and the emerging challenge of agentic AI. Credential eviction gets particular attention, because doing it in the wrong order lets the attacker straight back in.
Overview
Section 4 opens with an optional pre-class lab reviewing high-impact credential compromise cases, before moving into timeline visualization. A well-scoped timeline is a powerful communication tool; a poorly scoped one creates confusion. We work through how to build timelines for different audiences at different stages of an incident.
Credential theft and identity compromise take centre stage, and this is where the TRACE framework does its primary work. The core teaching point is one that catches organizations repeatedly: resetting a password does not evict an attacker who holds a valid refresh token. The 7Rs is a sequence, not a checklist: Restrict (lock the account; this stops Entra issuing new tokens), Revoke active sessions, Revoke refresh tokens, Reset credentials, Review MFA methods and trusted devices, Re-enroll MFA, Re-enable the account. Run them out of order and the attacker stays in. Lab 4.2 builds the full credential exposure picture for the Submarine Studios scenario and works through eviction planning using the TRACE tabs in AIM-RADAR.
Business Email Compromise is examined in depth: its stages, the six-plus attack types, where liability falls, how to support legal arguments, and what the IC needs to direct IR forensics effectively. Lab 4.3 puts students inside a BEC investigation where the operative challenge is doubt: doubt what you see and are told.
The section introduces agentic AI as an incident management challenge. As AI agents become more common in enterprise environments, incident managers need a framework for what happens when an agent behaves unexpectedly or when a vendor's agent is in scope during a third-party incident. The CORDS framework (Confirm, Own, Restrain, Document, Sanction) provides that structure, with graduated restraint options (from pausing the queue through to full termination) and an emphasis on evidence preservation before any reset or redeployment.
Lab 4.4 covers cloud management console attacks as a homework exercise. Lab 4.5 returns to the Submarine Studios scenario for a public statement update, applying the communications skills from Section 2 with the fuller picture now available.
Exercises
Topics
Section 5 examines AI risk in incident management before turning to ransomware, which remains the most significant operational threat facing most organizations. The section closes with a comprehensive capstone exercise available to all delivery formats, including OnDemand.
Overview
The industry uses the term artificial intelligence loosely. Section 5 does not: we break it into its actual categories before narrowing to LLMs and the GenAI tools used throughout the course. We examine hallucination risk, the governance implications of deploying AI in a response context, and where AI adds genuine value versus where it introduces risk that outweighs the benefit. Lab 5.1 works through an agent incident (building on the CORDS framework introduced in Section 4) where students investigate an AI agent behaving outside its intended scope.
Lab 5.2 covers hostile communications: managing dialogue with threat actors, understanding what the attacker is trying to achieve, and keeping executives informed of options and their consequences. This builds directly on the attacker engagement content in Section 2.
Ransomware occupies the second half of the section. We cover its evolution, the stages of a compromise from initial access to encryption, and where detection opportunities were missed. The IC's role is clear: direct IR, maintain context, press executives for decisions, and keep the organization's options open for as long as possible. We work through no-regret options, the implications of going dark, negotiation planning, and the evidence and documentation requirements that determine whether the post-incident review is productive or a liability exercise.
Students close with the capstone: a full multi-stage exercise running across live and OnDemand formats, drawing on every section of the course.
Exercises
Topics
Important! Bring your own system configured according to these instructions!
A laptop or mobile device with a current web browser is required to access the cloud-hosted course files and CIMTK materials. The CIMTK toolkit is provided on Google Drive, Dropbox or Proton; students must be able to connect to one these services. Corporate machines with VPN, intercepting proxies, or egress filtering must be configured to permit access, or students should bring a personal device.
Microsoft Office and LibreOffice are both supported. Files are maintained in Google first for multi-user collaboration capability; downloads are available in Office-compatible formats.
Students are issued a SANS ChatGPT account for the duration of the course. Other GenAI tools are welcome, but primary support is provided for the OpenAI-based toolset. Some labs use image generation and computer vision features; students relying on non-OpenAI tools should request a SANS ChatGPT account for those specific exercises.
If you have additional questions about the laptop specifications, please contact customer service.
Security Managers
Security Professionals
Managers
Legal, HR, and Communications Staff
The GIAC Cyber Incident Leader (GCIL) certification validates a practitioner’s ability to manage cyber incidents and lead a diverse incident management (IM) team to restore normal operations. GCIL holders demonstrate expertise in preparing for, assessing, handling, tracking, and documenting incidents; developing IM teams; managing vulnerabilities, threats, and attacks; facilitating communication; and improving IM processes.
This course covers the core areas of cyber incident management and assumes a basic understanding of technology, networks, and security concepts. It does not require hands-on technical experience. The focus throughout is management and leadership, not forensics or malware analysis. For those new to the field with no background knowledge, the recommended starting point is SEC401: Security Essentials.
LDR553: Cyber Incident Management is part of the SANS Cybersecurity Leadership curriculum and the Cyber Risk Officer Triad, alongside LDR512: Security Leadership Essentials for Managers and LDR519: Cybersecurity Risk Management and Compliance. Together, these three courses provide a holistic blueprint for modern cyber risk officers—whether stepping into leadership from technical ranks or leveling up within executive roles. The triad develops leaders who not only understand how to build, govern, and respond, but who can unify teams under pressure and steer organizations through complexity with clarity and resilience.
Cyber Incident Management coordinates the response to significant security breaches that exceed the capacity of regular SOC and IR teams. It sits above the technical investigation, handling business impact, stakeholder communications, regulatory obligations, and strategic decisions. An Incident Manager leads cross-functional teams, keeps executives informed, and drives the organization toward recovery while IR handles the technical work. As incidents grow in scale and sophistication, the demand for capable people in this role continues to grow faster than the supply.
No other course covers incident management at this depth, supported by a single continuous real-world scenario where every lab connects to the one before it. LDR553 develops the leadership, communication, and decision-making skills that are genuinely scarce in the market, and that organizations are increasingly willing to pay for. The GCIL certification provides a recognized credential; the CIMTK toolkit provides something you can use from the day you get back. Students regularly apply specific tools and frameworks within days of completing the course.
Lead cybersecurity risk strategy at the highest level.
Explore learning pathCo-ordination of detection, response, and recovery activities across teams and systems. Emphasis is placed on minimising impact, restoring services, and maintaining clear communication during disruptions.
Explore learning pathMonitor the organisation’s cybersecurity state, handle incidents during cyber-attacks and assure the continued operations of ICT systems.
Explore learning pathResponsible for managing the cybersecurity of a program, organization, system, or enclave.
Explore learning pathDaily focus is on the oversight of technical teams while aligning them to overall business strategies. Includes titles such as Technical Director, Information Security Officer, and CISO.
Explore learning pathDevelopment of frameworks that align technology use with business objectives and regulatory requirements. Focus areas include policy design, risk controls, and enterprise accountability structures.
Explore learning pathResponsible for developing and conducting cybersecurity awareness, training, or education.
Explore learning pathSecurity Operations Center (SOC) managers bridge the gap between business processes and the highly technical work that goes on in the SOC. They direct SOC operations and are responsible for hiring and training, creating and executing cybersecurity strategy, and leading the company’s response to major security threats.
Explore learning pathEnroll your team as a group or arrange a private session for your organization. We’ll help you choose the format that fits your goals.
It was awesome to have the opportunity to apply existing and newly learned skills to the labs. It was obvious that a significant amount of time had been invested in these.
The hands-on experiences and assignments have been exceptional and have significantly contributed to my learning experience.
This is a great course for incident managers or anyone that could be put into the firing line of dealing with incidents.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources