SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Apply your credits to renew your certifications
Train at your own pace from wherever you are
Course material is for individuals with an understanding of IT or cyber security concepts
Improve persuasive communication techniques to breach readers' defenses, ensuring security reports influence decisions even when audiences resist engaging with technical content.
Outstanding course. Provides a writing framework/rubric to evaluate & guide future writing.
SEC402 teaches cybersecurity professionals to write so their reports, briefings, and emails get read and acted on. The technical insight is often there, but the writing that carries it loses the reader before the recommendation lands. This course teaches a reader-centered approach built around the five “golden” elements: structure, look, words, tone, and information. Students spot and fix problems in writing samples, including incident reports, threat reports, and assessment findings. They also learn how to use AI to draft, critique, and improve their writing, without ceding judgment to it.
Want to write better? Learn to hack the reader! Discover how to find an opening, break down your readers' defenses, and capture their attention to deliver your message—even if they are too busy or indifferent to others' writing. This unique course, built exclusively for cybersecurity professionals, will strengthen your writing skills and boost your security career.
You will:
The course builds upon the author's two decades of cybersecurity experience. You'll learn from examples relevant to security professionals, whether they're experts or beginners, managers or individual team members.
It also focuses on common writing problems you will learn to avoid, instead of presenting tedious grammar rules or theoretical explanations. You will advance your writing by reviewing and improving real-world cybersecurity samples.
You will master the writing secrets that will make you stand out in the eyes of your peers, colleagues, managers, and clients, learn to communicate your insights, requests, and recommendations persuasively and professionally, and make your cybersecurity writing remarkable.
"How can you stand out from other cybersecurity professionals with similar technical skills? How can you get your managers, clients, and colleagues to notice your contribution, accept your advice, and appreciate your input? Write better!
Here's an uncommon opportunity to improve your writing skills without sitting through tedious lectures or writing irrelevant essays. You'll make your writing remarkable by learning how to avoid common mistakes, working on real-world exercises to spot and correct cybersecurity writing problems. You'll write clearly and effectively right away with the help of practical checklists.
This course captures my experience of writing in cybersecurity for over two decades and incorporates insights from other members of the community. It's a course I wish I could have attended when I needed to improve my own writing skills. It's a course I know will help you propel your own cybersecurity career."
- Lenny Zeltser


Lenny Zeltser is a leader in developing resilient security programs. His invaluable tools, like REMnux, a widely used Linux distribution for malware analysis, have become industry standards in combating malicious software.
Read more about Lenny ZeltserExplore the course syllabus below to view the full range of topics covered in SEC402: Cybersecurity Writing: Hack the Reader.
Section 1 introduces the reader-centered approach and the first three elements that determine whether your writing gets read. Students learn to organize cybersecurity reports and messages, so readers find the takeaway, make it easy to scan, and choose words that work for both technical and business audiences. Hands-on exercises use weak and strong examples.
Overview
Day 1 - Section 1: How to Strengthen Your Writing Skills-A Reader-Centered Approach
CPE/CMU Credits: 0.5
You'll learn how a reader-centered approach to writing allows you to prepare cybersecurity materials that connect with your audience. You'll discover how the five "golden elements" of writing work together to assist you with these tasks. These elements, which we discuss throughout the course, are:
You'll understand how to use the hands-on exercises in this course to avoid problems common to the security reports, emails, and other content you regularly create.
Day 1 - Section 2: The Right Structure
CPE/CMU Credits: 2.5
We all have way too much to read. You'll learn how to structure your writing so readers don't want to put it down. You'll discover how to:
You'll understand how to use the right structure by spotting and fixing structural issues with many cybersecurity examples.
Day 1 - Section 3: The Right Look
CPE/CMU Credits: 3
You have just seconds to grab your reader. You'll learn how to give your writing the right look to hook your readers at a first glance. You'll be able to:
You'll master the right look by examining security writing samples that have an amazingly misguided look. (Expect much fun.)
Section 2 turns to tone and information, which readers weigh before they trust you and act on what you wrote. Students learn to set a tone that stays professional, responsive, and constructive, even in disagreements and negative findings. They also learn what each report type, including incident, assessment, and threat reports, needs to deliver to readers.
Overview
Day 2 - Section 4: The Right Words
CPE/CMU Credits: 2.5
The word is mightier than the sword. You'll learn how to pick the right words to inform and persuade your readers. You'll find out how to make sure your words are:
The key to using the right words is deliberate practice. You'll have many opportunities to improve poorly worded cybersecurity text.
Day 2 - Section 5: The Right Tone
CPE/CMU Credits: 2
Tone is the key to creating a bond with your reader. You'll learn how to make your tone:
Real-world examples will help you learn to spot tone problems, so you can turn them into writing that says just what your reader will understand and appreciate.
Day 2 - Section 6: The Right Information - Cybersecurity Incident Reports
CPE/CMU Credits: 0.5
What do readers of your cybersecurity incident report want to know? You'll learn to include the right information in such writing, so you can:
The best way to learn how to write a good incident report is to look for problems in bad ones. You'll have many opportunities to do this.
Day 2 - Section 7: The Right Information - Pen Testing and Other Security Assessment Reports
CPE/CMU Credits: 0.5
Learn how to craft a security assessment report so the readers truly benefit from your insights. Master the skill of including just the right information to:
You'll review many problematic penetration testing and other security assessment reports, so you'll understand how to avoid their pitfalls.
Day 2 - Section 8: The Right Information - Malware and Other Threat Reports
CPE/CMU Credits: 0.5
Writing about cybersecurity threats, such as phishing messages, malware infections, and attack groups, can be challenging because of the multiple audiences that might read the reports. Learn how to include the right information in such writing, so your readers:
You'll learn to include the right information in threat reports with the help of hands-on exercises, during which you'll spot and fix information-related weaknesses.
A laptop or desktop with a current web browser, since the course runs through the SANS OnDemand portal. The exercises don’t require specialized software, just your usual reading and writing tools.
Cybersecurity professionals who write reports, briefings, emails, or other content as part of their job. The course works for managers and individual contributors, consultants and in-house staff, beginners and experts. If your job depends in part on whether your writing gets read and acted on, this course is for you.
No specific technical prerequisites. The course works for cybersecurity professionals at any level, from analysts and engineers to managers and executives. Some familiarity with the kinds of writing security teams produce, like incident reports, advisories, and emails, helps but isn’t required.
SEC402 covers foundational materials that apply across SANS curricula. Cybersecurity professionals often take SEC402 alongside their technical and leadership training.
Cybersecurity writing turns security knowledge into reports, briefings, and emails that the right people read and act on. It matters because security recommendations only protect the organization when someone with authority decides to follow them.
Cybersecurity professionals who write well influence more decisions and earn more credit for their analysis. Over time, strong writers get invited into the decisions other professionals only hear about secondhand.
Responsible for providing cybersecurity legal advice and recommendations, including monitoring related legislation and regulations.
Explore learning pathResponsible for operating an information system at an acceptable level of risk to organizational operations, organizational assets, individuals, other organizations, and the nation.
Explore learning pathDaily focus is on the leadership of technical teams. Includes titles such as Manager, Information Security Specialist, and Program/Project Leader.
Explore learning pathResponsible for managing the Communications Security (COMSEC) resources of an organization.
Explore learning pathResponsible for developing and conducting cybersecurity awareness, training, or education.
Explore learning pathResponsible for managing and administering processes and tools to identify, document, and access an organization’s intellectual capital.
Explore learning pathResponsible for conducting evaluations of technology programs or their individual components to determine compliance with published standards.
Explore learning pathThis dynamic and fast-paced role involves identifying, mitigating, and eradicating attackers while their operations are still unfolding.
Explore learning pathEnroll your team as a group or arrange a private session for your organization. We’ll help you choose the format that fits your goals.
Outstanding course. Provides a writing framework/rubric to evaluate and guide future writing.
I attended a training at my company right before coming here related to improving written communication. I notice similarities here but the cybersecurity focus here is invaluable!
Cybersecurity writing skills are critical for professional development.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources