SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Apply your credits to renew your certifications
Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months
Course content applicable to people with limited or no cyber security experience
Apply what you learn with hands-on exercises and labs
Understand cybersecurity, ask sharper questions, and work confidently with technical teams. No technical background required.
I appreciated how SEC301 broke down complex topics. The instructor made it accessible even for someone without a technical background.
SEC301: Cybersecurity Fluency for Business Professionals is built for people who need to understand cybersecurity as part of their work, without becoming technical security specialists. This includes managers and professionals in human resources, legal, finance, operations, audit, compliance, sales, marketing, and customer-facing roles.
This course also prepares you to earn the GISF certification (GIAC Information Security Fundamentals), a globally respected credential that validates your understanding of essential cybersecurity concepts.
You don’t have to work in cybersecurity for cybersecurity to affect your work. Reviewing a vendor, supporting a customer, managing employees, or approving a project can involve security considerations. SEC301 helps you understand those considerations and participate confidently in the decisions that follow.
This course goes beyond security awareness. You’ll explore how attacks happen, how security technologies work, and why particular defenses matter. Technical concepts are explained in plain language and connected to organizational responsibilities, business priorities, and real-world consequences.
The goal is not to train you to administer security tools or investigate incidents independently. It is to help you understand what technical teams are explaining, ask useful questions, and contribute the knowledge and judgment your role brings.
Across five focused days, you’ll explore the modern cybersecurity landscape through stories, visuals, and hands-on activities that make abstract ideas tangible:
No prior technical experience is required. Guided labs and realistic scenarios make the concepts tangible, helping you understand how cybersecurity works, not just memorize its vocabulary.
You’ll leave better equipped to explain risks, understand security recommendations, and connect technical issues to the decisions and responsibilities of your own role.
I built SEC301 for people who need cybersecurity knowledge to do their jobs, not become security specialists. Maybe you manage a team, review contracts, support customers, or coordinate projects. You deserve to understand the security conversations that affect your work.
We cover real technical concepts through clear explanations, stories, and guided activities. The goal is to help you ask better questions, understand the answers, and bring your own expertise to the discussion.
The moment when someone says, “Now I understand how this connects to my job.” That’s why this course exists.
SEC301 is built around the exam objectives that make up the GISF certification:
Across all five sections, 14 hands-on labs give you the chance to apply each skill in a live virtualized cloud environment before you sit the exam.


Rich Greene, SANS Senior Solutions Engineer and SEC301 author, brings 20+ years of cyber operations and teaching experience to the classroom. With 15+ GIAC certifications and a passion for mentorship, he equips defenders with real-world confidence and skill.
Read more about Rich GreeneExplore the course syllabus below to view the full range of topics covered in SEC301: Cybersecurity Fluency for Business Professionals.
Begin with the essentials that make cybersecurity practical. Learn how threats become risk, why availability can be life-critical, and how trust grows from clear process and communication. Each lab brings concepts to life so you can explain, choose, and apply controls with confidence.
Overview
Every strong security program begins with understanding why security matters and how risk actually forms. Day 1 anchors the course with plain-language fundamentals the human, legal, and technical building blocks that make cybersecurity both possible and practical. Students move from abstract ideas (“hackers and firewalls”) to clear reasoning: how threats exploit vulnerabilities, why availability can be as life-critical as confidentiality, and how frameworks turn scattered controls into repeatable habits of trust.
By the end of this section, learners can explain the CIA Triad, apply the Risk = Threat × Vulnerability × Impact model to real situations, and recognize that cyber resilience depends as much on communication and accountability as on technology. The day closes by connecting these ideas to global compliance frameworks GDPR, HIPAA, SOX and showing that security is really about people, process, and proof.
Cybersecurity is not a collection of tools it’s a way of thinking. Section 1 transforms beginners into informed practitioners who can describe why controls exist, how risk evolves, and what accountability looks like when things go wrong. From the first lab forward, learners begin building the confidence to explain, choose, and apply controls that protect both people and mission because trust, once earned, is the true currency of security.
Full Lab Details
Build the foundations of digital trust with the core ideas behind encryption, identity, and access. Learn how math protects data, how certificates prove who’s who, and how authentication and authorization shape accountability. Each lab turns complex concepts into clear steps you can use with confidence.
Overview
Section 2 moves from why security matters to how digital trust is built and verified. Students explore how cryptography underpins nearly every act of trust in the modern enterprise—from a secure login to a cloud transaction or a digital signature. The day follows the chain of digital trust step by step: first encrypting data for confidentiality and integrity, then proving identity through certificates, and finally enforcing accountability through authentication, authorization, and logging.
Learners discover that cryptography isn’t magic—it’s math that earns trust—and that identity systems don’t just control access; they define responsibility. By the end of the day, students can explain in plain language how encryption, certificates, and identity management combine to make “Zero Trust” possible.
By the end of Section 2, students can trace how every secure interaction—from encryption to login to audit log—relies on cryptographic proof and disciplined identity management. They learn that the real challenge isn’t technology, but earning and maintaining trust: protecting keys, verifying identity, enforcing least privilege, and proving integrity at every step. Day 2 transforms abstract math into the language of credibility—showing that in cybersecurity, trust is not a feeling; it’s a function.
Full Lab Details
Explore how data travels and what it reveals along the way. You’ll break down layers, packets, routing, and DNS, then see how firewalls and segmentation shape trust. Each lab turns network theory into clear understanding so you can follow data in motion and make smarter defense decisions grounded in visibility.
Overview
Section 3 shifts the learner’s focus from individual systems to the pathways that connect them. Every modern attack, investigation, and defense activity relies on understanding how data moves across networks—and how visibility, segmentation, and trust change along the way.
Students start by demystifying network fundamentals: layers, packets, ports, and protocols. They trace what really happens when you load a web page or send an email, seeing how every hop leaves behind clues defenders can use. From there, they explore addressing and routing, DNS resolution, and the difference between metadata and content. The day then expands into how traffic is filtered, logged, and segmented through firewalls, proxies, and DMZs—and how design decisions at these layers shape both performance and security.
The capstone concept, Zero Trust networking, ties it all together: the idea that in modern environments, trust is not a perimeter but a process—one continually verified for every user, device, and packet in motion. By day’s end, students can visualize the full journey of data, explain how it’s protected (or exposed) at each stage, and apply the language of networks to real-world defense decisions.
Data in motion is where visibility, trust, and vulnerability converge. Section 3 transforms abstract network diagrams into a living system of connections, dependencies, and controls. Students walk away able to see the network as defenders do—understanding how information flows, how attacks exploit those flows, and how layered defenses keep operations resilient.
Full Lab Details
Step into the attacker’s mindset to understand how threats evolve. Section 4 explores phishing, credential abuse, wireless compromise, malware behavior, and AI-driven campaigns. Labs help you trace attacker choices, map tactics to ATT&CK and D3FEND, and build defenses that break the chain of compromise.
Overview
Day 4 moves from defense to offense—not to make students hackers, but to help them think like one. By understanding how attackers choose their targets, exploit trust, and chain together small weaknesses into major compromises, learners develop the mindset needed to anticipate, detect, and disrupt modern attacks.
The day begins with the human side of exploitation—phishing, social engineering, and credential abuse—before expanding into the technical realities of wireless compromise, malware behavior, and living-off-the-land attacks. Students learn how adversaries bypass firewalls, manipulate trust, and weaponize legitimate tools like PowerShell or cloud services.
From there, the course explores how AI is reshaping both sides of the battlefield: automating phishing, voice cloning, malware generation, and disinformation campaigns. Learners conclude the day by mapping attacker behavior using MITRE ATT&CK and D3FEND, translating complex intrusions into a structured model that connects offensive tactics to defensive countermeasures.
By the end of Section 4, students can recognize not just what an attacker did, but why—and use that understanding to design defenses that stay one step ahead.
Full Lab Details
Section 5 ties the course together with the tools, teams, and web risks that shape real security. You’ll break down common web flaws, see how SOC technologies work in practice, and explore cloud, IoT, and AI-driven defense. Each lab shows how people and systems combine to protect data, safety, and trust.
Overview
Day 5 brings the course full circle—from individual awareness to organizational resilience. Students move from understanding how attacks happen to mastering how modern defenses work together. They’ll see how technologies like SIEM, EDR, IDS/IPS, IAM, and SOAR form the nervous system of a security program—collecting, correlating, and responding to threats across networks, endpoints, and cloud environments.
The day opens with the web itself, where most attacks still begin. Students dissect web application vulnerabilities like XSS, SQL injection, and clickjacking, learning how insecure input, weak validation, and missing controls turn trusted sites into attack platforms. They explore HTTPS, security headers, and OWASP Top 10 risks—and see how even secure connections don’t guarantee secure applications.
From there, the focus shifts to the tools and teams that power cybersecurity in practice. Learners step inside the SOC to experience how alerts become action, how automation supports humans (not replaces them), and how roles from GRC to Red and Purple Teams combine for continuous improvement. They then move beyond the SOC—into the cloud, IoT, and OT—to understand shared responsibility, configuration risk, and how digital and physical systems are increasingly connected.
Finally, students look ahead to the future of defense, exploring how AI is reshaping security operations, decision-making, and ethics. They learn to separate hype from value, balancing automation with oversight, and discovering why the most resilient organizations are human-led but machine-accelerated.
By the end of this section, learners can explain, evaluate, and communicate how all these technologies, teams, and trends fit into a single goal: protecting data, people, and trust—wherever they live.
Full Lab Details
Important! Bring your own system configured according to these instructions.
Students must have a properly configured system to fully take part in this course. If you do not carefully read and follow these instructions, you will not be able to do the hands-on exercises in your course. Therefore, please arrive with a system meeting all the specified requirements.
Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.
Mandatory System Hardware Requirements
If there are questions about the computer specifications, please contact customer service.
Designed primarily for non-technical professionals whose work intersects with cybersecurity:
The GIAC Information Security Fundamentals (GISF) certification validates a practitioner's knowledge of security's foundation, computer functions and networking, introductory cryptography, and cybersecurity technologies. GISF certification holders will be able to demonstrate key concepts of information security including understanding the threats and risks to information and information resources and identifying best practices to protect them.
No prior cybersecurity, coding, or IT experience is required. Basic computer and web browser skills are sufficient; technical concepts and labs are guided.
SEC301 is a standalone course, built for business professionals who need cybersecurity fluency for their current role, not a step in a technical certification track.
If your goal is to move into a hands-on, technical cybersecurity role instead, these courses are built for that path:
Cybersecurity is the practice of protecting computer systems, networks, and data from digital attacks, unauthorized access, damage, or theft. It involves a combination of technologies, processes, and measures designed to defend against threats like hacking, malware, and phishing.
Cybersecurity is crucial because nearly every business decision now carries some security implication, approving a vendor, signing a contract, launching a new platform, or hiring a new employee. A successful cyberattack can lead to significant financial losses, legal exposure, and lasting damage to an organization's reputation. You don't need to work in security to be affected by these risks or to help manage them. Understanding how threats happen and how organizations defend against them helps you make more informed decisions, ask sharper questions, and work more effectively with the technical teams responsible for security day to day.
SEC301 helps you bring cybersecurity understanding to the work you already do. You’ll be better equipped to ask informed questions, explain business impacts, understand security recommendations, and collaborate with technical teams.
Whether you manage people, support customers, review contracts, oversee compliance, or coordinate projects, the goal is greater effectiveness in your role. The course builds cybersecurity fluency; it does not replace role-specific technical training.
Ensures systems and software security from development to maintenance by analyzing and improving security across all lifecycle phases.
Explore learning pathOversees full lifecycle of information systems from design through evaluation, ensuring alignment with functional and operational goals.
Explore learning pathResponsible for operating an information system at an acceptable level of risk to organizational operations, organizational assets, individuals, other organizations, and the nation.
Explore learning pathResponsible for managing the Communications Security (COMSEC) resources of an organization.
Explore learning pathDeploys, configures, maintains infrastructure software and hardware to support secure and effective IT operations across organizational systems.
Explore learning pathManages support resources and readiness for system components, ensuring operational capability through lifecycle logistics and maintenance.
Explore learning pathDesigns secure enterprise systems considering environmental constraints and translates them into enforceable security processes and protocols.
Explore learning pathResponsible for developing and conducting cybersecurity awareness, training, or education.
Explore learning pathEnroll your team as a group or arrange a private session for your organization. We’ll help you choose the format that fits your goals.
SEC301 was my first SANS course, and I was not disappointed! Keith was exceptional in presenting this information in a clear and concise manner. He took the time to really explain concepts and challenged us to think things through. I learned a great deal and look forward to future SANS events.
SEC301 is the only course of its kind. Every IT professional knows that your knowledge from networking to security is contiguous, and this is the only course I've seen that actually teaches both equally.
I never knew anything about cryptography and its complexities. This course is opening my eyes to how important it is!
As usual, SANS courses give incredible insight into the reality of the threats that are present in the cyber world. With SEC301, I have a better understanding of each threat, and the means to mitigate those threats.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources