SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.
Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.
Mandatory System Hardware Requirements
Mandatory Host Configuration And Software Requirements
Download and install the latest version of VMware Workstation Pro for Windows hosts, or VMWare Fusion Pro for Intel-based macOS hosts, prior to class beginning of class. Note that Workstation Pro and Fusion Pro are now available for free for both personal and commercial use from Broadcom.
Your course media is delivered via download. The media files for class are large, approximately 100GB in total. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.
Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.
Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.
If you have additional questions about the laptop specifications, please contact customer service.
FOR608 is aimed at digital forensics, incident response, intrusion detection, and threat hunting professionals in medium to large organizations, who constantly face battles with enterprise scale and complexity.
Please note that FOR608 is an advanced course that skips over introductory material of Windows host- and network-based forensics and incident response. Although this class is not necessarily more technical than our 500-level classes, it does assume that prior knowledge so that topics and concepts are not repeated.
The GIAC Enterprise Incident Response (GEIR) certification validates a practitioner's mastery of enterprise-class incident response and threat hunting tools and techniques. GEIR certification holders have demonstrated the ability to use analysis methodologies to understand attacker movement across varying functions and operating systems.
FOR608 is an advanced level course that skips over introductory material of Windows host- and network-based forensics and incident response. This class is not necessarily more technical than our 500-level classes, but it does assume that knowledge so that topics and concepts are not repeated.
Students must have multiple years of DFIR experience and/or have taken classes such as:
The FOR608 course is a part of the “Incident Response & Threat Hunting” Learning Path, which aims to equip forensics and incident response professionals with the specialized skills they need to move beyond first-response incident handling to analyze attacks and develop appropriate plans for remediation and recovery.
Depending on your current or desired future role, one of these courses is a great next step in your cybersecurity journey:
Enterprise incident response refers to a structured and comprehensive approach to handling cybersecurity incidents within large organizations. It goes beyond basic incident handling by incorporating a proactive, strategic mindset and leveraging advanced technologies.
The key distinctions of enterprise-class incident response include:
In today's complex threat environment, a robust incident response capability is crucial for organizations to protect their critical assets and minimize the impact of cyberattacks. Enterprise-class incident response helps organizations:
FOR608: Enterprise-Class Incident Response and Threat Hunting can greatly benefit your cybersecurity career. Here’s how:

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources