SEC536: Adversarial AI - Penetration Testing AI Systems

Cloud Accounts
SANS provides students with time-limited AWS accounts 24 hours before class starts for completing the labs. Students can log in to their SANS account and visit the MyLabs page to download their cloud credentials the day before class begins.
Mandatory Laptop Requirement
Students must bring their own system configured according to these instructions.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.
Students must be in full control of their system's network configuration. The system will need to communicate with the cloud-hosted student VM using a combination of HTTPS, SSH, and SOCKS5 traffic on non-standard ports. Running VPN, intercepting proxy, or egress firewall filters may cause connection issues communicating with the student VM. Students must be able to configure or disable these services to connect to the lab environment.
Bring Your Own Laptop Configured Using the Following Directions
A properly configured system is required for each student participating in this course. Before starting your course, carefully read and follow these instructions exactly:
Mandatory Host Hardware Requirements
Mandatory Software Requirements
Summary
Before beginning the course you should:
After you have completed those steps, access the SANS provided AWS account to connect to the SANS Cloud Security Flight Simulator and connect to the SEC545 student VM. The SEC545 Instance hosts an electronic workbook, VSCode, Gitlab, and Terminal services that can be accessed through the Firefox browser.
Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.
Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.
If you have additional questions about the laptop specifications, please contact customer service.
SEC545 is designed for practitioners in Protect AI roles who are responsible for securing GenAI and LLM-powered applications, AI-enabled workflows, and the infrastructure that supports them. This includes
Many of these titles are still being defined inside organizations. SEC545 gives you the practical skills to step into them with credibility as the roles form, rather than waiting for hiring patterns to catch up.
The GIAC AI Platform Security (GAIPS) certification validates a practitioner’s ability to audit and secure Generative AI applications and large language model (LLM) development pipelines. GAIPS certification holders demonstrate hands-on skills protecting data flows, model integrations, APIs, and deployment workflows against emerging threats across the AI lifecycle.
Students should have working familiarity with the following technologies and tools before attending SEC545:
Preparing for SEC545
SEC545 makes heavy use of DevOps, MLOps, and cloud-native tooling throughout the labs. Students who arrive with hands-on familiarity with the following will get more out of the lab time:
While many GenAI systems run in cloud environments, SEC545 is a defensive AI course focused on protecting the AI application stack itself, not a general cloud infrastructure security course.
Depending on your current or desired future role, the courses below are great next steps in your cybersecurity journey.
SEC545: GenAI and LLM Application Security aligns with the Protect AI pillar by teaching defenders how to secure GenAI and LLM applications in production. The course focuses on protecting AI systems by threat modeling GenAI architectures, defending RAG and vector database pipelines, mitigating prompt injection, and hardening MLOps deployments across cloud and on-prem environments.
While many GenAI systems run in cloud environments, SEC545 is a defensive AI course focused on protecting the AI application stack itself, not a general cloud infrastructure security course. Students learn to identify security risks in GenAI and LLM application architectures, secure RAG pipelines, vector databases, and model-serving workflows to protect AI data flows from leakage, poisoning, and abuse, and apply defensive controls to MLOps environments and AI-enabled application stacks in support of a Protect AI strategy.
GenAI and Large Language Model (LLM) application security refers to the strategies, tools, and practices used to protect generative AI systems from misuse, manipulation, and cyber threats. As organizations increasingly build and deploy GenAI-powered applications, these systems become valuable targets for attackers. Unlike traditional software, GenAI introduces unique risks, including prompt injection attacks, malicious model outputs, and vulnerabilities in third-party tools or models. Without strong security measures, GenAI applications can inadvertently leak sensitive data, generate harmful content, or expose organizations to supply chain attacks.
Prioritizing security in GenAI applications ensures that these powerful technologies can be used safely, ethically, and reliably. Securing GenAI is essential not only for protecting business assets but also for maintaining public trust.
This 5-day course provides a comprehensive look at GenAI and LLM application security, covering everything from prompt-level risks and supply chain vulnerabilities to in-depth topics like model training, MLSecOps, agent infrastructure, and cloud deployment scenarios. Students gain hands-on experience in threat modeling real-world GenAI pipelines and defending AI infrastructure that includes components such as Airflow, SageMaker, AWS Bedrock, and containerized environments.
Why it matters:
SEC545 will strengthen your cybersecurity career by equipping you with the skills needed to secure one of the fastest-growing areas in technology: Generative AI. As more organizations adopt GenAI tools, there is a growing demand for security professionals who can identify risks, implement controls, and build secure AI applications. This course provides both technical knowledge and strategic guidance, helping you stand out in a competitive job market.
The 5-day course goes significantly further than its 3-day predecessor. It includes new labs on threat modeling with MAESTRO, securing MLOps pipelines, training models with SageMaker, and attacking agent infrastructure through MCP. Students gain hands-on experience defending against advanced GenAI threats across a real deployment pipeline. This level of depth gives practitioners a unique edge in applying GenAI security concepts in production environments.
Career benefits:

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources