SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions!
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.
It is critical that you back-up your system before class. It is also strongly advised that you do not bring a system storing any sensitive data.
CPU
BIOS
RAM
Hard Drive Free Space
Operating System
Additional Software Requirements
VMware Player Install
Your course media will now be delivered via download. The media files for class can be large, some in the 40 - 50 GB range. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as you get the link. You will need your course media immediately on the first day of class. Waiting until the night before the class starts to begin your download has a high probability of failure.
If you have additional questions about the laptop specifications, please contact customer service.
SEC504 training is recommended for a diverse range of individuals, including:
The GIAC Incident Handler (GCIH) certification validates a practitioner's ability to detect, respond, and resolve computer security incidents using a wide range of essential security skills. GCIH certification holders have the knowledge needed to manage security incidents by understanding common attack techniques, vectors and tools, as well as defend against and respond to such attacks when they occur.
The SEC504: Hacker Tools, Techniques, Exploits, and Incident Handling course has specific prerequisites to ensure that participants can fully engage with the material. Recommended prerequisites include:
If you are new to these concepts, SEC401: Security Essentials - Network, Endpoint, and Cloud covers many of these foundational skills and provides an excellent starting point before advancing to SEC504. While these skills are recommended, SEC504 training is designed to accommodate varying levels of experience by providing hands-on labs and detailed instruction. Those with foundational IT and security knowledge will gain the most value from this course.
SEC504 training is part of the Core Techniques Learning Path, which aims to equip security professionals with crucial information, skills, and strategies for protecting, maintaining, and securing systems. It is also part of the Offensive Operations Learning Path, which includes skills and focus areas like penetration testing, red team, and purple team.
In the context of SEC504: Hacker Tools, Techniques, Exploits, and Incident Handling, incident handling refers to the structured approach for detecting, responding to, and managing cybersecurity incidents like data breaches, malware infections, or unauthorized access attempts. The goal of incident handling is to quickly identify and contain a security incident, mitigate its impact, and restore normal operations as efficiently as possible.
Why Incident Handling Is Important
The SEC504 course covers these processes extensively, training participants to handle incidents systematically and confidently. This prepares cybersecurity professionals to protect their organizations and rapidly recover from incidents, aligning with SANS's mission to empower practical, high-stakes cybersecurity expertise.
Completing the SEC504 course can significantly boost your cybersecurity career, especially in roles focused on threat detection and incident response:
Overall, SEC504 training builds essential skills, provides recognized certification pathways, and strengthens your profile for advanced cybersecurity roles.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources