SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all the specified requirements.
Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.
Mandatory System Hardware Requirements
Mandatory Host Configuration and Software Requirements
Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.
Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.
If you have additional questions about the laptop specifications, please contact customer service.
This course is designed for technical professionals who secure, monitor, or respond to identity-related threats in Microsoft cloud and hybrid environments.
SEC559 is part of the SANS Cloud Security curriculum, designed to help practitioners build advanced skills for securing modern cloud and hybrid environments. The course complements cloud security, detection, and architecture training by focusing specifically on identity as the primary control plane.
It fits naturally for professionals who already work with cloud or enterprise environments and want to deepen their ability to detect and remediate identity-driven attacks across cloud and hybrid identity control planes.
The course is also part of the Cloud Security Analyst journey, designed for practitioners who needs to secure environments, detect threats, secure identity, and respond to breach. The Analyst Journey is built to develop all three. The other two courses in the journey are:
Identity security protects users, applications, and services that control access to modern environments, ensuring access is legitimate, authorized, and continuously validated across cloud and hybrid systems. As traditional network boundaries dissolve under cloud, remote work, automation, and AI, identity becomes the primary control plane and the primary target.
Attackers chain small identity failures together: compromised credentials, abused OAuth consent, leaked secrets, and manipulated federation trust let them operate with legitimate access that bypasses traditional defenses and escalates into tenant- or domain-wide compromise. But detection alone is not enough. Privilege sprawl, orphaned accounts, and ungoverned application access create the conditions attackers exploit long before a breach begins. Effective identity security means governing the full lifecycle of every identity in your environment so that when an attack occurs, the blast radius is contained, and the path to remediation is clear.
SEC559 builds expertise in one of the fastest-growing areas of cybersecurity: identity security. As organizations shift to cloud and hybrid environments, security teams urgently need practitioners who can detect, govern, and respond to identity-based attacks that bypass traditional defenses.
This course gives you hands-on experience across the full identity lifecycle, from detecting OAuth abuse and token theft to governing privilege and access, and executing safe, structured remediation. You will develop practical skills that align directly with roles in IAM, cloud security, SOC operations, incident response, and security architecture.
By completing SEC559, you position yourself as a cyber professional who understands how attackers operate today: abusing credentials, tokens, applications, and trust relationships rather than exploiting software vulnerabilities. You will also have the skills to govern identity at scale, closing the privilege and lifecycle gaps that attackers rely on before an incident ever begins.
Beta courses are part of the SANS course development process, designed to bring new training to market in collaboration with the practitioner community. These early-access runs allow students to engage with the course while providing feedback that helps refine content, labs, and delivery before full release.
For SEC559, the beta delivers fully developed course content with complete labs, expert instruction, and full student support. It is also offered at a 25% discount off full course cost, giving you the opportunity to take the course early while it is being finalized for general release.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources