Group Purchasing
Group Purchasing
AI SKILLSUPDATED

SEC556: IoT Penetration Testing

SEC556Offensive Operations, Artificial Intelligence
  • 3 Days (Instructor-Led)
  • 18 Hours (Self-Paced)
Course authored by:
Larry PesceJames Leyte-Vidal
Larry Pesce & James Leyte-Vidal
SEC556: IoT Penetration Testing
Course authored by:
Larry PesceJames Leyte-Vidal
Larry Pesce & James Leyte-Vidal
  • 18 CPEs

    Apply your credits to renew your certifications

  • Virtual Live Instruction or Self-Paced

    Train from anywhere. Attend a live instructor-led course remotely or train on your time over 4 months.

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 13 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

SEC556 equips security professionals with comprehensive skills to identify, assess, and exploit IoT device security mechanisms across diverse technological ecosystems.

Course Overview

SEC556 teaches students how to assess the security of modern Internet of Things (IoT) and embedded systems through hands-on analysis of firmware, hardware, wireless protocols, network communications, and application interfaces. Students learn practical techniques to identify, exploit, and defend vulnerabilities across connected ecosystems.

2026 Course Update Summary

The latest SEC556 update expands SANS Institute’s hands-on IoT penetration testing course with modern firmware analysis workflows, AI-assisted testing techniques, expanded wireless exploitation labs, and updated offensive methodologies for today’s connected ecosystems.

For a detailed breakdown of what's new and how these updates can strengthen your team, download the flyer.

What You’ll Learn

  • Assess IoT network controls comprehensively
  • Investigate hardware interaction points
  • Uncover firmware vulnerabilities
  • Analyze wireless technology weaknesses
  • Manipulate Bluetooth Low Energy devices
  • Reverse-engineer unknown radio protocols
  • Use AI as a force multiplier for penetration testing activities

Business Takeaways

  • Faster detection of real threats
  • Maximized ROI on existing tools
  • Develops in-house threat detection expertise
  • Defensive coverage against modern tactics
  • Operational confidence and retention
  • Alignment with security goals and audit requirements

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC556: IoT Penetration Testing.

Section 1Introduction to IoT Network Traffic and Web Services

This section introduces IoT security challenges, focusing on testing methodologies applicable across diverse implementations. Students explore threat modeling, network reconnaissance, web application vulnerabilities, and API interaction techniques. The section emphasizes practical strategies for identifying and exploiting IoT network and web-based vulnerabilities.

Topics covered

  • Course methodology introduction
  • IoT testing framework
  • Network discovery techniques
  • Web service reconnaissance
  • Vulnerability exploitation strategies

Labs

  • AI-assisted threat modeling for IoT devices
  • Analyze an IoT device packet capture
  • Scan and exploit an IoT router device
  • Access a publicly exposed IoT webcam
  • Steal a car through IoT web service APIs

Section 2Exploiting IoT Hardware Interfaces and Analyzing Firmware

Students will learn advanced hardware testing techniques, including device deconstruction, communication interface analysis, and firmware recovery. The section covers destructive and non-destructive testing methodologies, focusing on identifying hardware vulnerabilities and extracting critical system information.

Topics covered

  • Hardware testing fundamentals
  • Device disassembly techniques
  • Communication port identification
  • Firmware analysis methodologies
  • Filesystem exploitation

Labs

  • Obtaining and analyzing specification sheets
  • Sniffing Serial and SPI
  • Recovering Firmware from PCAP
  • Recovering filesystems with Binwalk
  • Pillaging the filesystem

Section 3Exploiting Wireless IoT: WiFi, BLE, Zigbee, LoRA, and SDR

This section explores wireless technologies prevalent in IoT ecosystems, providing comprehensive techniques for traffic capture, network access, and device compromise. Students will gain expertise in analyzing standard and proprietary wireless communication protocols.

Topics covered

  • WiFi security assessment
  • Bluetooth Low Energy vulnerabilities
  • Zigbee protocol analysis
  • LoRA communication techniques
  • Software-Defined Radio exploration

Labs

  • WiFi PSK cracking
  • Bluetooth Low Energy interaction
  • Zigbee traffic analysis
  • Conducting a replay attack on IoT

Things You Need To Know

Relevant Job Roles

Vulnerability Analysis (OPM 541)

NICE: Protection and Defense

Responsible for assessing systems and networks to identify deviations from acceptable configurations, enclave policy, or local policy. Measure effectiveness of defense-in-depth architecture against known vulnerabilities.

Explore learning path

Application Pen Tester

Offensive Operations

Application penetration testers probe the security integrity of a company’s applications and defenses by evaluating the attack surface of all in-scope vulnerable web-based services, clientside applications, servers-side processes, and more. Mimicking a malicious attacker, app pen testers work to bypass security barriers in order to gain access to sensitive information or enter a company’s internal systems through techniques such as pivoting or lateral movement.

Explore learning path

Red Teamer Training, Salary, and Career Path

Offensive Operations

Monitor and analyze activity across cloud environments, proactively detect and assess threats, and implement preventive controls and targeted defenses to protect critical business systems and data.

Explore learning path

Systems Testing and Evaluation (OPM 671)

NICE: Design and Development

Responsible for planning, preparing, and executing system tests; evaluating test results against specifications and requirements; and reporting test results and findings.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $5,250 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Live Online Europe October 2026

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €4,935 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Japan November 2026

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    ¥798,750 JPY*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Stay Sharp: Jan 2027

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $5,250 USD*Prices exclude applicable local taxes
    Registration Options
Showing 4 of 4

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources