SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.
Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.
Mandatory System Hardware Requirements
Mandatory Host Configuration and Software Requirements
Your course media is delivered via download. The media file for class is around 50GB. As such, you need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.
Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.
Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.
If you have additional questions about the laptop specifications, please contact customer service.
This hands-on course, which covers ransomware and cyber extortion history, prevention strategies, early detection techniques, threat hunting, and practical lab-driven incident response training, is ideally suited for the following roles and audiences:
Technical and Security Practitioners
Legal, Investigative, and Advisory Roles
Leadership, Risk, and Governance
Industry and Sector-Specific Audiences
Career Development and General Interest
A background in Incident Response (IR) is suggested, but not required. . IR experience or at least alert triage experience such as one acquired within a SOC or CIRT is useful, but the course covers all techniques and background knowledge required to succeed in this training endeavor. We also recommend familiarity with regular expressions (regex). If you are not yet familiar with regex, we recommend reviewing the following resources:
All these items are covered in the course, but the general idea is to have experience working incidents.
The FOR528 course is a part of the “Digital Forensics, Malware Analysis, & Threat Intelligence” Learning Path, which aims to equip cybersecurity professionals with specialized investigative skills.
Depending on your current or desired future role, one of these courses is a great next step in your cybersecurity journey:
Ransomware is a type of malicious software designed to block access to a computer system or its data until a ransom is paid. Cyber extortion involves threats to release stolen data or disrupt systems unless demands, often financial, are met. These attacks have become increasingly sophisticated and impactful, making them critical to understand.
Why they are important:
FOR528: Ransomware and Cyber Extortion equips you with valuable knowledge and skills in a critical area of cybersecurity. Here’s how:

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources