SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions!
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.
Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.
Mandatory System Hardware Requirements
Mandatory Host Configuration And Software Requirements
Your course media will now be delivered via download. The media files for class can be large, some in the 40 - 50 GB range. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as you get the link. You will need your course media immediately on the first day of class. Waiting until the night before the class starts to begin your download has a high probability of failure.
SANS has begun providing printed materials in PDF form. Additionally, certain classes are using an electronic workbook in addition to the PDFs. The number of classes using eWorkbooks will grow quickly. In this new environment, we have found that a second monitor and/or a tablet device can be useful by keeping the class materials visible while the instructor is presenting or while you are working on lab exercises.
If you have additional questions about the laptop specifications, please contact customer service.
SEC670 training is recommended for a diverse range of individuals, including:
It is strongly recommended that students have experience with developing programs in C/C++ for either Linux or Windows platforms. Students should have C/C++ experience programming loops, conditional statements, and switch statements, creating functions and function pointers, and using pointers, linked lists, and type casting.
In addition, students should have a basic understanding of how Windows works internally. A basic understanding of process address space, virtual memory, physical memory, the registry, etc. would be a great place to start. The book titled 'Windows Via C/C++' is a solid resource to understand Windows and getting to learn programming at the same time.
Courses that lead into SEC670:
SEC670 gives alumni of these courses a more in-depth look at how the tools used in them operate. It also shows students how to make their own tools and add missing features that other compiled tools might not have. As an example, in SEC660, there is a brief mention of tampering with Windows AMSI and AMSI bypasses. SEC670 will take you behind the scenes where students will create their own, fully customized AMSI bypass.
The SEC670 learning path begins with foundational knowledge in Windows programming, continuing through on-target reconnaissance, process manipulation, persistence engineering, and defense evasion. Participants should first acquire basic penetration testing skills (SEC504/560), advanced red teaming concepts (SEC565), and introductory C programming before undertaking this specialized development course.
Red Team Operations involve simulating sophisticated adversary tactics to evaluate security effectiveness. This course equips participants with capabilities to develop customized tools that closely mirror advanced threat tactics, enabling organizations to validate defenses against realistic attacks rather than theoretical vulnerabilities.
By mastering Windows implant creation, participants position themselves for specialized roles in offensive security, threat research, and defense validation. This capability enhances professional value through unique technical abilities that few practitioners possess.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources