SEC536: Adversarial AI - Penetration Testing AI Systems

Cloud Accounts and API Keys
SANS provides students with access to labs hosted on AWS infrastructure, along with the required LLM API keys for lab participation. Students can log in to their SANS account and visit the MyLabs page 24 hours before class begins to access the information and materials needed to get started.
Mandatory Laptop Requirement
Students must bring their own system configured according to these instructions.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.
Students must be in full control of their system's network configuration. The system will need to communicate with the cloud-hosted student VM using a combination of HTTPS, SSH, and SOCKS5 traffic on non-standard ports. Running VPN, intercepting proxy, or egress firewall filters may cause connection issues communicating with the student VM. Students must be able to configure or disable these services to connect to the lab environment.
Bring Your Own Laptop Configured Using the Following Directions
A properly configured system is required for each student participating in this course. Before starting your course, carefully read and follow these instructions exactly:
Mandatory Host Hardware Requirements
Mandatory Software Requirements
Prior to class, ensure that the following software is installed on the host operating system:
Summary
Before beginning of the course you should:
After you have completed those steps, access the SANS provided AWS account to connect to the SANS Cloud Security Flight Simulator and connect to the SEC546 student VM. The SEC546 Instance hosts an electronic workbook, VSCode, Git Server, and Terminal services that can be accessed through the Firefox browser.
Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 20 minutes or more to complete these instructions.
Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.
If you have additional questions about the laptop specifications, please contact customer service.
This course is designed for practitioners in Protect AI roles, including AI SOC Orchestrators
The course assumes working comfort with Python, command line, and containers, along with a foundational understanding of LLMs and GenAI concepts.
Many of these titles are still being defined inside organizations. SEC546 gives you the practical skills to step into them with credibility as the roles form, rather than waiting for hiring patterns to catch up.
While agentic AI systems may be deployed in cloud environments, SEC546 is a defensive AI course focused on securing agents, tools, and orchestration layers rather than general cloud infrastructure. It focuses on what changes when an LLM stops just answering questions and starts taking actions: calling tools, reading data, moving across business systems. Agents like that need different controls than traditional apps, and that's what the course teaches.
Depending on your current or desired future role, the courses below are great next steps in your cybersecurity journey.
Together, they prepare you to defend GenAI, secure agentic AI, and lead the program that governs both.
SEC546 aligns with the SANS Secure AI Blueprint’s Protect AI pillar by focusing on the defensive controls needed to secure agentic AI systems in production.
The course teaches practitioners how to protect autonomous AI behavior across real-world workflows by identifying agentic AI threats, designing and validating guardrails, defending against prompt injection and context poisoning, enforcing agent scope and goal integrity, securing multi-agent chains, and containing rogue or compromised agents.
While agentic AI may run in cloud environments, SEC546 is not a general cloud infrastructure course. It is a defensive AI course focused on securing agents, tools, orchestration layers, and autonomous behavior.
Agentic AI Security is the discipline of securing autonomous AI systems that can plan, make decisions, execute actions, invoke tools, retain memory, operate across browsers and desktops, and coordinate with other agents, often with limited human oversight. Unlike traditional chatbot-style AI applications that primarily generate text, agentic systems exercise real agency: they pursue multi-step goals, call external tools and services, access sensitive data and environments, maintain context across tasks, and delegate work across connected agent workflows. This autonomy introduces a fundamentally different class of security risks, including prompt injection with execution impact, memory and context poisoning, tool response tampering, agent identity abuse, delegated authorization failures, uncontrolled privilege, cross-agent data leakage, and cascading failures across multi-agent systems.
Securing agentic AI is critical because organizations are rapidly deploying these systems to automate high-value workflows such as software development, infrastructure operations, security tasks, compliance activities, customer support, and increasingly, actions that affect physical devices and environments. An agent that can be manipulated into misusing its permissions, leaking sensitive data, following poisoned context, or executing unauthorized actions creates direct risk to business continuity, data integrity, system safety, and regulatory obligations. The consequences grow even more severe in connected agent ecosystems, where one compromised agent, tool, or context source can rapidly propagate failures across an entire pipeline.
SEC546 positions students at the forefront of the next major shift in cybersecurity: securing autonomous AI agents. As organizations move beyond passive chatbot use cases to systems that plan, execute actions, invoke tools, maintain memory, operate across browsers and desktops, and coordinate across multi-agent workflows, demand is growing for professionals who can defend these high-risk environments. This course delivers the specialized, defense-focused skills needed to close that gap and differentiate students in a fast-expanding market.
Five intensive, lab-driven days go far beyond general AI security concepts to focus on the distinct attack surface of autonomous AI systems. Students build and apply production-grade defenses across input and output boundaries, prompt injection resistance, agent identity and permissions, memory and context security, rogue-agent containment, runtime governance, defensive MCP gateways, MCP data integrity, tool execution sandboxing, desktop agent security, agent supply chain provenance, multi-agent trust chains, browser and computer-use agents, delegated authorization, cross-agent data isolation, cyber-physical fail-safes, and emerging defenses such as confidential agent execution, then prove those skills in a comprehensive live-fire defense capstone.
Beta courses are part of the SANS course development process, bringing new training to market in collaboration with the practitioner community. SEC546 delivers fully developed content, complete labs, and expert instruction at 25% off full course cost.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources