Group Purchasing
Group Purchasing
AI-FOCUSED

SEC598: AI and Security Automation for Red, Blue, and Purple Teams

SEC598Offensive Operations, Artificial Intelligence
  • 6 Days (Instructor-Led)
  • 36 Hours (Self-Paced)
Course authored by:
Jeroen VandeleurJason Ostrom
Jeroen Vandeleur & Jason Ostrom
SEC598: AI and Security Automation for Red, Blue, and Purple Teams
Course authored by:
Jeroen VandeleurJason Ostrom
Jeroen Vandeleur & Jason Ostrom
  • GIAC AI Security Automation Engineer (GASAE)
  • 36 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 25 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Harness GenAI, agentic AI, world-class automation, emulation and detection-as-code to unify red and blue operations into a continuous purple team model.

Course Overview

SEC598: AI and Security Automation for Red, Blue, and Purple Teams empowers you to elevate your security program across offensive and defensive domains. Whether you're automating adversary emulation campaigns, building intelligent response workflows, or engineering detection-as-code pipelines, this course teaches you to harness AI-driven automation to outpace modern threats.

You’ll develop the skills to operationalize AI, agentic automation, detection-as-code, and SOAR while integrating GenAI and LLMs into enrichment and response workflows, deploying secure cloud infrastructure, and emulating attack techniques.

These capabilities are brought to life through 25 immersive labs and practical frameworks that unify red and blue team functions into continuous purple teaming—enabling you to automate offensive testing, scale cloud-native detection, and build AI-powered playbooks for faster, smarter, and more resilient cybersecurity operations.

Automate Security with Generative AI

Today’s security operations centers (SOCs) face unprecedented challenges: overwhelming alert volumes, complex hybrid cloud environments, fragmented tooling, and increasingly AI-augmented adversaries. Many teams are overburdened, reactive, and struggling to keep pace with modern attack speed and complexity.

SEC598: AI and Security Automation for Red, Blue, and Purple Teams is built to tackle these challenges and accelerate your transformation journey. This course provides world-class approaches, practical frameworks, tools, and hands-on experience to build smarter, faster, and more resilient security operations, turning automation workflows, GenAI and agentic automation as force multipliers for both offensive and defensive teams.

This course doesn’t just teach concepts; it shows you how to implement them in enterprise-grade environments and what modernized security operations look like when fully operational. During the hands-on labs, you’ll work in GLOBEX Automation, a realistic hybrid enterprise environment adopting AI and spanning Azure, AWS, and on-premises infrastructure, designed to reflect the real challenges SOC teams and organizations face on a daily basis.

Through 25 immersive labs and bonus challenges, you will gain experience deploying automation playbooks, engineering detection-as-code pipelines, integrating GenAI and LLM-powered RAG for enrichment, building red team AI agents for continuous control validation, and designing AI-augmented defensive workflows to accelerate detection and response. You will also explore continuous purple teaming, closing the gap between offensive testing and defensive detection, and building modernized security capabilities that continuously improve SOC maturity.

By the end of the course, you will leave with ready-to-use automation playbooks, IaC templates, AI-driven workflows, and detection-as-code pipelines, everything needed to immediately uplift your own security program. You will gather experience with LLM-powered detection engineering, autonomous red team agents, automated response workflows, and practical frameworks for integrating AI and automation across your SOC.

SEC598 is not theoretical; it’s practical, immersive, and a built-for-action SANS course. From LLM-powered detection engineering to autonomous red team agents, from automated workflows to continuous purple teaming, this course empowers you to defend smarter, respond faster, and lead the next generation of AI-enabled security operations.

Author Statement

Over the past several years, my focus has been on applying automation and Generative AI within large and complex organizations to solve some of the bigger challenges and transforming isolated teams into a modern security operation. Together with course author Jason Ostrom, we decided to share not only our professional experiences but also the research, lessons, and solutions we have developed while leveraging GenAI, automation, and detection engineering for both offense and defense.

With SEC598, you will get these different perspectives to create a practical and unified approach for red and blue teams that addresses real-world problems such as fragmented tooling, alert overload, and increasingly AI-augmented adversaries.

I am very excited to release SEC598, which has a clear and in-depth focus on security automation leveraging GenAI to tackle the challenges we face daily. I am convinced that SEC598 gives you an in-depth understanding of automation concepts, technologies, and how to apply them for offense and defense. This course is your game-changer to begin your journey into continuous purple teaming!

– Jeroen Vandeleur

What You’ll Learn

  • Build and operationalize automation playbooks for both offensive and defensive workflows
  • Implement detection-as-code pipelines and integrate them into CI/CD environments
  • Apply LLM-powered workflows for enrichment, detection generation, and decision support
  • Engineer and deploy RAG-based agents for investigation and context-aware response
  • Utilize red team AI agents for autonomous adversary emulation and control validation
  • Design and implement AI-augmented defensive playbooks to reduce detection and response time
  • Adopt automation and continuous purple teaming practices to unify offensive and defensive teams

Business Takeaways

  • Accelerate SOC maturity by automating repetitive tasks and enabling AI-driven decision-making
  • Bridge operational gaps between red and blue teams through continuous purple teaming
  • Modernize detection engineering by adopting detection-as-code and CI/CD best practices
  • Reduce risk exposure by continuously validating defenses against AI-driven adversaries
  • Maximize security operations capabilities by integrating automation and AI into existing processes
  • Develop future-ready skills to manage increasingly hybrid and AI-powered environments

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC598: AI and Security Automation for Red, Blue, and Purple Teams.

Section 1Foundations of GenAI, LLMs, & Security Automation

Build the foundation for modern security automation by understanding why AI and automation matter now. Learn how to secure AI systems, leverage AI for security, and integrate automation strategies that scale across hybrid cloud environments and SOC operations.

Topics covered

  • Why security automation and AI are critical today
  • Security engineering the CI/CD approach
  • Configuration management & policy-as-code at scale
  • Automation triggers and SOAR workflows
  • Foundations of detection-as-code, GenAI and LLMs

Labs

  • One Bucket Is All It Takes
  • OS Hardening Baselines with Ansible
  • Link Triggers to Automation Scripts
  • Intro to LLM and RAG
  • Detection as Code I: Write a Detection Using LLM

Overview

This section establishes the strategic and technical foundation of the course. We explore why AI and automation have become essential to modern security operations and how they enable security teams to move from reactive to proactive, adaptive operations. You will learn how AI impacts security both defensively and offensively, and how automation frameworks can be applied across enterprise SOCs.

A major highlight of this section is the Globex Automation environment, which simulates hybrid cloud environments, SOC workflows, and automation infrastructure at scale. Students will implement Ansible for policy-as-code to manage configuration baselines, build CI/CD pipelines for detection-as-code, and create initial automation triggers to kickstart AI-driven workflows. In the last modules, SEC598 covers the foundations of detection-as-code, Generative AI, and LLMs to enhance your security capabilities.

Full Lab Details

  • Lab 1.1: One Bucket Is All It Takes: Execution of offensive techniques and cloud misconfiguration detections
  • Lab 1.2: OS Hardening Baselines with Ansible: Deploy security configuration at scale
  • Lab 1.3: Link Triggers to Automation Script: Build automated security workflows
  • Lab 1.4: Intro to LLM and RAG: Explore large language models in enrichment workflows
  • Lab 1.5: Detection as Code I: Write a Detection Rule Using LLM

Full Topics Details

  • Why Security Automation and AI Matter
    • Drivers behind SOC automation and AI adoption
    • Challenges in scaling security operations and talent gaps
  • Policy-as-Code and Secure Configuration Management
    • Automating baselines with Ansible
    • Enforcing consistent security policies across hybrid environments
    • Define desired state configuration and monitor compliance
  • CI/CD for Security Engineering
    • Introduction to DevOps for Cyber Security
    • Version-controlled detection logic and deployment pipelines
    • Automating detection and response workflows at scale
  • Triggers for automation
    • Standardized automation workflows
    • Common triggers used for automation
  • Automation Playbooks:
    • Introduction to modular, reusable automation workflows
    • Integrating APIs and security platforms for automated orchestration
  • Foundations of GenAI and LLMs
    • Applying LLMs for enrichment, detection, and purple teaming use cases
    • Understanding the different LLM models and RAG-based solutions
  • Detection Engineering for Purple Teams
    • Leveraging offensive insights for defensive detection logic
    • Building and deploying detection-as-code pipelines at scale

Section 2Security Automation Engineering & AI Workflows

This section focuses on practical automation workflows using PowerShell, Terraform, Ansible, Python, and Jupyter Notebook. Students will learn how to build secure infrastructure-as-code deployments, create automated firing ranges, engineer SOAR playbooks, and develop AI-driven agentic workflows for next-generation SOC operations.

Topics covered

  • Automated security workflows with PowerShell for both offense and defense
  • Infrastructure as Code (IaC) for secure cloud management using Terraform
  • Building automated firing ranges for testing and validation
  • Python and Jupyter Notebook for SOC enrichment and analysis
  • SOAR tooling, playbook automation, and agentic AI engineering

Labs

  • OS Hardening Baselines with PowerShell
  • Cloud Management with Terraform
  • Deploying a Firing Range with Terraform and Ansible
  • Email Threat Analysis with Jupyter Notebook
  • Creating a Tines Story

Overview

Section 2 builds on foundational automation principles and applies them across multiple technologies commonly used in modern SOCs. Students start with PowerShell to automate baseline configuration and extend its application to both blue team hardening and red team simulation tasks. The module then moves to Infrastructure as Code (IaC) using Terraform, focusing on secure cloud provisioning and repeatable deployments that integrate easily into CI/CD pipelines.

To validate automation workflows, students will build firing ranges using Terraform and Ansible, enabling safe, repeatable testing of detection pipelines and security controls. Next, students leverage Python and Jupyter notebooks to build flexible security automation scripts for enrichment, analysis, and incident response, emphasizing modular and reusable code.

The section concludes with an exploration of SOAR tooling and agentic AI Engineering, demonstrating how to build and automate SOAR playbooks while integrating AI-powered reasoning agents that can autonomously investigate and respond to incidents, closing the gap between detection and response with human-in-the-loop controls.

Full Lab Details

  • Lab 2.1: OS Hardening Baselines with PowerShell: Automate Windows host baseline enforcement
  • Lab 2.2: Cloud Management with Terraform: Deploy secure hybrid cloud resources
  • Lab 2.3: Deploy a Firing Range with Terraform and Ansible: Build repeatable testing environments for SOC workflows
  • Lab 2.4: Email Threat Analysis with Jupyter Notebook: Automate phishing email analysis and IOC extraction
  • Lab 2.5: Create a Tines Story: Build and automate a SOAR workflow using Tines

Full Topics Details

  • Automated Workflows with PowerShell
    • Blue team automation for baseline hardening
    • Red team use cases for offensive testing
  • The Power of Infrastructure as code (IaC)
    • Secure, repeatable cloud provisioning with Terraform
    • Infrastructure provisioning and configuration management
    • Define desired state configuration and monitor compliance
  • Building Firing Ranges
    • Building your firing range
    • Terraform and Ansible-based emulation environments
  • Security Automation with Python and Jupyter Notebook
    • Enrichment and investigation workflows
    • Visualization and modular notebook-driven SOC automation
  • SOAR playbook automation engineering
    • Define automation workflows
    • Comparing current SOAR platforms and their capabilities
    • The future of Hyperautomation
  • Agentic AI engineering
    • Design and define agentic workflows
    • Integrating agentic AI for autonomous decision support and response

Section 3Cloud Automation & AI Security Services

This section covers cloud-native security automation across Microsoft Azure and AWS. You will learn to enforce security policies, automate response workflows, integrate AI services, and deploy offensive and defensive automation, including AI-driven Kubernetes attack simulation and continuous security testing with GenAI-powered agents.

Topics covered

  • Cloud security fundamentals and governance (Azure & AWS)
  • Cloud-native services for automated security monitoring & enforcement
  • Intelligent automation with Microsoft AI and AWS Bedrock services
  • Cloud-native incident response, monitoring, and third-party API integrations
  • AWS AI agents targeting Kubernetes and continuous security testing

Labs

  • Create Automated Actions in Azure
  • Cloud-Native IR for Compromised Systems
  • Continuous Security Testing Enhanced with AI
  • Kubernetes Takedown with Offensive AI Agents

Overview

Section 3 focuses on building, securing, and automating cloud operations. Students begin with cloud security fundamentals and move to Microsoft Azure, learning to implement Azure Policy and Blueprints to enforce governance and compliance through automation. Azure monitoring, SOAR orchestration with Logic Apps and Functions, and Microsoft AI services are introduced to enhance enrichment and automated decision-making.

For AWS, the section covers AWS Config, Security Hub, Lambda, and Step Functions to enable automated governance, incident response, and integration with third-party APIs. Students explore AWS Bedrock for AI-powered insights and implement continuous security testing using AI-driven automation pipelines.

Finally, students gain offensive perspectives by deploying AI-driven attack agents against Kubernetes environments, providing insights into cloud-native threat simulation and defense validation. This section bridges operational security and offensive simulation, delivering a complete view of how AI and automation are transforming cloud security operations.

Full Lab Details

  • Lab 3.1: Create Automated Actions in Azure: Build and trigger automated SOC response workflows using Logic Apps
  • Lab 3.2: Cloud-Native IR for Compromised Systems: Automate incident response in Azure and AWS cloud workloads
  • Lab 3.3: Integrate AWS with Third-Party API: Extend AWS automation with external data and workflows
  • Lab 3.4: Continuous Security Testing Enhanced with AI: Implement GenAI-powered security control validation
  • Lab 3.5: Kubernetes Takedown with Offensive AI Agents: Deploy AI-driven attack agents to simulate Kubernetes threats

Full Topics Details

  • Cloud Security Fundamentals
    • Core cloud security architecture and detection capabilities
    • Securing hybrid and multi-cloud environments with automation
  • Azure Policy and Blue Printing
    • Governance-as-code using Azure Policy and Blueprints
    • Infrastructure as code with cloud templates stacks
    • Enforcing compliance and deploying secure baseline configurations
  • Security Monitoring and Automation in Azure
    • Using cloud-native logs, detection tools, and Sentinel
    • Building automated detection and response workflows
  • SOAR Azure Logic Apps & Functions
    • Orchestrating SOC response workflows with native Azure services
    • Automated workflows using Azure Logic Apps and Functions
  • Intelligent Automation with Microsoft AI Services
    • GenAI-powered SOC enhancements for incident investigation
    • Azure AI Foundry and agentic AI
    • Enrichment and decision support with Microsoft AI and Copilot
  • AWS Config and Infrastructure Governance
    • Continuous configuration monitoring and compliance enforcement
    • Policy-as-code using AWS Config rules and remediations
  • Security Monitoring and Automation within AWS
    • AWS Security Toolset
    • Automating detection and response within AWS
  • AWS Lambda and Step Functions
    • Serverless orchestration for security automation pipelines
    • Event-driven workflows for threat detection and response
  • Intelligent Automation with AWS Bedrock
    • Leveraging LLMs for threat detection and analysis in AWS
    • Building AI-enhanced investigative workflows
  • Offensive AWS Agents: Attacking Kubernetes
    • Using AI-driven agents to simulate attacks
    • Testing defensive readiness and validating detection pipelines

Section 4Red Team Automation & Offensive AI Agents

This section explores offensive automation using AI-powered red team agents, adversary emulation frameworks, and CI/CD-driven continuous testing. Students will learn to leverage MITRE ATT&CK, automate multi-step attack flows, simulate autonomous adversaries, and validate cloud detection capabilities using AI-augmented offensive techniques.

Topics covered

  • Adversary emulation & purple teaming methodologies
  • MITRE ATT&CK-driven offensive frameworks
  • AI-powered red team agents & autonomous adversaries
  • Cloud-native adversary emulation and detection validation
  • Continuous adversary simulation integrated into CI/CD pipelines

Labs

  • Fully Automate Adversary Techniques with Atomic
  • Using Caldera to Run a Breach Exercise
  • Red Team Agents with CrewAI
  • Cloud Adversary Simulation with Automated Detections
  • Adversary Emulation as Code using Tines

Overview

This section builds a practical skillset for automating offensive security operations and continuously validating defenses. Starting with Introduction to Adversary Emulation & Purple Teaming, students learn how collaborative offensive and defensive testing increases SOC maturity and detection resilience.

Offensive Frameworks & the Power of MITRE ATT&CK demonstrates how ATT&CK provides a structured foundation for adversary emulation, detection mapping, and capability measurement. Adversary Emulation Tooling focuses on operationalizing common frameworks like Atomic Red Team and Caldera to create repeatable and scalable attack simulations.

Technique Chaining with Atomic extends this approach to simulate realistic kill chain scenarios, and Breach and Attack Simulation Tools demonstrate how modern BAS platforms provide continuous and production-safe control validation. The section progresses to Autonomous Adversaries and AI-Powered Attacks, where students learn how attackers are leveraging generative AI for adaptive attacks.

In agentic AI Frameworks: Red Team Agents, students develop CrewAI-based agents capable of autonomous decision-making and execution. Cloud Adversary Emulation focuses on AI-driven offensive operations in cloud-native environments, testing hybrid detections. The final module, Continuous Adversary Emulation via CI/CD, integrates offensive testing into DevSecOps pipelines to create persistent and automated purple teaming feedback loops.

Full Lab Details

  • Lab 4.1: Fully Automate Adversary Techniques with Atomic: Build and chain ATT&CK techniques into automated, repeatable attack flows
  • Lab 4.2: Using Caldera to Run a Breach Exercise: Execute and orchestrate breach simulation exercises to evaluate SOC detection and response
  • Lab 4.3: Red Team Agents with CrewAI: Design and deploy AI-powered red team agents for autonomous offensive testing
  • Lab 4.4: Cloud Adversary Simulation with Automated Detections: Launch automated cloud-native attacks to validate detection pipelines
  • Lab 4.5: Adversary Emulation as Code using Tines: Embed adversary emulation into CI/CD for continuous testing and validation

Full Topics Details

  • Introduction to Adversary Emulation & Purple Teaming
    • Fundamentals of adversary emulation and collaborative purple teaming
    • Building continuous improvement loops between offensive and defensive teams
  • Offensive Frameworks & the Power of MITRE ATT&CK
    • Using ATT&CK as a common language for emulation and detection mapping
    • Prioritizing emulation activities based on threat intelligence
  • Adversary Emulation Tooling
    • Overview of Atomic Red Team, Caldera, and BAS platforms
    • Creating repeatable emulation campaigns
  • Technique Chaining with Atomic
    • Automating complex multi-stage attack paths
  • Building modular, reusable offensive playbooks
  • Breach and Attack Simulation Tools
    • Continuous validation of detection and response pipelines
    • Leveraging BAS for production-safe testing
  • Autonomous Adversaries and AI-Powered Attacks
    • Using AI to enhance offensive operations
    • Examples of generative AI-driven attack automation
  • Agentic AI Frameworks: Red Team Agents
    • Building CrewAI agents for autonomous offensive actions
    • Enhancing offensive simulation with AI reasoning and tool integration
  • Cloud Adversary Emulation
    • Simulating attacks on cloud-native platforms and workloads
    • Testing cloud detection engineering against modern threats
  • Continuous Adversary Emulation via CI/CD
    • Automating adversary simulation within DevSecOps pipelines
    • Building always-on purple teaming practices

Section 5Defensive Automation & AI-Augmented Response

Learn to operate automation and AI to strengthen your SOC. This section focuses on defensible architecture, detection-as-code, modular incident response playbooks, and AI-driven workflows. Students will also explore how to counter adversarial automation with AI-augmented defenses and continuous purple teaming.

Topics covered

  • Modern SOC evolution and automation priorities
  • Defensible architectures with embedded automation
  • Modular incident response and SOAR workflows
  • AI-infused detection-as-code pipelines
  • Countering adversarial automation with defensive automation

Labs

  • Automated Triage and Analysis with Velociraptor and Timesketch
  • Create an Incident Response Playbook in PowerShell
  • Create an Incident Response Playbook in Tines
  • Detection as Code II: LLM-Assisted Detection Testing
  • Create an Adversary Emulation & Detection Playbook

Overview

This section explores how to transform defensive security operations using automation and AI. Introduction to the Modern SOC highlights the evolution of SOC operations and the growing need for automated triage, detection, and response workflows. Automation Priorities in Defensive Security provides a framework for identifying high-value automation opportunities.

Defensible Architectures with Automation focuses on building resilient SOC environments with security automation as a core component, while Detection Engineering and Incident Response demonstrate how detection-as-code and rapid incident handling improve response speed and quality. How to Apply SOAR and SOEL teaches the design of end-to-end security automation pipelines aligned to operational and business processes.

The section also introduces Incident Response Automation Phases and Building Modular Incident Response Playbooks, enabling teams to design reusable, scalable playbooks. AI-infused Detection as Code covers how LLMs accelerate detection engineering pipelines, and operationalizing agentic AI in the SOC demonstrates how autonomous agents can execute enrichment, triage, and decision-support tasks. Finally, Automated Defense vs. Adversarial Automation explores strategies to combat AI-powered adversaries through continuous purple teaming and adaptive response.

Full Lab Details

  • Lab 5.1: Automated Triage and Analysis with Velociraptor and Timesketch: Automate forensic triage and timeline analysis workflows.
  • Lab 5.2: Create an Incident Response Playbook in PowerShell: Build IR automation using native PowerShell workflows.
  • Lab 5.3: Create an Incident Response Playbook in Tines: Implement modular IR workflows using a cloud-native automation platform.
  • Lab 5.4: Detection as Code II: LLM-Assisted Detection Testing: Use LLMs to generate and validate detection logic in CI/CD pipelines.
  • Lab 5.5: Create an Adversary Emulation & Detection Playbook: Combine offensive simulation with automated defensive response.

Full Topics Details

  • Introduction to the Modern SOC
    • SOC evolution and intelligence-driven automation
    • Overcoming alert fatigue and skill shortages
  • Automation Priorities in Defensive Security
    • Identifying high-impact automation targets
    • Aligning automation to mission objectives
  • Defensible Architectures with Automation
    • Designing resilient SOC architectures
    • Embedding automation for scalable operations
  • Detection Engineering and Incident Response
    • Implementing detection-as-code pipelines
    • Connecting detection to automated IR workflows
  • How to Apply SOAR and SOEL
    • Building end-to-end incident response workflows
    • Aligning automation with business processes
  • Incident Response Automation Phases
    • Automating enrichment, triage, containment, and recovery
    • Leveraging orchestration for rapid response
  • Building Modular Incident Response Playbooks
    • Creating modular, reusable playbooks
    • Designing nested workflows for complex scenarios
  • AI-infused Detection as Code
    • Accelerating rule generation with LLMs
    • Integrating AI logic into CI/CD detection pipelines
  • Operationalizing agentic AI in the SOC
    • Building autonomous AI-driven SOC agents
    • Multi-agent collaboration for triage and decision support
  • Automated Defense vs. Adversarial Automation
    • Countering AI-enabled adversaries
    • Leveraging continuous purple teaming for resilience

Section 6Security Automation Capstone

The capstone is a full day of challenging hands-on work applying the principles taught throughout the course. Your team will progress through multiple levels and missions designed to ensure the presence of detection and defensive capabilities.

Full Topic Details

  • Applying Previously Covered Security Controls In-depth
  • Applying and fine-tuning detection capabilities and using automation to reduce false/positive ratio
  • Configuration management tools
  • Infrastructure as code templates
  • Tines playbook development
  • AWS Configuration rules & ARM templates

Things You Need To Know

Important! Bring your own system configured according to these instructions!

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.

As the course leverages the SANS OnDemand platform, the labs will be browser-based. The sections below outline the key requirements for optimal lab experiences.

Operating System

Students must bring a laptop to class running any of the following OS families:

  • Host Operating System: Latest version of Windows 10, macOS 10.15.x or later, or Linux. It is necessary to fully update your host operating system prior to the class to ensure you have the right drivers and patches installed to utilize the latest USB 3.0 devices. Those who use a Linux host must also be able to access exFAT partitions using the appropriate kernel or FUSE modules.
  • Note: Apple Silicon devices cannot perform the necessary virtualization and cannot be used for this course.
  • For troubleshooting reasons, please ensure you have local administrator privileges on your laptop

Browser

An up-to-date version of the following browser families is supported:

  • Microsoft Edge
  • Google Chrome
  • Mozilla Firefox

Hardware

  • x86-compatible or x64-compatible 2.0 GHz CPU minimum or higher
  • 4 GB RAM minimum with 8 GB or higher recommended
  • A wireless network adapter
  • 10 GB available hard-drive space

During the course, you will be connecting to a network filled with security experts! As a best practice, do not have any sensitive data stored on the system. SANS is not responsible for your system if someone in the class attacks it during the course.

By bringing the right equipment and preparing in advance, you can maximize what you will see and learn, as well as have a lot of fun.

Your course media will now be delivered via download. The media files for class can be large, some in the 40 - 50 GB range. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as you get the link. You will need your course media immediately on the first day of class. Waiting until the night before the class starts to begin your download has a high probability of failure.

SANS has begun providing printed materials in PDF form. Additionally, certain classes are using an electronic workbook in addition to the PDFs. The number of classes using eWorkbooks will grow quickly. In this new environment, we have found that a second monitor and/or a tablet device can be useful by keeping the class materials visible while the instructor is presenting or while you are working on lab exercises.

If you have additional questions about the laptop specifications, please contact customer service.

This course is ideal for both offense-focused and defense-focused security practitioners. The course is designed for SOC analysts, detection engineers, automation engineers, incident responders, and security engineers eager to adopt detection-as-code, integrate AI-driven logic creation, and enhance enrichment and response workflows.

Furthermore, our approaches are designed to support security architects, cloud engineers, red team operators, blue team members, purple team members, ethical hackers, and penetration testers who want to scale adversary emulation, create and structure detection pipelines, and apply automation augmented with GenAI at enterprise scale.

In general, the course applies to security practitioners looking to transform their skills to deliver more efficient and modernized and AI-infused security capabilities across hybrid and multi-cloud environments.

The GIAC AI Security Automation Engineer (GASAE) certification validates ability to apply practical, real-world automation and artificial intelligence across offensive, defensive and cloud security operations.  Certified professionals prove their proficiency in applying advanced tactics such as automated vulnerability discovery, AI driven attack simulations, host remediation, infrastructure automation workflows and SOAR driven incident response.

  • Automating asset discovery, configuration management and incident response workflows
  • Using automated offensive tools and adversary emulation to identify vulnerabilities
  • Deploying scripts and configurations to remediate Windows and Linux hosts
  • Applying AI concepts such as LLMs, RAG and agentic AI to detection and response
  • Building automation with scripting, Infrastructure as Code and collaborative red/blue team tools
  • Analyzing host artifacts and integrating automation into SOC operations
  • Implementing Azure and AWS security automation for monitoring and incident response
  • Using automated attack chaining and breach and attack platforms to assess defensive readiness

More Certification Details

  • Access to the in-class Virtual Training Lab for over 25 in-depth labs.
  • Virtual machine including automation tools, example Infrastructure as Code (IaC) templates for automation, Cyber Range tools, and offensive security testing tools.
  • Virtual machine including fourteen (14) perpetual use labs
  • Access to recorded course audio to help hammer home important automation techniques with offensive and defensive lessons.

At the moment, there aren’t any real prerequisites; however, you should have a basic understanding of cyber security, security architecture, limited PowerShell, Python, and cloud security experience.

SEC598 training is part of the Offensive Operations curriculum, which includes courses on penetration testing and focused offensive techniques. It’s part of a grouping of Purple Team courses that also includes SEC599: Defeating Advanced Adversaries – Purple Team Tactics & Kill Chain Defenses and SEC699: Advanced Purple Teaming – Adversary Emulation and Detection Engineering.

Security automation is the use of tools, code, and orchestration to detect, analyze, and respond to threats without manual intervention. It ensures consistent, scalable protection—especially vital in cloud-first and hybrid environments.

Security teams face increasing pressure: more threats, fewer people, and complex environments. Automation solves this by removing manual bottlenecks, accelerating response times, and minimizing errors. With SEC598 training, you’ll gain practical skills to build automation pipelines that defend at cloud speed—whether it’s triggering playbooks on suspicious activity, integrating threat intel, or auto-remediating vulnerabilities.

This is how defenders win at scale—by letting code carry the weight.

You’ll learn to automate both offensive and defensive tasks across hybrid and cloud environments, reducing manual workload and increasing your strategic value. These capabilities translate to faster job transitions, higher-impact roles, and leadership potential, especially as organizations seek professionals who can scale operations through code.

Pair this training with the GIAC Cloud Security Automation (GCSA) certification, and you signal to employers that you’re not just ready for today’s challenges—you’re built for the future of security.

Relevant Job Roles

Systems Administration (OPM 451)

NICE: Implementation and Operation

Responsible for setting up and maintaining a system or specific components of a system in adherence with organizational security policies and procedures. Includes hardware and software installation, configuration, and updates; user account management; backup and recovery management; and security control implementation.

Explore learning path

Systems Security Analysis (OPM 461)

NICE: Implementation and Operation

Responsible for developing and analyzing the integration, testing, operations, and maintenance of systems security. Prepares, performs, and manages the security aspects of implementing and operating a system.

Explore learning path

Purple Teamer

Offensive Operations

In this fairly recent job position, you have a keen understanding of both how cybersecurity defenses (“Blue Team”) work and how adversaries operate (“Red Team”). During your day-today activities, you will organize and automate emulation of adversary techniques, highlight possible new log sources and use cases that help increase the detection coverage of the SOC, and propose security controls to improve resilience against the techniques. You will also work to help coordinate effective communication between traditional defensive and offensive roles.

Explore learning path

Artificial Intelligence and Data Ethics (AIDE)

Skills Framework for the Information Age

Responsible design, development, and governance of AI and data-driven systems. Ethical principles are embedded into algorithms, models, and automated decision-making to ensure fairness, transparency, and accountability.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 20

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources