SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions!
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.
As the course leverages the SANS OnDemand platform, the labs will be browser-based. The sections below outline the key requirements for optimal lab experiences.
Operating System
Students must bring a laptop to class running any of the following OS families:
Browser
An up-to-date version of the following browser families is supported:
Hardware
During the course, you will be connecting to a network filled with security experts! As a best practice, do not have any sensitive data stored on the system. SANS is not responsible for your system if someone in the class attacks it during the course.
By bringing the right equipment and preparing in advance, you can maximize what you will see and learn, as well as have a lot of fun.
Your course media will now be delivered via download. The media files for class can be large, some in the 40 - 50 GB range. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as you get the link. You will need your course media immediately on the first day of class. Waiting until the night before the class starts to begin your download has a high probability of failure.
SANS has begun providing printed materials in PDF form. Additionally, certain classes are using an electronic workbook in addition to the PDFs. The number of classes using eWorkbooks will grow quickly. In this new environment, we have found that a second monitor and/or a tablet device can be useful by keeping the class materials visible while the instructor is presenting or while you are working on lab exercises.
If you have additional questions about the laptop specifications, please contact customer service.
This course is ideal for both offense-focused and defense-focused security practitioners. The course is designed for SOC analysts, detection engineers, automation engineers, incident responders, and security engineers eager to adopt detection-as-code, integrate AI-driven logic creation, and enhance enrichment and response workflows.
Furthermore, our approaches are designed to support security architects, cloud engineers, red team operators, blue team members, purple team members, ethical hackers, and penetration testers who want to scale adversary emulation, create and structure detection pipelines, and apply automation augmented with GenAI at enterprise scale.
In general, the course applies to security practitioners looking to transform their skills to deliver more efficient and modernized and AI-infused security capabilities across hybrid and multi-cloud environments.
The GIAC AI Security Automation Engineer (GASAE) certification validates ability to apply practical, real-world automation and artificial intelligence across offensive, defensive and cloud security operations. Certified professionals prove their proficiency in applying advanced tactics such as automated vulnerability discovery, AI driven attack simulations, host remediation, infrastructure automation workflows and SOAR driven incident response.
At the moment, there aren’t any real prerequisites; however, you should have a basic understanding of cyber security, security architecture, limited PowerShell, Python, and cloud security experience.
SEC598 training is part of the Offensive Operations curriculum, which includes courses on penetration testing and focused offensive techniques. It’s part of a grouping of Purple Team courses that also includes SEC599: Defeating Advanced Adversaries – Purple Team Tactics & Kill Chain Defenses and SEC699: Advanced Purple Teaming – Adversary Emulation and Detection Engineering.
Security automation is the use of tools, code, and orchestration to detect, analyze, and respond to threats without manual intervention. It ensures consistent, scalable protection—especially vital in cloud-first and hybrid environments.
Security teams face increasing pressure: more threats, fewer people, and complex environments. Automation solves this by removing manual bottlenecks, accelerating response times, and minimizing errors. With SEC598 training, you’ll gain practical skills to build automation pipelines that defend at cloud speed—whether it’s triggering playbooks on suspicious activity, integrating threat intel, or auto-remediating vulnerabilities.
This is how defenders win at scale—by letting code carry the weight.
You’ll learn to automate both offensive and defensive tasks across hybrid and cloud environments, reducing manual workload and increasing your strategic value. These capabilities translate to faster job transitions, higher-impact roles, and leadership potential, especially as organizations seek professionals who can scale operations through code.
Pair this training with the GIAC Cloud Security Automation (GCSA) certification, and you signal to employers that you’re not just ready for today’s challenges—you’re built for the future of security.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources