Group Purchasing
Group Purchasing
AI-FOCUSED

SEC535: Offensive AI - Attack Tools and Techniques

SEC535Offensive Operations, Artificial Intelligence
  • 3 Days (Instructor-Led)
  • 18 Hours (Self-Paced)
Course authored by:
Foster Nethercott
Foster Nethercott
SEC535: Offensive AI - Attack Tools and Techniques
Course authored by:
Foster Nethercott
Foster Nethercott
  • GIAC Offensive AI Analyst (GOAA)
  • 18 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 14 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Leverage cutting-edge AI tools and techniques to enhance offensive operations, automate attacks, and advance your penetration testing capabilities.

Course Overview

Attackers are already using AI to push past traditional defenses. They automate reconnaissance, craft convincing social engineering campaigns, and even generate custom malware designed to bypass security controls. This course is built for security professionals who need to understand how offensive teams apply AI at every stage of an attack. Over three days, you’ll examine the same tools and techniques adversaries use to map networks, manipulate human targets, and build evasive payloads. Through labs based on real-world scenarios, you’ll see firsthand how these tactics unfold and learn to anticipate them. By studying offensive AI through the eyes of the attacker, you will build the insight and hands-on experience needed to outpace these evolving threats and protect what matters most when it counts

Preparing for AI-Enabled Cyber Threats

Today's threat landscape is no longer composed of traditional threats. AI-driven attacks have become a reality, and they have shattered the barrier to entry that was keeping so many unsophisticated threat actors at bay. Staying one step ahead of these AI-fueled adversaries hinges on your ability to adopt their tools, tactics, and techniques before they exploit those capabilities against your organization.

SEC535 equips you with practical offensive AI strategies, including bypassing security guardrails, automating reconnaissance, and delivering AI-driven malware. Through immersive labs, you will apply real-world TTPs like deepfake phishing and automated vulnerability discovery to simulate advanced attacks. By adopting the attacker’s mindset and mastering cutting-edge techniques, you will stay ahead of evolving threats and fortify your security posture.

Author Statement

“The cyberattack space is evolving, and so should the penetration testers. In this new era of AI-driven attacks it is critical that cybersecurity professionals from blue teams, red teams, and everything in between familiarize themselves with the tactics, techniques, and procedures of these new attackers. In SEC535: Offensive AI we will fully embrace the adversarial mindset as we dive into the dark psychological tricks of social engineering and evaluate how AI can be used to bolster them, as well as looking at automating reconnaissance techniques, using AI for exploit development and utilization, as well as the process of writing novel malware with AI. As a former SANS Institute MSISE program graduate I am proud to return to the SANS ecosystem to give back to an organization that gave so much to me. When I was a cybersecurity instructor previously, I had one simple motto: Knowledge is forged by action. This sentiment was embodied during my time at SANS, and I wanted to make sure I continued that legacy with this course by introducing a large number of labs, all culminating in a massive capture the flag event on the last day of class. I love this area of study, and I’m excited to share that passion and knowledge with all of you.”

- Foster Nethercott

What You'll Learn

  • Engineer AI-Powered Pentesting GPTs
  • Perform Patch Diffing with AI-Driven Analysis
  • Supercharge OSINT analysis with AI Automation
  • Weaponize AI for Social Engineering Attacks
  • Craft Custom AI Generated Malware
  • Design AI Optimized Exploits

Business Takeaways

  • Reduce organizational risk from AI-enabled cyber threats
  • Improve detection capabilities against novel attack vectors
  • Enhance security team readiness for emerging AI threats
  • Protect critical assets from advanced persistent threats
  • Strengthen compliance posture for AI security controls
  • Create robust security architecture resistant to AI attacks
  • Decrease incident response time for AI-powered attacks

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC535: Offensive AI - Attack Tools and Techniques.

Section 1Introduction to Offensive AI and Vulnerability Exploitation

Discover how threat actors leverage AI to gather intelligence and exploit vulnerabilities. Students explore advanced OSINT tools enhanced by machine learning, examine RAG-powered penetration testing workflows, and exploit vulnerabilities using AI.

Topics covered

  • Introduction to Artificial Intelligence
  • Introduction to AI Models and Capabilities
  • OSINT AI For Penetration Testers
  • Network Reconnaissance and Vulnerability Exploitation
  • Web Exploitation Using AI

Labs

  • AI-Powered Reconnaissance
  • Automated Nmap Output Analysis Using N8N and RAG
  • Metasploit Reengineered
  • AInjection: Using AI for SQL Exploits
  • AI Assisted Brute Force and Command Injection

Overview

The first day of SEC535 focuses on AI-driven reconnaissance and social engineering attacks, equipping you with the tools and techniques modern adversaries use to infiltrate organizations. We kick off with Open Source Intelligence (OSINT) gathering using AI, leveraging powerful tools like Spiderfoot and Bbot to uncover valuable intelligence such as DNS records, employee emails, and internal phone numbers at the notional company “Meridian Systems.” From there, we explore how an AI Pentest Assistant powered by a Retrieval-Augmented Generation (RAG) database can streamline network enumeration and optimize vulnerability discovery to enhance penetration testing workflows.

Armed with this intelligence, we will transition to exploiting the vulnerabilities using AI with Metasploit, and performing SQL Injection attacks.

Full Lab Details

  • AI-powered reconnaissance
  • Automated Nmap Output Analysis using N8N and RAG
  • Metasploit Reengineered
  • AInjection: Using AI for SQL Exploits
  • AI Assisted Brute Force and Command Injection

Full Topic Details

  • Introduction to Artificial Intelligence
    • RAG
    • Generative AI
    • Large Language Models
    • GAN
    • Vector Databases and Embeddings
    • AI Agents and Decision Loops
  • Introduction to AI Models and Capabilities
    • ChatGPT
    • Refining ChatGPT
    • Building Pentesting GPTs
    • Hugging Face
    • Custom Assistants
    • Building your own assistants
    • SOAR
    • N8N
    • Automating Offensive Workflows
  • OSINT AI for Penetration Testers
    • Identifying Key Targets
    • Using the Intelligence Cycle
    • Active vs Passive OSINT
    • What are Google Dorks, and Dorking with AI
    • Using Spiderfoot for Reconnaissance
    • Bbot Reimagined using AI
    • Augmenting tools with Subwiz
  • Network Reconnaissance and Enumeration using AI
    • AI Powered Network Enumeration
    • Automated Vulnerability Prioritization using RAG databases
    • Adaptive Scanning and AI – Driven Enumeration Strategies
    • Intelligent Data Correlation for Asset Discovery
    • Building ExploitGPT
  • Web Exploitation Using AI
    • Burp AI
    • Exploring the Issue, Explainer, and AI Powered Authentication
    • AI Augmented SQL Injection
    • Using AI to Write Custom Programs for Brute Forcing
    • Using AI for Command Injection

Section 2Social Engineering Attacks

In this section, we'll explore the art of developing convincing phishing content, as well as how to supplement it with both audio and video deepfake content. We will then finish the day by performing patch diffing with AI.

Topics covered

  • Introduction to Social Engineering
  • Creating AI-Powered Phishing Emails
  • Creating Audio Deepfakes
  • Creating Image and Video Deepfakes
  • Patch Diffing

Labs

  • Building PhishGPT
  • Lure Lab: Phishing Mini-Range
  • ElevenLabs Voice Cloning
  • AI Dialed Deception: Vishing Mini-Range
  • AI-Assisted Vulnerability Discovery and Patch Analysis

Overview

In this section, we explore how AI is transforming traditional social engineering and targeted exploitation. We start by examining the social engineering attack surface and the psychology behind manipulation, then build practical campaigns using tools like GoPhish and SET. You will develop and tune PhishGPT to generate tailored phishing emails, leverage sentiment analysis for profiling, and automate large-scale attacks through N8N workflows. Moving deeper, we uncover how attackers create convincing audio deepfakes with platforms like ElevenLabs and Voice.ai to enable advanced vishing scenarios. From there, we step into visual deepfakes, applying face swapping, motion transfer, and lip syncing to craft realistic video lures. Finally, we shift focus to vulnerability research with AI-assisted patch diffing. You will use tools such as DeepBinDiff and ChatGPT to identify silent patches, evaluate exploitability through zero-shot techniques, and refine prompts that accelerate finding new attack paths before they are widely known. Finally, we introduce AI-automated patch diffing, where AI-driven agents perform binary comparisons to detect security fixes, rank exploitability, and generate working exploits before vulnerabilities are publicly disclosed.

Full Lab Details

  • Building PhishGPT
  • Lure Lab: Phishing Mini-Range
  • ElevenLabs Voice Cloning
  • AI Dialed Deception: Vishing Mini-Range
  • AI-Assisted Vulnerability Discovery and Patch Analysis

Full Topic Details

  • Introduction to Social Engineering
    • Social Engineering Attack Surface
    • The Psychology of Social Engineering and Manipulation
    • Legal and Ethical Considerations
    • GoPhish
    • SET
    • Building Social Engineering Attack Plans
  • Creating AI Powered Phishing Emails
    • Why Hugging Face Assistants are Favored by Attackers
    • Tips for Writing System Prompts
    • Building PhishGPT
    • Sentiment Analysis and Psychological Profiling
    • Automating Phishing Emails with N8N
  • Creating Audio Deepfakes
    • Components of Speech
    • Types of Audio Deepfake Technology
    • How Attackers Leverage Audio Deepfakes
    • Voice.ai
    • ElevenLabs
  • Creating Visual Deepfakes
    • Face Swapping
    • Motion Transfer
    • Image to Image Translation
    • Lip Syncing and Audio Matching
    • Application of Visual Deepfakes
  • Patch Diffing
    • DeepBinDiff
    • ChatGPT and Patch Diffing
    • Silent Patches
    • Zero Shot Evaluations
    • Prompt Engineering for Patch Diffing
    • Phases of Patch Diffing

Section 3Malware Development and Security Control Evasion

Explore cutting-edge AI applications in malware engineering and defense evasion. Students learn how neural networks transform malware development, grasp how attackers circumvent AI safety guardrails, demonstrate sophisticated evasion techniques powered by machine learning, and examine living-off-the-land tactics enhanced through computational intelligence.

Topics covered

  • Fundamentals of Malware
  • Writing Malware with AI
  • Hiding, Obscuring, and Trojanizing Persistent Malware
  • Agentic Malware
  • Bypassing Security Controls

Labs

  • Introduction to Writing Malware with AI
  • Advanced Malware Writing
  • Bypassing Security Controls with AI

Overview

In this section, we examine how AI is reshaping the creation and deployment of modern malware. We begin by breaking down the fundamental components of malicious software and exploring how attackers build anti-analysis capabilities to evade detection. From there, you will use AI to develop custom malware, starting with generating proof-of-concept payloads and progressively layering in quality-of-life and stealth features. We also highlight curious, sometimes unpredictable behaviors that emerge when tools like ChatGPT assist in crafting malicious code. Moving forward, you will learn techniques for hiding, obscuring, and embedding persistent malware using alternate data streams, wrapped execution, dynamic attribute access, and encoding substitutions. You will automate obfuscation, implement WMI persistence, build malicious DLLs, and use AI to trojanize payloads. Finally, we cover advanced agentic malware, leveraging AI assistants and frameworks like GNAW to rewrite code in memory, deploy subordinate programs, and bypass security controls by disabling Defender, defeating tamper protection, and writing AMSI bypasses.

Full Lab Details

  • Introduction to Writing Malware with AI
  • Advanced Malware Writing
  • Bypassing Security Controls with AI

Full Topic Details

  • Fundamentals of Malware
    • Components
    • Anti-Analysis Capabilities
  • Creating Custom Malware with AI
    • Obtaining Proof-of-Concept
    • Quality of Life Features
    • Adding Stealth Features
    • Anomalous Behaviors from ChatGPT
  • Hiding, Obscuring, and Trojanizing Persistent Malware
    • ADS
    • Wrapped Execution
    • Dynamic Attribute Access
    • Encoding Substitution
    • Function Aliasing
    • Automating Obfuscation
    • WMI Persistence
    • Application Shimming
    • Writing DLLs with AI
    • Trojanizing a Payload with AI
  • Agentic Malware
    • AI Assistants and the Angry Beaver
    • GNAW
    • Dynamic System Prompts
    • Rewriting Code to Memory
    • Writing and Deploying Subordinate Programs
  • Bypassing Security Controls
    • Disabling Defender with AI
    • Windows Tamper Protection
    • Tamper Protection and AI Agents
    • Writing AMSI Bypasses with AI

Things You Need To Know

Important! Bring your own system configured according to these instructions!

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.

It is critical that you back-up your system before class. It is also strongly advised that you do not bring a system storing any sensitive data.

CPU

  • 64-bit Intel i5/i7 2.0+ GHz processor
  • CRITICAL NOTE: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot be used for this course.
  • Your system's processor must be a 64-bit Intel i5 or i7 2.0 GHz processor or higher. To verify on Windows 10 or 11, press Windows key + "I" to open Settings, then click "System", then "About". Your processor information will be listed near the bottom of the page. To verify on a Mac, click the Apple logo at the top left-hand corner of your display and then click "About this Mac".

BIOS

  • Enabled "Intel-VT"
  • Intel's VT (VT-x) hardware virtualization technology must be enabled in your system's BIOS or UEFI settings. You must be able to access your system's BIOS to enable this setting in order to complete lab exercises. If your BIOS is password-protected, you must have the password. This is absolutely required.

RAM

  • 16 GB RAM is highly recommended for the best experience. To verify on Windows 10, press Windows key + "I" to open Settings, then click "System", then "About". Your RAM information will be toward the bottom of the page. To verify on a Mac, click the Apple logo at the top left-hand corner of your display and then click "About this Mac".

Hard Drive Free Space

  • 100 GB of FREE space on the hard drive is critical to host the VMs and additional files we distribute. SSD drives are also highly recommended, as they allow virtual machines to run much faster than mechanical hard drives.

Operating System

  • Your system must be running either the latest version of Windows 10, macOS 10.15.x or later, or Linux that also can install and run VMware virtualization products described below.

Additional Software Requirements

VMware Player Install:

  • Download and install VMware Workstation Pro 17+ (for Windows hosts), or VMWare Fusion Pro 13+ (for macOS hosts) prior to class beginning. Workstation Pro and Fusion Pro are now available free for personal use from the VMware website. Licensed commercial subscriptions to these products can also be used.
  • Other virtualization products, such as Hyper-V and VirtualBox, are not supported and will not work with the course material.

Your course media will now be delivered via download. The media files for class can be large, some in the 40 - 50 GB range. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as you get the link. You will need your course media immediately on the first day of class. Waiting until the night before the class starts to begin your download has a high probability of failure.

If you have additional questions about the laptop specifications, please contact customer service.

SEC535 training is recommended for a diverse range of individuals, including:

  • Penetration Testers
  • Red Team Operators
  • Security Consultants
  • SoC Personnel
  • Security Architects
  • AI and Machine Learning Enthusiasts
  • Incident Responders
  • Security Engineers
  • Security Managers, Directors, and CISOs looking to broaden their knowledge in the current attack space

The GIAC Offensive AI Analyst (GOAA) certification validates ability to apply practical, real-world offensive artificial intelligence techniques to modern cybersecurity challenges. Certified professionals prove their proficiency in applying advanced tactics such as deepfake-enabled phishing, automated vulnerability discovery, and AI-driven attack simulations to emulate sophisticated adversaries.

  • AI-powered reconnaissance & OSINT automation
  • AI-aided vulnerability discovery, patch diffing, and exploit generation
  • Malware development with AI
  • Bypassing security controls and guardrails
  • Designing and deploying AI-driven phishing
  • Legal, ethical, and OPSEC considerations

  • Unlimited access to several hands-on lab exercises that never expire
  • Printed and electronic course books and a hands-on workbook
  • MP3 audio files of the entire course
  • Detailed video walkthroughs for all lab exercises
  • Visual association maps to break down complex material
  • A digital index for quick reference to all material
  • Bonus content and hands-on exercises to develop your skills beyond the course
  • Essential cheat sheets for tools and complex analysis tasks

Students should have a solid foundation in cybersecurity principles, familiarity with enterprise security architecture, and a basic understanding of AI/ML concepts. Experience with Python programming is beneficial but not required.

AI security encompasses the strategies, tools, and techniques needed to protect against threats that leverage artificial intelligence capabilities while ensuring the security of AI systems themselves. This course focuses on defensive approaches against offensive AI tools used by adversaries.

This course will position you as a specialist in AI security defense, a rapidly growing field with high demand. You will gain practical skills in detecting and countering AI-powered attacks, making you valuable to organizations facing sophisticated threats.

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 15

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources