SEC536: Adversarial AI - Penetration Testing AI Systems

SEC598: AI and Security Automation for Red, Blue, and Purple Teams empowers you to elevate your security program across offensive and defensive domains. Whether you're automating adversary emulation campaigns, building intelligent response workflows, or engineering detection-as-code pipelines, this course teaches you to harness AI-driven automation to outpace modern threats.
You’ll develop the skills to operationalize AI, agentic automation, detection-as-code, and SOAR while integrating GenAI and LLMs into enrichment and response workflows, deploying secure cloud infrastructure, and emulating attack techniques.
These capabilities are brought to life through 25 immersive labs and practical frameworks that unify red and blue team functions into continuous purple teaming—enabling you to automate offensive testing, scale cloud-native detection, and build AI-powered playbooks for faster, smarter, and more resilient cybersecurity operations.
Today’s security operations centers (SOCs) face unprecedented challenges: overwhelming alert volumes, complex hybrid cloud environments, fragmented tooling, and increasingly AI-augmented adversaries. Many teams are overburdened, reactive, and struggling to keep pace with modern attack speed and complexity.
SEC598: AI and Security Automation for Red, Blue, and Purple Teams is built to tackle these challenges and accelerate your transformation journey. This course provides world-class approaches, practical frameworks, tools, and hands-on experience to build smarter, faster, and more resilient security operations, turning automation workflows, GenAI and agentic automation as force multipliers for both offensive and defensive teams.
This course doesn’t just teach concepts; it shows you how to implement them in enterprise-grade environments and what modernized security operations look like when fully operational. During the hands-on labs, you’ll work in GLOBEX Automation, a realistic hybrid enterprise environment adopting AI and spanning Azure, AWS, and on-premises infrastructure, designed to reflect the real challenges SOC teams and organizations face on a daily basis.
Through 25 immersive labs and bonus challenges, you will gain experience deploying automation playbooks, engineering detection-as-code pipelines, integrating GenAI and LLM-powered RAG for enrichment, building red team AI agents for continuous control validation, and designing AI-augmented defensive workflows to accelerate detection and response. You will also explore continuous purple teaming, closing the gap between offensive testing and defensive detection, and building modernized security capabilities that continuously improve SOC maturity.
By the end of the course, you will leave with ready-to-use automation playbooks, IaC templates, AI-driven workflows, and detection-as-code pipelines, everything needed to immediately uplift your own security program. You will gather experience with LLM-powered detection engineering, autonomous red team agents, automated response workflows, and practical frameworks for integrating AI and automation across your SOC.
SEC598 is not theoretical; it’s practical, immersive, and a built-for-action SANS course. From LLM-powered detection engineering to autonomous red team agents, from automated workflows to continuous purple teaming, this course empowers you to defend smarter, respond faster, and lead the next generation of AI-enabled security operations.
Over the past several years, my focus has been on applying automation and Generative AI within large and complex organizations to solve some of the bigger challenges and transforming isolated teams into a modern security operation. Together with course author Jason Ostrom, we decided to share not only our professional experiences but also the research, lessons, and solutions we have developed while leveraging GenAI, automation, and detection engineering for both offense and defense.
With SEC598, you will get these different perspectives to create a practical and unified approach for red and blue teams that addresses real-world problems such as fragmented tooling, alert overload, and increasingly AI-augmented adversaries.
I am very excited to release SEC598, which has a clear and in-depth focus on security automation leveraging GenAI to tackle the challenges we face daily. I am convinced that SEC598 gives you an in-depth understanding of automation concepts, technologies, and how to apply them for offense and defense. This course is your game-changer to begin your journey into continuous purple teaming!
– Jeroen Vandeleur
At the moment, there aren’t any real prerequisites; however, you should have a basic understanding of cyber security, security architecture, limited PowerShell, Python, and cloud security experience.
Important! Bring your own system configured according to these instructions!
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.
As the course leverages the SANS OnDemand platform, the labs will be browser-based. The sections below outline the key requirements for optimal lab experiences.
Operating System
Students must bring a laptop to class running any of the following OS families:
Browser
An up-to-date version of the following browser families is supported:
Hardware
During the course, you will be connecting to a network filled with security experts! As a best practice, do not have any sensitive data stored on the system. SANS is not responsible for your system if someone in the class attacks it during the course.
By bringing the right equipment and preparing in advance, you can maximize what you will see and learn, as well as have a lot of fun.
Your course media will now be delivered via download. The media files for class can be large, some in the 40 - 50 GB range. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as you get the link. You will need your course media immediately on the first day of class. Waiting until the night before the class starts to begin your download has a high probability of failure.
SANS has begun providing printed materials in PDF form. Additionally, certain classes are using an electronic workbook in addition to the PDFs. The number of classes using eWorkbooks will grow quickly. In this new environment, we have found that a second monitor and/or a tablet device can be useful by keeping the class materials visible while the instructor is presenting or while you are working on lab exercises.
If you have additional questions about the laptop specifications, please contact customer service.
Build the foundation for modern security automation by understanding why AI and automation matter now. Learn how to secure AI systems, leverage AI for security, and integrate automation strategies that scale across hybrid cloud environments and SOC operations.
This section establishes the strategic and technical foundation of the course. We explore why AI and automation have become essential to modern security operations and how they enable security teams to move from reactive to proactive, adaptive operations. You will learn how AI impacts security both defensively and offensively, and how automation frameworks can be applied across enterprise SOCs.
A major highlight of this section is the Globex Automation environment, which simulates hybrid cloud environments, SOC workflows, and automation infrastructure at scale. Students will implement Ansible for policy-as-code to manage configuration baselines, build CI/CD pipelines for detection-as-code, and create initial automation triggers to kickstart AI-driven workflows. In the last modules, SEC598 covers the foundations of detection-as-code, Generative AI, and LLMs to enhance your security capabilities.
This section focuses on practical automation workflows using PowerShell, Terraform, Ansible, Python, and Jupyter Notebook. Students will learn how to build secure infrastructure-as-code deployments, create automated firing ranges, engineer SOAR playbooks, and develop AI-driven agentic workflows for next-generation SOC operations.
Section 2 builds on foundational automation principles and applies them across multiple technologies commonly used in modern SOCs. Students start with PowerShell to automate baseline configuration and extend its application to both blue team hardening and red team simulation tasks. The module then moves to Infrastructure as Code (IaC) using Terraform, focusing on secure cloud provisioning and repeatable deployments that integrate easily into CI/CD pipelines.
To validate automation workflows, students will build firing ranges using Terraform and Ansible, enabling safe, repeatable testing of detection pipelines and security controls. Next, students leverage Python and Jupyter notebooks to build flexible security automation scripts for enrichment, analysis, and incident response, emphasizing modular and reusable code.
The section concludes with an exploration of SOAR tooling and agentic AI Engineering, demonstrating how to build and automate SOAR playbooks while integrating AI-powered reasoning agents that can autonomously investigate and respond to incidents, closing the gap between detection and response with human-in-the-loop controls.
This section covers cloud-native security automation across Microsoft Azure and AWS. You will learn to enforce security policies, automate response workflows, integrate AI services, and deploy offensive and defensive automation, including AI-driven Kubernetes attack simulation and continuous security testing with GenAI-powered agents.
Section 3 focuses on building, securing, and automating cloud operations. Students begin with cloud security fundamentals and move to Microsoft Azure, learning to implement Azure Policy and Blueprints to enforce governance and compliance through automation. Azure monitoring, SOAR orchestration with Logic Apps and Functions, and Microsoft AI services are introduced to enhance enrichment and automated decision-making.
For AWS, the section covers AWS Config, Security Hub, Lambda, and Step Functions to enable automated governance, incident response, and integration with third-party APIs. Students explore AWS Bedrock for AI-powered insights and implement continuous security testing using AI-driven automation pipelines.
Finally, students gain offensive perspectives by deploying AI-driven attack agents against Kubernetes environments, providing insights into cloud-native threat simulation and defense validation. This section bridges operational security and offensive simulation, delivering a complete view of how AI and automation are transforming cloud security operations.
This section explores offensive automation using AI-powered red team agents, adversary emulation frameworks, and CI/CD-driven continuous testing. Students will learn to leverage MITRE ATT&CK, automate multi-step attack flows, simulate autonomous adversaries, and validate cloud detection capabilities using AI-augmented offensive techniques.
This section builds a practical skillset for automating offensive security operations and continuously validating defenses. Starting with Introduction to Adversary Emulation & Purple Teaming, students learn how collaborative offensive and defensive testing increases SOC maturity and detection resilience.
Offensive Frameworks & the Power of MITRE ATT&CK demonstrates how ATT&CK provides a structured foundation for adversary emulation, detection mapping, and capability measurement. Adversary Emulation Tooling focuses on operationalizing common frameworks like Atomic Red Team and Caldera to create repeatable and scalable attack simulations.
Technique Chaining with Atomic extends this approach to simulate realistic kill chain scenarios, and Breach and Attack Simulation Tools demonstrate how modern BAS platforms provide continuous and production-safe control validation. The section progresses to Autonomous Adversaries and AI-Powered Attacks, where students learn how attackers are leveraging generative AI for adaptive attacks.
In agentic AI Frameworks: Red Team Agents, students develop CrewAI-based agents capable of autonomous decision-making and execution. Cloud Adversary Emulation focuses on AI-driven offensive operations in cloud-native environments, testing hybrid detections. The final module, Continuous Adversary Emulation via CI/CD, integrates offensive testing into DevSecOps pipelines to create persistent and automated purple teaming feedback loops.
Learn to operate automation and AI to strengthen your SOC. This section focuses on defensible architecture, detection-as-code, modular incident response playbooks, and AI-driven workflows. Students will also explore how to counter adversarial automation with AI-augmented defenses and continuous purple teaming.
This section explores how to transform defensive security operations using automation and AI. Introduction to the Modern SOC highlights the evolution of SOC operations and the growing need for automated triage, detection, and response workflows. Automation Priorities in Defensive Security provides a framework for identifying high-value automation opportunities.
Defensible Architectures with Automation focuses on building resilient SOC environments with security automation as a core component, while Detection Engineering and Incident Response demonstrate how detection-as-code and rapid incident handling improve response speed and quality. How to Apply SOAR and SOEL teaches the design of end-to-end security automation pipelines aligned to operational and business processes.
The section also introduces Incident Response Automation Phases and Building Modular Incident Response Playbooks, enabling teams to design reusable, scalable playbooks. AI-infused Detection as Code covers how LLMs accelerate detection engineering pipelines, and operationalizing agentic AI in the SOC demonstrates how autonomous agents can execute enrichment, triage, and decision-support tasks. Finally, Automated Defense vs. Adversarial Automation explores strategies to combat AI-powered adversaries through continuous purple teaming and adaptive response.
The capstone is a full day of challenging hands-on work applying the principles taught throughout the course. Your team will progress through multiple levels and missions designed to ensure the presence of detection and defensive capabilities.