SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Earn 30 CPEs.
Course material is geared for cybersecurity professionals with hands-on experience.
Apply what you learn with hands-on exercises and labs.
Security operations does not have a data problem. It has an analysis problem. The logs are already flowing; the question is whether anything in them would tell you an attack was underway.
SEC555 is five days of live, virtual instruction on building detections that answer that question. You construct your own detection lab, learn to read logs for what they actually contain, write rules that fire on the behavior you meant to catch, and build a pipeline that gets new content into production without a six-week wait. Cloud and on-premises sources are treated as one problem, because that is how they arrive.
The final section covers automated detection engineering pipelines, CI/CD workflows for detection content, and using large language models to assist rule authoring without handing over the judgment. 30 CPE credits, aligned to the GIAC Certified Detection Analyst (GCDA) certification.
Detection engineers and detection analysts, SOC and security analysts, security engineers, threat hunters, incident responders, and security architects who own monitoring coverage. A working understanding of TCP/IP, logging methods, and operating system fundamentals is the baseline.
SEC555 teaches excellent, pertinent information along with practical, easy-to-follow lab exercises. A tremendously valuable course!
This course uses real-world events and hands-on training to allow me to immediately improve my organization’s security stance. Day one back in the office I was implementing what I learned.
The course content is simply incredible, and I will likely be referencing it for years to come! Also, the provided VM is top notch. The labs were really informative.
Overall, this course taught me so much about using a SIEM. I had limited knowledge and skill on using our Security Onion setup, but this course helped developed them with the techniques and concepts taught. It also told me about tools I didn't know we had in our setup. Everyone I work with is rather new to the defensive cybersecurity realm, so there's been a lot to learn.
To learn more about SEC555, business takeaways, laptop requirements and more, please visit the course page.
Save $750 USD using the code "EarlyBirdNA" and pay for any 4-6 day course (excluding Beta Courses and 300 Level Courses) by October 20, 2026.
Looking for Group Purchasing? Contact Sales
2 Free practice tests when you add a certification exam attempt to your course. Available for select courses below.
Add OnDemand Extended Access for 120 days to help you prepare for your GIAC exam. Available for select courses below.


Nick Mitropoulos is a SANS Certified Instructor and author of SEC555: Detection Engineering and SIEM Analytics. As CEO of Scarlet Dragonfly and a veteran of SOC and incident response leadership, he equips students with real-world skills in detection engineering. Nick also serves on the GIAC Advisory Board, SANS CISO Network, and faculty of the SANS Technology Institute.
Read more about Nick MitropoulosEliminate the hassle of daily commutes and wasted travel time. You’ll have everything you need right from your home.
Hands-on learning with the opportunity to ask questions and receive instant feedback from world-renowned experts. Afterward, reinforce your skills with 4-months of access to daily course lecture archives.
Learn cutting-edge cybersecurity knowledge with hands-on labs that provide you with techniques you can immediately use in your organization.

