SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Earn 36 CPEs.
Course material is geared for cybersecurity professionals with hands-on experience.
Apply what you learn with hands-on exercises and labs.
Learning how an attack works is the easy half. Knowing which control would have stopped it, and whether that control survives contact with a competent adversary, is the part most teams skip.
SEC599 spends six days of live, virtual instruction on exactly that. You compromise a fictional organization on day one, so the rest of the week has stakes, then work forward through the attack chain implementing and testing the controls that break each stage. The labs run in a browser-based environment, so nobody spends the first morning fighting a hypervisor, and the student virtual machines come with you afterward.
Course authors Erik Van Buggenhout and Stephen Sims wrote SEC599 after years of teaching offense to students who turned out to be defenders. The result splits roughly half prevention, a third detection, and the remainder attack emulation. 36 CPE credits, aligned to the GIAC Defending Advanced Threats (GDAT) certification.
Security architects and engineers who want to know whether their controls change adversary behavior, SOC analysts and engineers focused on detection, red teamers curious about what stops them, and technical security managers deciding which controls to fund first. Comfort with Windows and Linux command lines, Active Directory, and TCP/IP is assumed.
The labs are incredibly effective for understanding and applying the concepts. I'm amazed by the complexity of the architecture, and it's clear how much work went into achieving the course objectives. A huge congratulations to everyone who built these complex infrastructures, which so realistically simulate real-world scenarios, allowing us to practice and experience firsthand how to apply what we've learned throughout the course.
I highly recommend this course to any cybersecurity professional. It doesn't just teach you how to configure security controls like AppLocker, AMSI, or YARA; it forces you to understand how attackers bypass them and how defenders can detect those bypass attempts through rigorous log analysis and troubleshooting.
To learn more about SEC599, business takeaways, laptop requirements and more, please visit the course page.
Save $750 USD using the code "EarlyBirdNA" and pay for any 4-6 day course (excluding Beta Courses and 300 Level Courses) by October 20, 2026.
Looking for Group Purchasing? Contact Sales
2 Free practice tests when you add a certification exam attempt to your course. Available for select courses below.
Add OnDemand Extended Access for 120 days to help you prepare for your GIAC exam. Available for select courses below.


Bryce Galbraith brings decades of real-world cybersecurity experience to SANS, teaching professionals how to emulate, detect, and defend against advanced adversaries through hands-on training.
Read more about Bryce GalbraithEliminate the hassle of daily commutes and wasted travel time. You’ll have everything you need right from your home.
Hands-on learning with the opportunity to ask questions and receive instant feedback from world-renowned experts. Afterward, reinforce your skills with 4-months of access to daily course lecture archives.
Learn cutting-edge cybersecurity knowledge with hands-on labs that provide you with techniques you can immediately use in your organization.

