SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.
Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.
Mandatory System Hardware Requirements
Additional requirements for this course:
Mandatory Host Configuration And Software Requirements
Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.
Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.
If you have additional questions about the laptop specifications, please contact customer service.
SEC699 training is recommended for a diverse range of individuals, including:
This is a fast-paced, advanced course that requires a strong desire to learn advanced red and blue team techniques. The following SANS courses are recommended either prior to or as a companion to taking this course:
Experience with programming in any language is highly recommended. At a minimum, students are advised to read up on basic programming concepts.
You should also be well versed with the fundamentals of penetration testing prior to taking this course. Familiarity with Linux and Windows is mandatory. A solid understanding of TCP/IP and networking concepts is required. Please contact the author at evanbuggenhout@nviso.be if you have any questions or concerns about the prerequisites.
SEC699 training is part of the Offensive Operations curriculum. It is considered Purple Team training, along with SEC598: AI and Security Automation for Red, Blue, and Purple Teams and SEC599: Defeating Advanced Adversaries – Purple Team Tactics & Kill Chain Defenses.
Purple team training is a collaborative cybersecurity approach that breaks down silos between red teams (attackers) and blue teams (defenders) to simulate real-world threats and improve detection and response capabilities. Rather than operating independently, both teams work together in live-fire exercises to test defenses and immediately fine-tune them based on observed adversary behavior. This training is essential because it accelerates the feedback loop, enhances defensive readiness, and builds stronger, more threat-informed detection strategies. SANS courses like SEC599 and SEC699 integrate purple team methodology to help professionals operationalize threat intelligence, validate controls, and build more resilient security operations.
SEC699: Purple Team Tactics – Adversary Emulation for Defenders is a career accelerator for cybersecurity professionals aiming to bridge offensive and defensive operations. This expert-level course builds deep technical expertise in emulating advanced adversary tactics and validating the effectiveness of enterprise defenses in real time. Whether you're a senior blue teamer, detection engineer, threat hunter, or transitioning from red team roles, SEC699 equips you with the skills and credibility to lead purple team initiatives, conduct threat-informed defense assessments, and drive measurable security outcomes. Graduates of SEC699 are often tapped for high-impact roles, including purple team leadership, adversary emulation programs, and cross-functional cybersecurity strategy.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources