SEC536: Adversarial AI - Penetration Testing AI Systems

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system that meets all the specified requirements.
Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.
Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 10 minutes or more to complete these instructions.
Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.
If you have questions about the laptop specifications, please contact customer service.
SEC588 is appropriate for:
The GIAC Cloud Penetration Tester (GCPN) certification validates a practitioner's ability to conduct cloud-focused penetration testing and assess the security of systems, networks, architecture, and cloud technologies.
SEC588 was written as a Venn Diagram between Network-based Penetration Testing, Web Applications Penetration Testing, and a Site Reliability Engineer (SRE). Having a base knowledge in any of those disciplines will ensure an easier transition for those in the course.
This course has many labs that are run from the command line, so students must come prepared with the following base level of knowledge:
Courses that can lead up to SEC588 include any of the following:
SEC588 training is part of the Specialized Offensive Operations Learning Path, which equips professionals with advanced skills in cloud-specific penetration testing and adversary simulation. This path is designed for those focused on leveraging modern cloud infrastructure environments, such as AWS and Azure, by utilizing containerized applications, serverless functions, Identity and access management, cloud-native applications, and deployment pipelines. SEC588 is also aligned with the Cloud Security Specialization Path, enabling learners to adapt traditional penetration testing expertise to cloud-native technologies and infrastructure, with an emphasis on identifying business risk in shared-hosting and cloud-first environments.
Cloud penetration testing involves simulating a cyberattack on cloud-based environments—such as AWS, Azure, or Google Cloud—to identify vulnerabilities, misconfigurations, and security gaps before malicious attackers can exploit them. As organizations rapidly shift to the cloud, traditional security testing falls short. Cloud pen testing is crucial for identifying vulnerabilities in cloud-native technologies, including Kubernetes, containers, serverless functions, and identity and access management (IAM) services. By proactively testing cloud security, organizations can strengthen their defenses, ensure regulatory compliance, and protect sensitive data in highly dynamic cloud infrastructures.
SEC588: Cloud Penetration Testing equips you with cutting-edge skills that are in high demand across the cybersecurity industry. You will learn how to conduct real-world cloud security assessments on platforms like AWS and Azure, attacking IdP infrastructure such as Entra ID, master modern attack techniques, and gain hands-on experience with container security, serverless functions, and cloud IAM abuse. Completing this course positions you as a go-to expert in cloud security and offensive operations, boosts your resume with the GCPN certification, and opens doors to roles such as cloud security analyst, penetration tester, red team operator, and DevSecOps engineer.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources