SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.
Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.
Mandatory System Hardware Requirements
Mandatory Host Configuration And Software Requirements
Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.
Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.
Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.
If you have additional questions about the laptop specifications, please contact customer service.
SEC522 training is recommended for a diverse range of individuals, including:
The GIAC Web Application Defender (GWEB) certification allows candidates to demonstrate mastery of the security knowledge and skills needed to deal with common web application errors that lead to most security problems. The successful candidate will have hands-on experience using current tools to detect and prevent input validation flaws, cross-site scripting (XSS), and SQL injection as well as an in-depth understanding of authentication, access control, and session management, their weaknesses, and how they are best defended. GWEB candidates have the knowledge, skills, and abilities to secure web applications and recognize and mitigate security weaknesses in existing web applications.
This class requires a basic understanding of web application technology and concepts such as HTML and JavaScript. To maximize the benefit for a wider range of audiences, the discussions in this course will be programming-language-agnostic. Attendees should have some understanding of concepts like databases (SQL) and scripting languages used in modern web applications.
SEC522: Application Security: Securing Web Applications, APIs, and Microservices is part of the Cloud Security Engineer Journey within the Cloud Security curriculum, focusing on defending the application layer in cloud-native environments. Alongside SEC510: Cloud Security Controls and Mitigations and SEC540: Cloud Native Security and DevSecOps Automation, it forms a flexible, hands-on path for engineers to build deep, end-to-end expertise in securing infrastructure, code, and cloud workloads—empowering them to become adaptable defenders in today’s dynamic threat landscape.
Application security protects web applications and APIs from a variety of current cyber threats. It identifies and mitigates vulnerabilities. Key strategies include implementing a secure architecture, employing secure coding practices, protecting against attacks like SQL injection and cross-site scripting (XSS), and implementing proper access controls.
Application security is crucial because cyber threats are constantly evolving, and applications are a prime target for hackers. Vulnerabilities like SQL injection, cross-site scripting (XSS), and broken authentication can lead to data breaches, financial loss, and reputational damage. Strong security measures help prevent unauthorized access, protect sensitive user data, and ensure compliance with industry regulations.
Embedding security early in the development process reduces risk and maintains data integrity. Organizations must adopt proactive security strategies, such as regular vulnerability assessments, penetration testing, and the use of security frameworks, to minimize risks and maintain trust with users. A secure application safeguards both business assets and customer information.
SEC522: Application Security: Securing Web Apps, APIs, and Microservices gives you in-depth knowledge and hands-on skills to protect modern web applications, APIs, and microservices architectures. As businesses increasingly rely on cloud-based applications and microservices, securing these environments has become critical.
This course teaches you how to identify vulnerabilities, apply security best practices, and prevent common attacks like SQL injection, cross-site scripting, and API security risks.
In SEC522, you will learn to secure the software development lifecycle (SDLC), implement secure authentication and authorization mechanisms, and address complex security challenges in distributed systems. This expertise positions you as a valuable asset to organizations, boosting your career prospects in cybersecurity roles such as application security specialist, security engineer, or architect.
Starting with SANS Cloud Security Exchange Summit & Training 2026 in San Francisco, CA, US, SEC522 will be streamlined as a 5-day course. All sessions before this event will continue in the current 6-day format. Content previously delivered on Day 6, including the Defending the Flag Capstone Exercise, will be incorporated into Day 5, with tuition priced accordingly. The course page will be updated with the new 5-day syllabus following the final 6-day session at SANS Live Online Europe July 2026.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources