Group Purchasing
Group Purchasing

SEC560: Enterprise Penetration Testing

SEC560Offensive Operations
  • 6 Days (Instructor-Led)
  • 36 Hours (Self-Paced)
Course authored by:
Jeff McJunkinJon Gorenflo
Jeff McJunkin & Jon Gorenflo
SEC560: Enterprise Penetration Testing
Course authored by:
Jeff McJunkinJon Gorenflo
Jeff McJunkin & Jon Gorenflo
  • GIAC Penetration Tester (GPEN)
  • 36 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 30 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Learn enterprise-scale penetration testing; identify, exploit, and assess real business risks across on-prem, Azure, and Entra ID environments through hands-on labs and an intensive CTF.

Course Overview

SEC560 teaches students how to conduct comprehensive enterprise penetration tests that mirror real-world attacks. Starting with reconnaissance and scanning, students progress through gaining initial access, post-exploitation, privilege escalation, lateral movement, and maintaining persistence while evading detection.

The course emphasizes practical, hands-on techniques using industry-standard tools including Nmap, Metasploit, Sliver, BloodHound, Impacket, and Mimikatz. Students learn both on-premises Active Directory attacks and cloud-based Azure/Entra ID exploitation. Each section includes multiple labs reinforcing concepts through realistic scenarios against purpose-built vulnerable environments.

The course culminates in a Capture the Flag competition where students apply all learned techniques across multiple target networks, demonstrating mastery of the complete penetration testing lifecycle from initial foothold through domain dominance.

Comprehensive Enterprise Penetration Testing Training

SEC560: Enterprise Penetration Testing provides security professionals with the technical skills and strategic mindset necessary to conduct professional penetration tests against modern enterprise environments. This course goes far beyond basic vulnerability scanning, teaching students how real attackers compromise organizations and how penetration testers can safely replicate these techniques to identify security weaknesses before malicious actors exploit them.

The course emphasizes the complete penetration testing lifecycle, from pre-engagement planning and reconnaissance through exploitation, privilege escalation, lateral movement, persistence, and effective reporting. Students learn to think like attackers while maintaining the professionalism and ethical standards expected of security practitioners. Each phase of the penetration test receives thorough coverage with both theoretical foundations and extensive hands-on practice.

Modern penetration testing requires understanding both traditional on-premises infrastructure and cloud environments. SEC560 addresses this reality by covering Active Directory attacks extensively while also including comprehensive Azure and Entra ID exploitation techniques. Students learn to identify and exploit misconfigurations in Active Directory Certificate Services, abuse Kerberos authentication, perform pass-the-hash attacks, and achieve domain dominance through golden and silver ticket attacks.

The defensive perspective remains central throughout the course. Students learn not just how attacks work, but why they succeed and how organizations can detect and prevent them. This dual perspective makes SEC560 graduates valuable both as penetration testers identifying vulnerabilities and as defenders implementing effective security controls.

Real-world tooling forms the foundation of the hands-on labs. Students gain practical experience with Nmap and Masscan for network reconnaissance, Metasploit and Sliver for command and control, BloodHound for Active Directory attack path analysis, Impacket for Windows protocol exploitation, Hashcat for password cracking, and numerous other tools that professional penetration testers use daily. The labs use realistic scenarios and vulnerable systems that mirror actual enterprise environments.

The course structure builds skills progressively. Section 1 establishes fundamentals through a miniature engagement demonstrating the complete attack lifecycle, then covers reconnaissance and scanning techniques. Section 2 focuses on gaining initial access through password attacks, Azure exploitation, network sniffing, and exploitation frameworks. Section 3 addresses post-exploitation activities including credential harvesting, command and control, and privilege escalation. Section 4 covers Active Directory-specific attacks including Kerberoasting, Active Directory Certificate Services exploitation, and lateral movement. Section 5 addresses persistence mechanisms, defense evasion, domain dominance techniques, and Azure infrastructure exploitation. Section 6 provides a comprehensive Capture the Flag competition and guidance for continuing the penetration testing journey.

Author Statement

SEC560 represents decades of combined penetration testing experience from its author team. We've designed this course to bridge the gap between theoretical security knowledge and practical penetration testing skills. Every technique taught has been validated through real-world engagements, and the labs reflect actual vulnerabilities and misconfigurations we encounter in enterprise environments. Our goal is not just to teach you how to use tools, but to develop your penetration testing mindset—the ability to identify attack paths, chain vulnerabilities, and think creatively while maintaining ethical boundaries. By the end of this course, you'll have the practical skills and confidence to conduct professional penetration tests that provide real value to organizations seeking to improve their security posture.

— Jeff McJunkin and Jon Gorenflo

2025 Course Update Summary

The latest SEC560 update brings enterprise-scale penetration testing into the hybrid cloud age. This 2025 refresh modernizes the labs, content, and tooling to reflect how real adversaries operate across on-prem, Azure, and Entra ID environments.

For a detailed breakdown of what's new and how these updates can strengthen you or your team, download the flyer.

What You'll Learn

  • Gather intel with OSINT, DNS, and breach data to map targets and identify attack surfaces.
  • Exploit weak authentication via credential stuffing, spraying, and hash-based attacks.
  • Harvest creds, establish C2, and escalate privileges post-exploitation on Windows and Linux.
  • Attack Active Directory using Kerberoasting, BloodHound, and ADCS exploitation.
  • Move laterally with pass-the-hash, Impacket, SSH tunneling, and pivoting techniques.
  • Maintain persistence through tasks, services, and WMI while evading EDR and AV.
  • Gain domain dominance using DCSync, golden tickets, and Azure RBAC exploitation.

Business Takeaways

  • Run realistic pentests to find exploitable flaws before attackers can discover and exploit them.
  • Use real attacker tactics to guide security investments based on real-world threats, not theory.
  • Review MFA to uncover single-factor services that expose critical enterprise entry points.
  • Evaluate AD for privilege paths, misconfigurations, and Kerberos authentication weaknesses.
  • Test how fast defenders detect and respond to lateral movement and post-exploitation.
  • Stay compliant and show progress through regular pentests documenting security maturity.
  • Build internal pentest skills to cut reliance on consultants and strengthen in-house expertise.

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC560: Enterprise Penetration Testing.

Section 1Miniature Engagement, Recon, and Scanning

Section 1 begins with a credential stuffing attack to introduce the penetration testing mindset then guides students through infrastructure setup, Linux fundamentals, and pre-engagement planning. It dives into reconnaissance using OSINT to gather organizational intelligence, concluding with scanning via Masscan and Nmap to identify active hosts and services.

Topics covered

  • Penetration Testing Frameworks and Methodology
  • Infrastructure Setup and Linux Essentials
  • Pre-engagement and Rules of Engagement
  • OSINT and Reconnaissance Techniques
  • Port Scanning with Masscan and Nmap

Labs

  • Lab 1.1: Credential Stuffing to a Breach
  • Lab 1.2: Reconnaissance and OSINT
  • Lab 1.3: Masscan
  • Lab 1.4: Nmap

Overview

Section 1 establishes the foundation for effective enterprise penetration testing by demonstrating the complete attack lifecycle through a miniature engagement before diving deep into reconnaissance and scanning techniques.

Students begin by witnessing a full credential stuffing attack that achieves initial access, immediately experiencing the penetration testing mindset and understanding how individual techniques combine into successful compromises. The section then methodically builds essential skills in infrastructure setup, Linux command-line proficiency, and professional pre-engagement practices before exploring the critical reconnaissance phase. By learning to gather organizational intelligence, identify infrastructure, harvest breached credentials, and enumerate employees through OSINT, students understand how real attackers prepare for targeted attacks.

The section concludes with comprehensive scanning instruction covering both Masscan for rapid large-scale port discovery and Nmap for detailed service enumeration, providing the technical foundation necessary for identifying attack surfaces and potential entry points into target environments.

Full Lab Details

  • Lab 1.1: Credential Stuffing to a Breach
  • Lab 1.2: Reconnaissance and OSINT
  • Lab 1.3: Masscan
  • Lab 1.4: Nmap

Full Topic Details

  • Getting Started: This module establishes the foundational framework for enterprise penetration testing, introducing students to the essential mindset, concepts, and methodologies needed throughout the course.
  • Miniature Engagement: This module provides a concentrated yet comprehensive introduction to the entire penetration testing workflow through a practical, hands-on demonstration of a complete attack.
  • Building an Infrastructure: This module addresses the fundamental requirement for professional penetration testing by establishing robust, secure, and efficient testing environments for both operations and practice.
  • Linux for Penetration Testers: This module provides essential Linux command-line skills and security concepts necessary for effective penetration testing, focusing on privilege structures, file permissions, and system reconnaissance.
  • Pre-engagement: This module establishes the critical foundation for successful penetration testing through comprehensive planning, scoping, authorization procedures, and Rules of Engagement that ensure legal compliance and operational safety.
  • Reconnaissance Overview: This module establishes the critical foundation for effective penetration testing through systematic intelligence gathering and analysis using both passive and active reconnaissance techniques.
  • Scanning Goals, Types, and Tips: This module establishes the strategic framework for active network reconnaissance, transforming passive intelligence gathering into direct target interaction through carefully orchestrated scan types.
  • Port Scanning: This module provides deep technical understanding of how penetration testers systematically discover open services on target systems through protocol manipulation and response analysis of TCP and UDP communications.
  • Masscan: This module introduces a revolutionary approach to high-speed port scanning using stateless architecture that enables orders-of-magnitude performance improvements over traditional tools for large-scale network reconnaissance.
  • Nmap: This module explores the capabilities of the world's most widely used network reconnaissance tool, demonstrating how it has evolved from a simple port scanner into a comprehensive vulnerability assessment platform.

Section 2Scanning and Initial Access

Section 2 expands on Nmap’s advanced scanning with version and OS detection plus scripting for vulnerabilities. Students then explore initial access through password attacks, Azure and Entra ID spraying, and network exploits using Responder, Metasploit, and Meterpreter to gain and control compromised systems.

Topics covered

  • Nmap Version and OS Detection
  • Nmap Scripting Engine and Vulnerability Scanning
  • Password Guessing and Spraying Attacks
  • Azure and Entra ID Reconnaissance
  • Network Protocol Attacks with Responder

Labs

  • Lab 2.1: Version Scanning, OS Detection, NSE, and GoWitness
  • Lab 2.2: Password Guessing
  • Lab 2.3: Azure Recon and Password Spraying
  • Lab 2.4: Responder
  • Lab 2.5: Metasploit and Meterpreter

Overview

Section 2 transitions from reconnaissance and basic scanning to gaining initial access through multiple attack vectors that mirror real-world penetration tests.

The section begins by advancing Nmap skills through version detection, operating system fingerprinting, and the powerful Nmap Scripting Engine that automates vulnerability detection and detailed service enumeration. Students learn to leverage these scanning capabilities to identify exploitable services and misconfigurations. The section then systematically addresses initial access techniques, starting with password-based attacks including password spraying and targeted password guessing against SMB and SSH services. Cloud environments receive comprehensive coverage through Azure and Entra ID reconnaissance, username enumeration, and password spraying attacks that exploit single-factor authentication in Microsoft cloud services. Network-based attacks using Responder demonstrate how attackers capture and relay NTLM authentication to gain unauthorized access without valid credentials.

Finally, the Metasploit Framework provides hands-on experience with exploit modules, payload generation, and Meterpreter sessions that establish persistent command and control. By combining these techniques, students understand the multiple paths attackers use to breach perimeter defenses and establish initial footholds in target environments.

Full Lab Details

  • Lab 2.1: Version Scanning, OS Detection, NSE, and GoWitness
  • Lab 2.2: Password Guessing
  • Lab 2.3: Azure Recon and Password Spraying
  • Lab 2.4: Responder
  • Lab 2.5: Metasploit and Meterpreter

Full Topic Details

  • Nmap OS & Version Scanning
  • Netcat
  • GoWitness and EyeWitness
  • Vulnerability Scanning
  • Nmap Scripting Engine
  • Initial Access
  • Password Guessing
  • Azure Intro
  • Entra ID
  • Azure Recon
  • Azure Password Attacks
  • Sniffing and Relaying
  • Responder
  • Exploitation
  • Exploit Categories
  • Metasploit and Meterpreter

Section 3Post-Exploitation

Section 3 focuses on post-exploitation, teaching credential access with Mimikatz, Metasploit, and Hashcat. Students build C2 skills with Sliver, craft evasive payloads, and use tools like Seatbelt for situational awareness on Linux and Windows. The section ends with Windows privilege escalation techniques to gain admin access.

Topics covered

  • Credential Harvesting and Password Dumping
  • Offline Password Cracking with Hashcat
  • Command and Control with Sliver
  • Payload Generation and Delivery
  • Windows and Linux Situational Awareness

Labs

  • Lab 3.1: MSF psexec, hashdump, and Mimikatz
  • Lab 3.2: Hashcat
  • Lab 3.3: Sliver
  • Lab 3.4: Payloads
  • Lab 3.5: Seatbelt

Overview

Section 3 focuses on the critical post-exploitation phase where penetration testers must quickly establish situational awareness, harvest credentials, escalate privileges, and maintain access before defensive measures detect and respond to the intrusion.

The race between attacker progression and defender response begins immediately after initial access, making efficient post-exploitation techniques essential for successful penetration tests. Students learn to extract password hashes from compromised Windows systems using both Metasploit's built-in capabilities and the powerful Mimikatz tool that harvests plaintext passwords, Kerberos tickets, and NTLM hashes from memory. These credentials enable lateral movement and privilege escalation across the target environment. Offline password cracking with Hashcat transforms captured hashes into plaintext passwords through dictionary attacks, rule-based mutations, and brute force techniques, revealing password patterns that inform security recommendations.

Modern command and control requires understanding frameworks beyond Metasploit, so the Sliver C2 framework provides hands-on experience with contemporary red team tooling including implant generation, multiplayer capabilities, and advanced payload execution through techniques like execute-assembly. Payload generation and delivery receive comprehensive coverage, addressing how to create and deliver malicious payloads while evading antivirus and endpoint detection systems. Situational awareness forms the foundation for all subsequent actions, teaching students to enumerate system information, running processes, network connections, and security controls on both Windows and Linux systems, with the Seatbelt tool automating comprehensive Windows enumeration.

Finally, Windows privilege escalation techniques teach students to identify and exploit common misconfigurations including unquoted service paths, weak file permissions, vulnerable services, and insecure registry settings that enable standard users to execute code as SYSTEM, demonstrating why proper system hardening remains essential for enterprise security.

Full Lab Details

  • Lab 3.1: MSF psexec, hashdump, and Mimikatz
  • Lab 3.2: Hashcat
  • Lab 3.3: Sliver
  • Lab 3.4: Payloads
  • Lab 3.5: Seatbelt
  • Lab 3.6: Windows Privilege Escalation

Full Topic Details

  • Passwords and Credential Access
  • Password Representations
  • Obtaining Password Hashes
  • Hashcat
  • Assumed Breach
  • Command and Control (C2)
  • Sliver
  • Payloads
  • Post-Exploitation
  • Situational Awareness
  • Linux Situational Awareness
  • Windows Situational Awareness
  • Seatbelt
  • Privilege Escalation
  • Windows Privilege Escalation

Section 4Domain Privilege Escalation and Lateral Movement

Section 4 explores Kerberos and Kerberoasting to crack service accounts, plus BloodHound for attack path mapping and ADCS exploitation for privilege escalation. Students practice lateral movement using SSH, Impacket, and native tools, then perform Pass-the-Hash and pivoting with Metasploit and C2 frameworks.

Topics covered

  • Kerberos Authentication and Kerberoasting
  • BloodHound for Attack Path Analysis
  • Active Directory Certificate Services Exploitation
  • Lateral Movement from Windows and Linux
  • Impacket Toolkit Usage

Labs

  • Lab 4.1: Kerberoasting
  • Lab 4.2: BloodHound
  • Lab 4.3: Active Directory Certificate Services
  • Lab 4.4: Lateral Movement from Windows
  • Lab 4.5: Lateral Movement from Linux

Overview

Section 4 focuses on Active Directory-specific attacks that enable domain privilege escalation and lateral movement across enterprise networks. Understanding Kerberos authentication forms the foundation for these attacks, as Active Directory relies entirely on Kerberos for authentication in modern Windows environments. Students learn how Kerberos tickets work, how service principal names identify services, and critically, how the Kerberoasting attack exploits the protocol by requesting service tickets encrypted with service account passwords that can be cracked offline without alerting defenders.

BloodHound revolutionizes Active Directory attack planning by representing the directory as a graph database, revealing complex attack paths from compromised accounts to domain administrators that would be nearly impossible to identify manually. The tool analyzes permissions, group memberships, local administrator rights, and session information to map routes for privilege escalation and lateral movement. Active Directory Certificate Services introduces additional attack vectors through template misconfigurations, with detailed coverage of ESC1 (allowing certificate requests for arbitrary users), ESC4 (vulnerable certificate template permissions), and ESC8 (NTLM relay to web enrollment).

These attacks frequently provide paths to domain dominance even when other privilege escalation routes have been hardened. Lateral movement techniques receive comprehensive treatment for both Windows and Linux attack platforms, covering native Windows remote administration tools, SSH tunneling with local and dynamic port forwarding for accessing systems across network boundaries, and the powerful Impacket toolkit that implements Windows protocols in Python for remote command execution, file manipulation, and credential dumping without uploading traditional tools. Pass-the-Hash attacks enable credential reuse without cracking passwords, using captured NTLM hashes directly for authentication to access additional systems.

Finally, pivoting techniques using both Metasploit and modern C2 frameworks teach students to use compromised systems as stepping stones to reach otherwise inaccessible network segments, essential for demonstrating the full scope of potential compromise in network-segmented environments.

Full Lab Details

  • Lab 4.1: Kerberoasting
  • Lab 4.2: BloodHound
  • Lab 4.3: Active Directory Certificate Services
  • Lab 4.4: Lateral Movement from Windows
  • Lab 4.5: Lateral Movement from Linux
  • Lab 4.6: Impacket
  • Lab 4.7: C2 Pivoting and Pass-the-Hash

Full Topic Details

  • Kerberos
  • Kerberoasting
  • BloodHound
  • Active Directory Certificate Services (AD CS) and Attacks
  • Lateral Movement from Windows
  • Lateral Movement from Linux
  • Impacket
  • Pass-the-Hash
  • Pivoting
  • C2 Pivoting and Pass-the-Hash

Section 5Persistence and Evading Controls

Section 5 teaches persistence via registry edits, tasks, and WMI while evading AMSI and EDR defenses. Students learn professional reporting, advanced AD attacks like Pass-the-Ticket, DCSync, and Golden/Silver tickets, then shift to cloud exploits targeting Azure authentication, RBAC abuse, and managed identities.

Topics covered

  • Persistence Mechanisms and Techniques
  • Bypassing AMSI, AV/EDR, and Application Controls
  • Penetration Testing Reporting Best Practices
  • Advanced Kerberos and Domain Dominance Attacks
  • Golden and Silver Ticket Forgery

Labs

  • Lab 5.1: Persistence
  • Lab 5.2: MSBuild and Application Control Bypass
  • Lab 5.3: Domain Dominance
  • Lab 5.4: Golden Ticket
  • Lab 5.5: Silver Ticket

Overview

Section 5 addresses the advanced topics of maintaining persistence, evading detection, achieving domain dominance, and exploiting cloud infrastructure that distinguish sophisticated penetration tests from basic vulnerability assessments.

Persistence mechanisms receive comprehensive coverage, teaching students multiple techniques for surviving system reboots including registry run keys, scheduled tasks, Windows services, WMI event consumers, and startup folder manipulation. Understanding persistence helps both offensive teams maintain access during long-term engagements and defensive teams identify indicators of compromise during incident response.

Modern defensive technologies pose significant challenges for penetration testers, so this section addresses evasion techniques including bypassing the Antimalware Scan Interface (AMSI) that integrates with PowerShell, disabling Windows Defender through policy modifications, evading behavioral detection in endpoint detection and response products, and circumventing application control solutions like AppLocker by abusing trusted Windows binaries such as MSBuild to execute malicious code.

Professional reporting forms a critical component of penetration testing value delivery, so students learn effective reporting practices including executive summaries, technical finding documentation, risk assessment and prioritization, reproduction steps with evidence, and actionable remediation recommendations that enable organizations to improve their security posture based on test results.

Advanced Active Directory attacks enable domain dominance through techniques that extend beyond standard privilege escalation, including Pass-the-Ticket attacks that reuse stolen Kerberos tickets, Overpass-the-Hash (also called Pass-the-Key) that requests Kerberos tickets using NTLM hashes, DCSync attacks that impersonate domain controllers to replicate password hashes for all domain accounts, skeleton key attacks that patch domain controller authentication to allow a master password, and NTDS.dit extraction that steals the entire Active Directory database containing all domain credentials. Golden ticket attacks create forged Kerberos ticket-granting tickets with arbitrary privileges and extended lifetimes, granting long-term unrestricted domain access that survives password changes. Silver tickets create forged service tickets for specific resources, providing stealthy access to individual services without contacting the domain controller. OpenID Connect vulnerabilities in web applications demonstrate how authentication protocol implementations can be exploited.

Finally, the section transitions to Azure security by covering Azure infrastructure including virtual machines, storage accounts, and networking, running commands on Azure VMs through various methods, understanding Azure role-based access control (RBAC) that governs permissions in cloud environments, and exploiting managed identities that allow Azure resources to authenticate to other services without stored credentials, demonstrating that comprehensive penetration tests must address both on-premises and cloud infrastructure in modern hybrid environments.

Full Lab Details

  • Lab 5.1: Persistence
  • Lab 5.2: MSBuild and Application Control Bypass
  • Lab 5.3: Domain Dominance
  • Lab 5.4: Golden Ticket
  • Lab 5.5: Silver Ticket
  • Bonus Lab: Running Commands via Azure

Full Topic Details

  • Persistence
  • Living Off Trusted Sites with Ngrok
  • AV/EDR Evasion
  • Application Control Bypass
  • Reporting
  • More Kerberos Attacks
  • Domain Dominance
  • Golden Ticket
  • Silver Ticket
  • OpenID
  • Azure Infrastructure
  • Running Commands in Azure
  • Permissions in Azure

Section 6CTF and Next Steps

Section 6 culminates in a team-based Capture the Flag event applying all learned skills across target networks. Afterward, students explore next steps with cloud pentesting resources, GIAC GPEN prep, home lab guidance, and advanced training like Game of Active Directory to refine attack mastery.

Topics covered

  • Capture the Flag Competition
  • Cloud Penetration Testing Resources
  • GIAC GPEN Exam Preparation
  • Building Home Lab Environments
  • Advanced Training and Practice

Labs

  • CTF: Multi-Network Penetration Testing Competition

Overview

Section 6 provides the culminating experience of the course through a comprehensive Capture the Flag competition that requires applying all techniques learned throughout the six-day training.

Unlike individual labs that focus on specific skills, the CTF presents multiple interconnected target networks with realistic security controls, misconfigurations, and vulnerabilities that mirror actual enterprise environments. Students work in teams to conduct complete penetration tests from reconnaissance through privilege escalation, lateral movement, and objective completion, earning points for flags discovered along the way. The competition format encourages collaboration, creative problem-solving, and the ability to chain multiple techniques into successful attack paths. Success requires not just technical skills but also the penetration testing mindset developed throughout the course—knowing when to pivot strategies, how to prioritize targets, and understanding which techniques apply to specific situations. The competitive element adds urgency that simulates the time-sensitive nature of real penetration tests where defenders may detect and respond to activities.

After the CTF concludes, the section transitions to professional development guidance that helps students continue their penetration testing journey beyond the course. Cloud penetration testing resources address the growing importance of cloud security assessments, providing starting points for learning Azure, AWS, and GCP-specific attack techniques. GIAC GPEN certification preparation receives detailed attention, covering exam format, study strategies, indexing recommendations, and practice test approaches that maximize certification success.

Building effective home labs enables ongoing practice and skill development, with guidance on virtualization platforms, vulnerable machine resources, and network configuration for safe, legal practice environments. Advanced training environments like Game of Active Directory (GOAD) provide documented vulnerable Active Directory forests where students can practice complex attack chains in realistic but intentionally vulnerable environments. Additional resources point students toward bug bounty programs, vulnerable-by-design applications, and the broader information security community.

By combining the practical CTF experience with clear guidance for continuing education and skill development, Section 6 ensures students leave the course not just with current knowledge but with the resources and direction necessary for long-term success in penetration testing careers.

Full Lab Details

  • CTF: Multi-Network Penetration Testing Competition applying all course techniques

Full Topic Details

  • CTF Prep
  • Next Steps

Things You Need To Know

Important! Bring your own system configured according to these instructions.

Windows and macOS Laptops

You can run the virtual machines on Windows, Linux, or macOS laptops. The VMs run in VMware Workstation (Windows/Linux) or VMware Fusion (macOS). Free trials of these products work fine for class.

Apple Silicon Support

This course fully supports Apple Silicon (M1/M2/M3/M4/M5) MacBooks using VMware Fusion and specially built ARM64 virtual machines. Students with Apple Silicon devices receive ARM64 Linux and Windows 11 ARM64 virtual machines that provide native performance on these platforms.

Detailed Requirements

  • CPU: 64-bit Intel or AMD processor (VT-x/AMD-V hardware virtualization must be enabled in BIOS) OR Apple Silicon (M1/M2/M3/M4/M5) processor
  • RAM: 16 GB required, 32 GB strongly recommended for optimal performance
  • Free Disk Space: 150 GB minimum for virtual machine files
  • Host Operating System: Windows 10/11, macOS 11 (Big Sur) or later, or modern Linux distribution
  • Virtualization Software:
  • VMware Workstation Pro 17.x or later (Windows/Linux)
  • VMware Fusion 13.x or later (macOS Intel)
  • VMware Fusion 13.5 or later (Apple Silicon)
  • Free evaluation versions work for the duration of the course
  • Administrator/Root Access: Required for installing VMware and configuring virtual machines
  • Display: 1920x1080 resolution or higher recommended for viewing course materials and VMs simultaneously

Note

  • Students receive two Linux VMs (x64 and ARM64 for Apple Silicon) and two Windows VMs (Windows 11 x6464 and Windows 11 ARM64 for Apple Silicon). The appropriate VMs are selected based on the student's hardware platform.

If you have additional questions about the laptop specifications, please contact customer service.

SEC560 is designed for security professionals who need to conduct penetration tests or assess their organization's security posture:

  • Penetration testers and ethical hackers
  • Security analysts and engineers
  • IT professionals transitioning to offensive security roles
  • Red team operators
  • Security consultants performing network assessments
  • System administrators responsible for hardening enterprise environments
  • Incident responders seeking to understand attacker techniques
  • Security architects designing defensive controls
  • Compliance auditors requiring technical security validation

The GIAC Penetration Tester (GPEN) certification validates a practitioner's ability to properly conduct a penetration test using best-practice techniques and methodologies. GPEN certification holders have the knowledge and skills to conduct exploits, engage in detailed environmental reconnaissance, and utilize a process-oriented approach to penetration testing projects

  • Comprehensive Pen Test Planning, Scoping, and Recon
  • In-Depth Scanning and Exploitation, Post-Exploitation, and Pivoting
  • Azure Overview, Integration, and Attacks, and In-Depth Password Attacks

More Certification Details

  • Course Books: Comprehensive printed books covering all course material (6 books, one per section)
  • Lab Workbook: Detailed lab instructions for all 31 hands-on exercises
  • Virtual Machines: Pre-configured penetration testing VMs including SANS Slingshot Linux and Windows systems, with ARM64 versions for Apple Silicon users
  • Lab Environment Access: VPN connectivity to cloud-hosted vulnerable lab networks during class
  • Digital Course Materials: Electronic copy of all course content accessible through the SANS portal
  • Lab Files: Tool collections, password lists, scripts, and additional resources
  • MP3 Audio Files are included with all course modalities
  • Capture the Flag Competition: Team-based practical assessment of learned skills
  • The course does not include 4 months of OD access but, can be purchased separately
  • The GIAC certification attempt is not included with the course but, can be purchased separately

Required Prerequisites

  • Basic understanding of networking concepts (TCP/IP, DNS, routing)
  • Fundamental familiarity with Windows and Linux operating systems
  • Basic command-line proficiency in both Windows and Linux environments
  • Understanding of basic security concepts (authentication, authorization, encryption)

Recommended But Not Required

  • Prior system or network administration experience
  • Familiarity with Active Directory concepts
  • Basic scripting knowledge (PowerShell, Bash, Python)

Important Note

While not strictly required, students will benefit significantly from basic familiarity with command-line interfaces. The course teaches necessary commands and techniques, but comfort with terminal usage accelerates learning.

Enterprise penetration testing simulates real-world attacks against organizations to identify security vulnerabilities before malicious actors exploit them. Unlike automated vulnerability scanning, penetration testing requires skilled practitioners who think like attackers, chaining multiple vulnerabilities and misconfigurations into successful compromises that demonstrate actual business risk.

Modern enterprises face sophisticated adversaries using techniques like credential stuffing, password spraying, Kerberoasting, Active Directory exploitation, and ransomware deployment. Penetration testing validates whether security controls actually prevent these attacks or merely provide compliance checkbox satisfaction. By safely replicating attacker techniques, penetration tests reveal exploitable weaknesses in authentication mechanisms, privilege models, network segmentation, detection capabilities, and incident response effectiveness.

Organizations conduct penetration tests to:

  • Validate security investments by testing whether implemented controls actually prevent compromise
  • Meet compliance requirements mandated by PCI DSS, HIPAA, GDPR, and other regulatory frameworks
  • Measure detection and response capabilities by observing how quickly security teams identify and react to attacks
  • Prioritize remediation efforts by identifying which vulnerabilities attackers would actually exploit
  • Train security teams by demonstrating real attack techniques and indicators of compromise
  • Demonstrate due diligence to executives, boards, auditors, and cyber insurance providers

The difference between vulnerable and secure organizations often comes down to identifying and fixing exploitable weaknesses before attackers do. Professional penetration testing provides the realistic security assessment necessary to make informed decisions about security posture, resource allocation, and risk acceptance in an environment where breaches carry devastating financial, reputational, and operational consequences.

Immediate Skills for Current Role

SEC560 provides immediately applicable technical skills that enhance your effectiveness in current security positions. Security analysts gain understanding of attacker techniques that improves threat detection and response. System administrators learn which misconfigurations attackers exploit, enabling better system hardening. Compliance professionals understand the technical details behind security requirements, facilitating more effective audits and assessments.

Career Advancement

Penetration testing skills open doors to high-demand, well-compensated security positions. Organizations desperately need qualified penetration testers, with typical salaries ranging from $85,000 to $150,000+ depending on experience and location. The GPEN certification validates your skills to employers, providing credential recognition that facilitates job applications, promotions, and consulting opportunities.

Professional Growth

The penetration testing mindset developed through SEC560 fundamentally changes how you approach security problems. Rather than viewing security through a defensive checklist mentality, you learn to think strategically about attack paths, risk prioritization, and practical security effectiveness. This perspective makes you valuable in any security role, from architect to analyst to consultant.

Community and Network

SANS training connects you with a global community of security professionals. The relationships built during class, the GIAC certification holder community, and access to SANS resources provide ongoing professional development opportunities, job referrals, and collaborative learning throughout your career.

Market Differentiation

In competitive job markets, SEC560 training and GPEN certification distinguish you from candidates with only theoretical security knowledge or basic certifications. Employers recognize SANS training as rigorous, practical, and immediately applicable—exactly what they need in security professionals tasked with defending against real threats.

Relevant Job Roles

Vulnerability Assessment Analyst (DCWF 541)

DoD 8140: Cybersecurity

Assesses systems and networks to ensure compliance with policies and identify vulnerabilities in support of secure and resilient operations.

Explore learning path

Vulnerability Assessment

SCyWF: Protection And Defense

This role tests IT systems and networks and assesses their threats and vulnerabilities. Find the SANS courses that map to the Vulnerability Assessment SCyWF Work Role.

Explore learning path

Vulnerability Assessment (VUAS)

Skills Framework for the Information Age

Identification and classification of vulnerabilities across systems, applications, and networks. Findings are used to guide patching, mitigation, and security control enhancements.

Explore learning path

Vulnerability Analysis (OPM 541)

NICE: Protection and Defense

Responsible for assessing systems and networks to identify deviations from acceptable configurations, enclave policy, or local policy. Measure effectiveness of defense-in-depth architecture against known vulnerabilities.

Explore learning path

Exploitation Analyst (DCWF 121)

DoD 8140: Cyber Effects

Collaborates to identify access and collection gaps using cyber resources and techniques to penetrate target networks and support mission operations.

Explore learning path

Application Pen Tester

Offensive Operations

Application penetration testers probe the security integrity of a company’s applications and defenses by evaluating the attack surface of all in-scope vulnerable web-based services, clientside applications, servers-side processes, and more. Mimicking a malicious attacker, app pen testers work to bypass security barriers in order to gain access to sensitive information or enter a company’s internal systems through techniques such as pivoting or lateral movement.

Explore learning path

Cyber Operations Planner (DCWF 332)

DoD 8140: Cyber Effects

Coordinates cyber operations plans, working with analysts and operators to support targeting and synchronization of actions in cyberspace.

Explore learning path

Penetration Tester

European Cybersecurity Skills Framework

Assess the effectiveness of security controls, reveals and utilise cybersecurity vulnerabilities, assessing their criticality if exploited by threat actors.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 18

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources