SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
Important! Bring your own system configured according to these instructions.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.
Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.
Mandatory System Hardware Requirements
Operating System and Configuration (Mandatory)
Corporate security controls frequently interfere with virtualization and lab networking. If you cannot modify these settings, please arrange to use a different system.
Required Pre-Class Setup
Complete before the first day of class.
From your SANS Portal:
If you have questions, please contact customer service.
SEC501 is designed for experienced technologists whose defensive responsibilities cross systems, platforms, and teams. It is an intermediate course for practitioners with SEC401-level knowledge or equivalent experience who must connect records and decisions across the enterprise before deeper specialization.
The GIAC Certified Enterprise Defender (GCED) certification builds on the security skills measured by the GIAC Security Essentials certification. It assesses more advanced, technical skills that are needed to defend the enterprise environment and protect an organization as a whole. GCED certification holders have validated knowledge and abilities in the areas of defensive network infrastructure, packet analysis, penetration testing, incident handling and malware removal.
SEC401 or equivalent practical knowledge is recommended but not required. You should be comfortable working with TCP/IP from the Windows and Linux command lines and have basic experience administering systems or networks. Familiarity with virtualization will help you move efficiently through the labs.
SEC501 is the entry point to the Cyber Defense curriculum for practitioners with SEC401-level knowledge or equivalent experience. It connects visibility, detection, hardening, incident response, digital forensics, and malware analysis before deeper specialization. One persistent anomaly ties these functions to the same enterprise investigation.
Modern enterprises depend on cloud services and software supply chains. Managed security service providers may hold critical records, while AI agents may change systems under delegated authority. Applied cyber defense requires practitioners to follow suspicious activity across these boundaries and establish which systems and accounts require action. A network alert may require a host record, a hardening change, or malware analysis before containment is justified. Practitioners who make these connections reduce premature escalation, limit unnecessary disruption, and give leadership a clear technical basis for the response.
SEC501 prepares experienced technologists to take responsibility for investigations that cross systems, teams, and service providers.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources