SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system that meets all of the specified requirements.
Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.
Mandatory System Hardware Requirements
Mandatory Host Configuration and Software Requirements
Your course media is delivered via download. The media files for class are large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete before arrival to class. Internet connections and speed vary greatly and are dependent on many different factors. Consequently, it is impossible to estimate the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. Waiting until the night before the class starts to begin your download has a high probability of failure.
Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.
If you have questions about the laptop specifications, please contact customer service.
ICS515 training is recommended for a diverse range of individuals, including:
The GRID certification is for professionals who want to demonstrate that they can perform Active Defense strategies specific to and appropriate for an Industrial Control System (ICS) network and systems. Candidates are required to demonstrate an understanding of the Active Defense approach, ICS-specific attacks and how these attacks inform mitigation strategies. Candidates must also show an understanding of the strategies and fundamental techniques specific to core subjects with an ICS-focus such as network security monitoring (NSM), digital forensics and incident response (DFIR).
Students from either an IT or ICS background will do well in this course. Prior to attending the course, it is recommended that you attend SANS ICS410: ICS/SCADA Security Essentials, ICS456: Essentials for NERC Critical Infrastructure Protection, or equivalent essential cybersecurity classes such as SEC401, or that you have fundamental cybersecurity experience. Students do not need previous ICS experience, but they should be comfortable with ICS terminology and systems such as SCADA, DCS, PLCs, and RTUs, and have an understanding of distinct risks and mitigation approaches in OT environments.
With your purchase of this ICS Security course, you’ll receive complimentary OnDemand access to ICS310: ICS Cybersecurity Foundations — an added benefit, not a prerequisite or requirement. This course is a great way to reinforce key concepts or fill gaps in your ICS/OT security knowledge, whether you complete it in full or focus on what’s most relevant to you. Within 14 business days, you’ll receive a non-transferable access code via your SANS account email.
The recommended learning path starts with foundational courses like ICS410: ICS/SCADA Security Essentials, ICS456: Essentials for NERC Critical Infrastructure Protection, or SEC401: Security Essentials - Network, Endpoint, and Cloud. While prior ICS experience isn't required, familiarity with basic ICS terminology (SCADA, DCS, PLCs, RTUs) and OT risk concepts is beneficial. The course includes complimentary access to ICS310: ICS Cybersecurity Foundations.
ICS (Industrial Control System) Incident Response is the structured process of detecting, investigating, and mitigating cybersecurity incidents that affect operational technology (OT) environments—such as power grids, water treatment facilities, manufacturing systems, pipelines, and other critical infrastructure.
These environments rely on real-time control systems like SCADA (Supervisory Control and Data Acquisition), PLCs (Programmable Logic Controllers), and HMIs (Human Machine Interfaces), which differ significantly from traditional IT systems in both design and risk profile.
This course enhances careers by providing hands-on experience with real ICS equipment and advanced defense techniques. Learners gain specialized skills in industrial threat detection, incident response, and network monitoring that are highly sought after in critical infrastructure sectors, positioning you as a specialized security professional capable of bridging IT and OT security domains.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources