SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.
Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.
Mandatory System Hardware Requirements
Mandatory Host Configuration And Software Requirements
Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.
Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.
Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.
If you have additional questions about the laptop specifications, please contact customer service.
The GIAC Red Team Professional (GRTP) certification validates an individual’s ability to conduct end-to-end Red Team engagements. GRTP certification holders have demonstrated knowledge of building an adversary emulation plan, establishing a C2 infrastructure, and emulating adversary tactics, techniques, and procedures (TTPs) to assist in improving overall security.
The concepts and exercises in this course are built on the fundamentals of offensive security. An understanding of general penetration testing concepts and tools is encouraged, and a background in security fundamentals will provide a solid foundation upon which to build Red Team concepts.
Suggested experience:
Many of the Red Team concepts taught in this course are suitable for anyone in the security community. Both technical staff and management personnel will be able to gain a deeper understanding of Red Team exercises and adversary emulations.
The SEC565 training course is part of the Offensive Operations curriculum. In addition to SEC565, SANS offers SEC670 Red Team training on Windows Tool Development.
Other specialized areas within the Offensive Operations curriculum include pen testing and cloud, specialized penetration testing, and purple team.
Red team training is advanced cybersecurity instruction focused on emulating real-world adversaries to test and improve an organization’s security posture. Unlike traditional penetration testing, which often has limited scope and known boundaries, red teaming involves goal-oriented operations designed to simulate how an actual threat actor might breach a system, remain undetected, and achieve specific objectives (like exfiltrating data or gaining domain control).
Red teamers are trained to think like adversaries, leveraging tools, tactics, and procedures (TTPs) used by real-world attackers. This mindset allows them to assess the effectiveness of detection and response mechanisms, expose blind spots, and drive improvements across the defensive landscape.
Red team training is not just about breaking in—it is about sharpening the entire security system through realistic adversary simulation. It empowers professionals to go beyond defense, understand the enemy, and ultimately build more resilient organizations.
SEC565 will elevate your skills from traditional penetration testing to advanced adversary emulation. You will learn to execute complex, multi-phase operations, leverage cutting-edge AI tools for offensive security, and provide actionable, high-value insights to organizational leadership.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources