SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.
Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.
Mandatory System Hardware Requirements
Mandatory Host Configuration And Software Requirements
Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.
Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.
Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.
If you have additional questions about the laptop specifications, please contact customer service.
SEC575 training is recommended for a diverse range of individuals, including:
Experience with programming in any language is highly recommended. At a minimum, students are advised to read up on basic programming concepts such as conditional statements, variables, loops and functions. Ideally, students have some experience with either Java or JavaScript. The basics of programming will not be covered in this course.
Students should have a basic working experience with Linux and terminal commands.
Students should have familiarity with penetration testing concepts such as those taught in SANS SEC504: Hacker Tools, Techniques, and Incident Handling.
SEC575: iOS and Android Application Security Analysis and Penetration Testing™ is part of the Specialized Offensive Operations curriculum. Other specialized penetration testing courses that could complement and round out a penetration tester’s skill set include SEC580: Metasploit for Enterprise Penetration Testing™ and SEC556: IoT Penetration Testing™. Alongside these specialized penetration testing courses, you can find training in cloud penetration testing, red team, and purple team.
Mobile security refers to the strategies, practices, and technologies used to protect mobile devices—such as smartphones, tablets, and laptops—from threats like malware, unauthorized access, data breaches, and exploitation of vulnerabilities.
In today's digital world, mobile devices are gateways to sensitive personal, corporate, and governmental data. Whether it’s accessing email, using secure authentication apps, or handling payment and financial transactions, these devices are deeply integrated into our professional and personal lives.
Mobile security matters because today’s devices are constant targets for attackers, exposing sensitive data through app vulnerabilities, insecure networks, and phishing. With BYOD policies and increasing reliance on mobile access, weak mobile defenses can lead to data breaches, compliance violations, and credential theft—making mobile protection essential to any organization’s cybersecurity strategy.
SEC575 training equips you with the hands-on skills to assess, defend, and ethically hack mobile devices—skills that are increasingly critical as mobile becomes the most targeted enterprise endpoint. Whether you're a penetration tester, incident responder, or security architect, SEC575 gives you practical tools to identify mobile threats, analyze apps, bypass protections, and harden both iOS and Android environments.
You'll walk away with immediately applicable experience in using tools like Frida, Burp Suite, and MobSF, as well as a deep understanding of mobile OS internals—positioning you as a go-to mobile security expert within your organization.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources