SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
Windows and macOS Laptops
You can run the virtual machines on Windows, Linux, or macOS laptops. The VMs run in VMware Workstation (Windows/Linux) or VMware Fusion (macOS). Free trials of these products work fine for class.
Apple Silicon Support
This course fully supports Apple Silicon (M1/M2/M3/M4/M5) MacBooks using VMware Fusion and specially built ARM64 virtual machines. Students with Apple Silicon devices receive ARM64 Linux and Windows 11 ARM64 virtual machines that provide native performance on these platforms.
Detailed Requirements
Note
If you have additional questions about the laptop specifications, please contact customer service.
SEC560 is designed for security professionals who need to conduct penetration tests or assess their organization's security posture:
The GIAC Penetration Tester (GPEN) certification validates a practitioner's ability to properly conduct a penetration test using best-practice techniques and methodologies. GPEN certification holders have the knowledge and skills to conduct exploits, engage in detailed environmental reconnaissance, and utilize a process-oriented approach to penetration testing projects
Required Prerequisites
Recommended But Not Required
Important Note
While not strictly required, students will benefit significantly from basic familiarity with command-line interfaces. The course teaches necessary commands and techniques, but comfort with terminal usage accelerates learning.
SEC560 fits into multiple SANS learning paths:
Penetration Testing Path
Offensive Operations Path
Cloud Security Path
Enterprise penetration testing simulates real-world attacks against organizations to identify security vulnerabilities before malicious actors exploit them. Unlike automated vulnerability scanning, penetration testing requires skilled practitioners who think like attackers, chaining multiple vulnerabilities and misconfigurations into successful compromises that demonstrate actual business risk.
Modern enterprises face sophisticated adversaries using techniques like credential stuffing, password spraying, Kerberoasting, Active Directory exploitation, and ransomware deployment. Penetration testing validates whether security controls actually prevent these attacks or merely provide compliance checkbox satisfaction. By safely replicating attacker techniques, penetration tests reveal exploitable weaknesses in authentication mechanisms, privilege models, network segmentation, detection capabilities, and incident response effectiveness.
Organizations conduct penetration tests to:
The difference between vulnerable and secure organizations often comes down to identifying and fixing exploitable weaknesses before attackers do. Professional penetration testing provides the realistic security assessment necessary to make informed decisions about security posture, resource allocation, and risk acceptance in an environment where breaches carry devastating financial, reputational, and operational consequences.
Immediate Skills for Current Role
SEC560 provides immediately applicable technical skills that enhance your effectiveness in current security positions. Security analysts gain understanding of attacker techniques that improves threat detection and response. System administrators learn which misconfigurations attackers exploit, enabling better system hardening. Compliance professionals understand the technical details behind security requirements, facilitating more effective audits and assessments.
Career Advancement
Penetration testing skills open doors to high-demand, well-compensated security positions. Organizations desperately need qualified penetration testers, with typical salaries ranging from $85,000 to $150,000+ depending on experience and location. The GPEN certification validates your skills to employers, providing credential recognition that facilitates job applications, promotions, and consulting opportunities.
Professional Growth
The penetration testing mindset developed through SEC560 fundamentally changes how you approach security problems. Rather than viewing security through a defensive checklist mentality, you learn to think strategically about attack paths, risk prioritization, and practical security effectiveness. This perspective makes you valuable in any security role, from architect to analyst to consultant.
Community and Network
SANS training connects you with a global community of security professionals. The relationships built during class, the GIAC certification holder community, and access to SANS resources provide ongoing professional development opportunities, job referrals, and collaborative learning throughout your career.
Market Differentiation
In competitive job markets, SEC560 training and GPEN certification distinguish you from candidates with only theoretical security knowledge or basic certifications. Employers recognize SANS training as rigorous, practical, and immediately applicable—exactly what they need in security professionals tasked with defending against real threats.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources