Group Purchasing
Group Purchasing
AI-FOCUSEDMAJOR UPDATES

SEC573: AI-Powered Security Automation: Building Tools with Python, LLMs, and MCP

SEC573Cyber Defense, Artificial Intelligence
  • 6 Days (Instructor-Led)
  • 36 Hours (Self-Paced)
Course authored by:
Mark Baggett
Mark Baggett
SEC573: Automating Information Security with Python
Course authored by:
Mark Baggett
Mark Baggett
  • GIAC Python Coder (GPYC)
  • 36 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 128 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Learn how we can leverage Agentic AI development and Python as security professionals. From the Python essentials to developing AI Agents for your own information security tools.

Course Overview

Are you ready to supercharge your cybersecurity career with AI-driven automation and tackle the evolving threats in today's digital landscape? The key is mastering AI integration through practical tools like MCP (Model Context Protocol) and OpenAI agents, all built on accessible Python foundations. Want to leverage AI for real-time anomaly detection, automate analysis of forensic artifacts, or develop custom agents that uncover hidden attack patterns and outpace adversaries? From building AI-powered log analysts to integrating automation frameworks like n8n to writing stand along autonomous AI agents, this course equips you with the skills to harness massive data streams, enhance forensics, and create intelligent defenses that keep you ahead.

SEC573: AI-Powered Security Automation positions AI as the core of modern infosec. You will be taught to write and debug Python code. And when the code gets a little too complex you will learn to leverage AI code writing agents to "Vibe code" a solution to today complex problems. Have you ever wondered why so many SANS courses touch on the Python basics? It's because mastering Python is essential for completing advanced labs and staying relevant in fields like data science, machine learning, and penetration testing. This class will teach you the essentials and how to leverage AI to write, explain and enhance your Python programs to solve real-world problems.

When you're ready to elevate AI from a buzzword to your infosec superpower, SEC573 delivers exactly what you need to get started. This course also prepares you for the GPYC certification (GIAC Python Coder), validating your ability to apply AI and Python to solve real-world cybersecurity challenges.

Versatile, Repeatable, Efficient: Security Tasks Automated with AI and Python

SEC573 empowers security professionals to leverage AI and Python to drive automation for streamlining tasks, crafting intelligent agents, and responding swiftly to emerging threats. Designed for both beginners and seasoned experts, this course starts with Python fundamentals and AI enabled Agents can "Vibe coding" can assist you to turn your ideas into working code. AI makes Python integration approachable, then scales to advanced techniques. You will write your own MCP servers and OpenAI agents, ensuring you can create practical, high-impact solutions tailored to your needs. Whether you’re in digital forensics, network defense, penetration testing, incident response, cloud engineering, or industrial control systems, you’ll learn to build AI-enhanced tools that boost efficiency and keep you agile in the face of constant change.

In today’s job market, AI expertise is a must-have skill for infosec professionals. Organizations across industries are desperate for experts who can harness AI to address critical challenges:

  • Write and debug basic Python programs so you can avoid the typical AI workflow of repeatedly asking AI to rewrite massive broken program when a simple line change will do the trick.
  • Learn how to leverage Python code writing agents to fix problems in your code or just write code for you.
  • Custom Tool Development: When off-the-shelf tools fail, AI lets you create tailored solutions for forensics, penetration testing, or network defense, giving you a competitive edge.
  • Automation and Efficiency: Streamline repetitive tasks, from log analysis to vulnerability scanning, freeing you to focus on strategic priorities.

Why AI? Why Now?

AI’s transformative power and accessibility make it the go-to capability for security professionals. Its extensive frameworks and integrations empower you to tackle diverse challenges, from scripting quick automations to building complex AI-driven defenses with MCP and OpenAI agents. In a world where attackers leverage AI, cloud technologies, and sophisticated techniques, mastering AI is your weapon to fight back. The demand for AI-savvy professionals has never been higher. Job roles like SOC Analyst, Incident Responder, Penetration Tester, Threat Intelligence Analyst, Forensics Analyst, Data Scientist, and DevSecOps Specialist all require AI proficiency. No matter what your role is in infosec, having this powerful skill will make you an indispensable member of the team.

This self-paced course assumes no prior programming experience, starting with Python basics, then we will learn to leverage AI to write more challenging and advanced applications. If you’re already familiar with coding, our pywars lab environment lets you dive straight into sophisticated projects. You’ll gain hands-on skills to:

  • Automate repetitive security tasks with new Python tools you will develop with AI to save time and reduce errors.
  • Build custom AI agents for forensics, penetration testing, and threat hunting when existing solutions fall short.
  • Parse and analyze complex datasets to uncover critical insights.
  • Develop AI integrations with APIs, cloud platforms, and security tools.
  • Create rapid prototypes to address emerging threats or vulnerabilities.

You will see real-world impacts of this course for years to come. Imagine a new operating system feature that generates unique forensic artifacts, but no tool exists to extract them. With AI, you can develop an agent to access that evidence and keep your investigation on track. Or picture an attacker evading detection with novel techniques. AI lets you craft a custom python detection tool to stop them in their tracks. For penetration testers, AI enables you to develop unique exploits that outsmart outdated defenses. In every scenario, SEC573 equips you to adapt, innovate, and deliver results.

So, Is This Course Right For You?

SEC573 is for anyone in cybersecurity or related fields—penetration testers, forensic analysts, network defenders, security administrators, incident responders, and aspiring data scientists—who wants to stay relevant in a rapidly evolving industry. Change is constant, and leverage AI to develop customer tools and AI Agents is your key to mastering it. Organizations worldwide are seeking professionals who can understand complex problems and rapidly develop solutions. With SEC573, you’ll join the ranks of those who can, and stand out with the GPYC certification.

In a world driven by AI, data, and relentless cyber threats, AI is no longer optional. It’s essential. SEC573 gives you the skills to automate, innovate, and lead in today’s high-stakes job market. Enroll now and become the infosec professional organizations can’t afford to lose.

Author Statement

The ability to leverage AI skills to develop new tools is essential for professionals working in all aspects of information security. Understanding how to integrate AI into your workflows means you can automate complex tasks and achieve more, with fewer resources, in less time. SEC573 is designed for network defenders, forensics examiners, penetration testers, and other security professionals who want to learn how to apply AI-driven automation to do their job more efficiently. This course will help take your career to the next level by teaching you this highly sought-after skill. We will focus on the most important skills for security professionals, such as building AI agents, integrating with automation frameworks, and handling prompt injections, all while interacting with networks, websites, databases, and file systems. We will cover these essential skills as we build practical AI applications that you can immediately put into use in your place of work.

What You’ll Learn

  • Leverage AI to develop new tools to perform routine tasks quickly and efficiently.
  • Automate log analysis and packet analysis with AI agents, file operations, regular expressions, and analysis modules to detect threats
  • Develop forensics tools to carve binary data, process unstructured AI data, and extract new artifacts
  • Read data from databases and the Windows Registry to support AI-driven for investigations and tool development
  • Interact with websites and APIs to enrich logs and AI prompts to accomplish information security tasks
  • Develop MCP servers and OpenAI agents for advanced automation and threat identification and response
  • Understand prompt injection attacks and build secure AI integrations

Business Takeaways

  • Automate system processes with AI to handle inputs quickly and efficiently
  • Create AI-driven programs that increase efficiency and productivity
  • Develop intelligent tools to provide the vital defenses our organizations need
  • Integrate AI agents for proactive threat detection and response
  • Streamline forensics and incident response with custom AI automations
  • Enhance cloud and network security through AI-powered monitoring and analysis
  • Build resilient systems against emerging threats using MCP and OpenAI technologies

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC573: Automating Information Security with Python.

Section 1Essential Skills Workshop

The course starts with an intro to Python and the pyWars Capture-the-Flag challenge. Students learn at their own pace in the pyWars lab, with over 100 hands-on labs to build life-changing skills. Advanced students tackle Python bonus challenges, while beginners start with Python essentials.

Topics covered

  • Leveraging AI and Vibe Coding
  • The Essentials of Python Coding
  • Variables and Math Operators
  • Strings and Functions
  • Visual Studio Code and Debugging Code

Labs

  • 36 hands-on labs in Section 1 alone!
  • Working with Python Numeric variables
  • Working with Python Strings, Bytes and More
  • Understanding and Using Python Functions
  • Leveraging the Python Debugger to fix errors

Section 2Essentials Knowledge Workshop

You won't learn programming from slides. This section builds on the hands-on approach, covering data structures and programming concepts. Learn to use Python Virtual Environments to resolve library conflicts and organize your setup. We also cover debugging with Visual Studio Code and share tips to become a better Python programmer.

Topics covered

  • Python Virtual Environments
  • Python Modules
  • Lists, Loops, and Tuples
  • Dictionaries
  • Tips Tricks and Shortcuts

Labs

  • There are 22 Hands on labs for Section 2 alone
  • Need more? There are 7 Bonus labs on section 2 material
  • Managing and Using 3rd Party Modules and Virtual Environments
  • Master using Python Lists and Loops
  • Data Processing with Python Dictionaries and Sets

Section 3Automated Defense with AI

In this section, we take on the role of network defenders, using AI to develop code and access data to solve complex challenges. We’ll explore AI's limitations and the need for offline analysis, including regex and file analysis. Forensics and offensive security pros will also benefit, as skills like file reading and data parsing are essential for them.

Topics covered

  • File Operations
  • Leveraging Code writing Agents and “Vibe Coding”
  • Developing MCP Server Leveraging Automation Frameworks like n8n
  • Targeting Useful data with Regular Expressions
  • Log Parsing, Data Analysis Tools and Techniques

Labs

  • 18 hands on labs (plus 30+ CTF challenges to test your python coding/vibe coding skills)
  • Solving File I/O Challenges with Python and Vibe Coding
  • Developing MCP servers and integrate them into N8N
  • Using Regular Expression to find relevant data
  • Data Analytics Techniques to Minimize Context Windows

Section 4Automated Forensics with AI

In our forensics-themed section, we will assume the role of a forensic analyst who has to carve evidence from artifacts when no tool exists to do so.

Topics covered

  • Processing Unstructured and Structured Data
  • Developing AI Agents with Chat Completion and Tool Calling
  • Developing AI Agents with the Responses API
  • Giving Access to data sources such as JSON, Windows Registry, SQL data
  • Accessing Web APIs and Web Applications

Labs

  • Section 4 introduces 17 more labs in addition to the 30+ bonus CTF labs
  • Processing unstructured data with Struct, Pydantic and Regex
  • Developing AI Agents
  • Accessing the Windows Registry
  • Accessing Web APIs and Web Applications

Section 5Automated Offense with AI

In this offensive-themed section, we become penetration testers whose attempts have been blocked by modern defenses. You will build an agent to bypass these defenses and gain remote access. We’ll also learn how AI agents can be turned against us by exploring AI guardrails, their limitations, and applying them in offensive exercises.

Topics covered

  • AI Prompt Injection Attacks and Techniques
  • OpenAI Agent Input and Output Guardrails
  • Network TCP and UDP Socket Operations
  • Exception Handling and Process Execution
  • Blocking and Non-blocking Sockets

Labs

  • Prompt Injection Attacks against real world models
  • Communicating with TCP Sockets
  • Using error handling to develop a port scanner
  • Executing subprocesses to create a backdoor
  • Handling large amounts of data across a socket for uploads

Section 6Capstone Workshop

In the final section, you’ll team up with other students to apply your skills in programming challenges. You’ll solve problems, exploit vulnerable systems, analyze packets, parse logs, and automate code execution on remote systems. Test your skills, tackle challenges, and prove your expertise!

Things You Need To Know

CRITICAL NOTE: Apple Silicon devices cannot perform the necessary virtualization and cannot be used for this course.

Laptop Required

Students are required to bring their own laptop so that they can connect directly to the workshop network we will create, and thus get the most value out of the course. It is the student's responsibility to make sure that the system is properly configured and capable of running both a Windows and Linux VMWare compatible virtual machines at the same time.

Some of the course exercises are based on Windows, while others focus on Linux. VMware Player or VMware Workstation is required for the course. If you plan to use an Intel based Mac, please make sure you bring VMware Fusion, along with a Windows guest virtual machine. All of the VMware products are available at www.vmware.com.

Important Note: You may also be required to disable your anti-virus tools temporarily for some exercises, so make sure you have the anti-virus administrator permissions to do so. Do not plan on just killing your anti-virus service or processes, because most anti-virus tools still function even when their associated services and processes have been terminated. For many enterprise-managed clients, disabling your anti-virus tool may require a different password than the Administrator account password. Please bring that Administrator password for your anti-virus tool.

Enterprise VPN clients may interfere with the network configuration required to participate in the course. If your system has an enterprise VPN client installed, you may need to uninstall it for the course exercises.

  • Mandatory Laptop Hardware Requirements
  • CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class.
  • CRITICAL: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot in any way be used for this course.
  • BIOS settings must be set to enable virtualization technology, such as "Intel-VTx" or "AMD-V" extensions. Be absolutely certain you can access your BIOS if it is password protected, in case changes are necessary.
  • 16GB of RAM or more is required.
  • 200GB of free storage space or more is required.
  • At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

If you have additional questions about the laptop specifications, please contact customer service.

SEC573 training is recommended for a diverse range of individuals, including:

  • Security professionals who benefit from automating routine tasks so they can focus on what's most important
  • Forensic analysts who can no longer wait on someone else to develop a commercial tool to analyze artifacts
  • Network defenders who sift through mountains of logs and packets to find evil-doers in their networks
  • Penetration testers who are ready to advance from script kiddie to professional offensive computer operations operator
  • Security professionals who want to evolve from security tool consumer to security solution provider

The GIAC Python Coder (GPYC) certification validates a practitioner's understanding of core programming concepts, and the ability to write and analyze working code using the Python programming language. GPYC certification holders have demonstrated knowledge of common python libraries, creating custom tools, collecting information about a system or network, interacting with websites and databases, and automating testing.

  • Python language essentials
  • Packet and data analysis
  • Website and database interaction
  • Regular expressions
  • Exception handling and debugging

More Certification Details

  • A USB containing a virtual machine filled with sample code and working examples
  • MP3 audio files of the complete course lecture

A basic understanding of any programming or scripting language is highly recommended but not required for this course. SEC573 starts with the most basic fundamentals of Python programming. There is no aspect of programming or Python that must be understood before attending this course. The lab environment is self-paced and this allows students who have had some experience coding to advance more quickly than those who have not. You are provided a Virtual Machine that gives you the ability to complete the labs that are in your course book after the live course or your OnDemand access has finished.

AI-Powered Information Security Automation integrates artificial intelligence with automation tools to enhance cybersecurity operations, enabling systems to detect, respond to, and mitigate threats in real-time without constant human intervention. Using LLMs and the power of Python, you can develop tools to handle a variety of information security tasks from processing data from logs, networks, and endpoints to identifing anomalies, predict attacks, and automate defenses. This approach, emphasized in SEC573: AI-Powered Information Security Automation, leverages "Vibe coding" that makes development accessible even for non-experts, allowing quick creation of custom agents and integrations via protocols like MCP (Message Context Protocol) and OpenAI agents.

Key benefits include:

  • Faster Response: Automates repetitive tasks like system monitoring, enabling quicker detection and response to threats.
  • Consistency: Ensures that security procedures are executed in a consistent and error-free manner.
  • Scalability: Allows for easy scaling of security measures across large networks and systems.
  • Customizability: Python’s extensive libraries and frameworks make it easy to tailor automation to specific security needs.
  • Ultimately, automation helps reduce the workload on security professionals while improving the organization’s resilience to cyber threats.

SEC573 is a crucial course for anyone looking to advance in cybersecurity, particularly in the areas of automation and threat defense. By focusing on automated methods for defending IT infrastructure, this course equips professionals with the skills needed to efficiently manage and protect systems at scale.

Key benefits for your career include:

  • Enhanced Skillset: Learn how to design and implement automated defenses, improving your ability to mitigate cyber threats quickly and effectively.
  • Industry-Relevant Knowledge: The course covers modern attack vectors and automated defense tools, preparing you for the latest trends in cybersecurity.
  • Improved Efficiency: Mastering automation allows you to handle complex environments with greater speed, precision, and fewer errors, making you an asset to any team.
  • Career Advancement: With the growing demand for cybersecurity professionals skilled in automation, SEC573 can open doors to more advanced roles and opportunities in the field.
  • This course will make you more competitive and capable in the ever-evolving cybersecurity landscape.

Relevant Job Roles

Data Analysis (OPM 422)

NICE: Implementation and Operation

Responsible for analyzing data from multiple disparate sources to provide cybersecurity and privacy insight. Designs and implements custom algorithms, workflow processes, and layouts for complex, enterprise-scale data sets used for modeling, data mining, and research purposes.

Explore learning path

Technology Research and Development (OPM 661)

NICE: Design and Development

Responsible for conducting software and systems engineering and software systems research to develop new capabilities with fully integrated cybersecurity. Conducts comprehensive technology research to evaluate potential vulnerabilities in cyberspace systems.

Explore learning path

Malware Analyst

Digital Forensics and Incident Response

Malware analysts face attackers’ capabilities head-on, ensuring the fastest and most effective response to and containment of a cyber-attack. You look deep inside malicious software to understand the nature of the threat – how it got in, what flaw it exploited, and what it has done, is trying to do, or has the potential to achieve.

Explore learning path

Digital Forensic Analyst Training, Salary, and Career Path

Digital Forensics and Incident Response

This expert applies digital forensic skills to a plethora of media that encompass an investigation. The practice of being a digital forensic examiner requires several skill sets, including evidence collection, computer, smartphone, cloud, and network forensics, and an investigative mindset. These experts analyze compromised systems or digital media involved in an investigation that can be used to determine what really happened. Digital media contain footprints that physical forensic data and the crime scene may not include.

Explore learning path

Digital Forensics (OPM 212)

NICE: Protection and Defense

Responsible for analyzing digital evidence from computer security incidents to derive useful information in support of system and network vulnerability mitigation.

Explore learning path

Military Operations / Law Enforcement Agents

Digital Forensics and Incident Response

Execute digital forensic operations under demanding conditions, rapidly extracting critical intelligence from diverse devices. Leverage advanced threat hunting and malware analysis skills to neutralize sophisticated cyber adversaries.

Explore learning path

Vulnerability Assessment

SCyWF: Protection And Defense

This role tests IT systems and networks and assesses their threats and vulnerabilities. Find the SANS courses that map to the Vulnerability Assessment SCyWF Work Role.

Explore learning path

Media Exploitation Analyst

Digital Forensics and Incident Response

This expert applies digital forensic skills to a plethora of media that encompasses an investigation. If investigating computer crime excites you, and you want to make a career of recovering file systems that have been hacked, damaged or used in a crime, this may be the path for you. In this position, you will assist in the forensic examinations of computers and media from a variety of sources, in view of developing forensically sound evidence.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS DC Metro September 2026

    Bethesda, MD, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS London October 2026

    London, GB & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    £7,160 GBP*Prices exclude applicable taxes | EUR price available during checkout
    Registration Options
  • Location & instructor

    SANS Canberra November 2026

    Canberra, ACT, AU & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    A$13,350 AUD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Dallas 2026

    Dallas, TX, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Live Online Europe January 2027

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €8,230 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Security West 2027

    San Diego, CA, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Baltimore 2027

    Baltimore, MD, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANSFIRE 2027

    Washington, DC, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
Showing 9 of 9

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources