SEC536: Adversarial AI - Penetration Testing AI Systems

Important - Bring Your System Configured Using These Directions
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.
As a summary, you can use any operating system that also can install and run VMware virtualization products. Please note, macOS computers with M-series chips are not currently supported and cannot run the virtual machines provided for this course. If you arrive at class with a macOS device using an M-series chip we will be unable to assist you, and you may be unable to take part in the class activities.
Please download and install VMware Workstation 15 or VMware Fusion 7 or higher versions on your system before the start of the class.
This is common sense, but we will say it anyway: Back up your system before class. Better yet, do not have any sensitive data stored on the system. SANS cannot be responsible for your system or data.
Mandatory System Hardware Requirements
Mandatory System Software Requirements
Please install the following before the beginning of the class:
Additional Notes
If you have additional questions about the laptop specifications, please contact customer service.
FOR577 training is recommended for a diverse range of individuals, including:
The GIAC Linux Incident Responder (GLIR) certification validates a practitioner’s knowledge of Linux incident response and threat hunting skills. GLIR certification holders have a demonstrated ability to conduct system triage, perform evidence collection, and conduct incident response analysis to identify the initial entry point of an attack and movement across Linux systems.
This course uses the SIFT Workstation extensively to teach incident responders and forensic analysts how to investigate and respond to sophisticated attacks. The workstation contains hundreds of free and open-source tools, easily matching any modern forensic and incident response commercial response tool suite. A virtual machine is used with most of the hands-on class exercises. Features of the SIFT Workstation include:
FOR577 is an advanced incident response course that focuses on the Linux operating system. We do not cover basic forensic techniques or introductory attacker techniques. Students are not expected to have detailed understanding of Linux, but it is recommended that they have at least the level of knowledge provided by SEC401.
The FOR577 course is a part of the “Forensic Essentials” Learning Path, which aims to equip forensics and incident response professionals with the specialized skills they need for incident investigation and response.
Depending on your current or desired future role, one of these courses is a great next step in your cybersecurity journey:
Linux incident response is the process of detecting, managing, and recovering from security incidents involving Linux-based systems. This includes identifying breaches, containing threats, eradicating malicious activity, and restoring normal operations. Given the widespread use of Linux in servers, data centers, and cloud infrastructure, its security is critical to an organization's overall security posture. The ability to perform Linux incident response helps to:
Linux incident response helps organizations secure their systems, mitigate breach impacts, and stay compliant with industry regulations.
FOR577 offers valuable career benefits for security professionals by giving you the specialized skills to keep Linux systems secure. Key career benefits include:

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources