SEC536: Adversarial AI - Penetration Testing AI Systems


Overview
In the first section, we explore the reality that while organizations strive to prevent as many attacks as possible, not all threats will be stopped. Therefore, timely detection becomes critical. Understanding how to construct a defensible network architecture—along with the various network designs and communication flows—is essential to responding effectively.
Next, we examine how, within any organization, not all data holds equal value. Some information may be routine, while other data is highly sensitive and critical, with its loss potentially causing irreparable damage. It’s crucial to understand how network-based attacks introduce risk to this critical data and where vulnerabilities lie within an organization’s infrastructure. This requires a thorough understanding of modern network communication protocols.
Cloud computing naturally comes into focus as part of modern public and private network discussions. No conversation about defensible networking would be complete without addressing the cloud—its security features, capabilities, and associated concerns.
As we delve deeper, it becomes clear that adversaries rely on our networks as much as we do. They pivot relentlessly from system to system, exploiting our infrastructure to reach their objectives. By learning how our networks function in relation to our unique needs, we can better detect and mitigate adversarial activity.
By the end of this section, you will have a solid understanding of defensible network architecture, protocols and packet analysis, virtualization and cloud fundamentals, and wireless network security.
Topics covered
Labs
Overview
This section of the course explores large-scale threats to our systems and the strategies for defending against them, emphasizing the need for layered protection, known as defense-in-depth. We begin by laying the groundwork for information assurance, examining how security threats impact the confidentiality, integrity, and availability of our systems.
Since access controls are a fundamental component of defense-in-depth, we dive into the core aspects of identity and access management (IAM). Despite efforts to deprecate passwords as the primary authentication factor, they remain prevalent today, and many security breaches still stem from credential theft. This leads to an in-depth discussion on modern authentication methods and password security, particularly in the context of cloud computing. IAM is increasingly considered the new security perimeter for cloud-based systems, and its proper implementation is crucial for strong defense.
Midway through this section, we shift focus to contemporary security controls that are effective against today's adversaries. We do this by examining frameworks such as the Center for Internet Security (CIS) Controls, the NIST Cybersecurity Framework, and the MITRE ATT&CK knowledge base.
As we revisit earlier discussions on network architecture, we naturally explore additional ways to bolster network defensibility. This brings us to a broader environmental approach, emphasizing how best to secure data both in transit and at rest, leading to an in-depth conversation on data loss prevention (DLP) techniques.
Finally, no discussion on defense-in-depth would be complete without addressing one of the most critical technologies in use today-mobile devices. We conclude this section with a dedicated module on mobile devices, examining both the benefits and the security risks they present. Topics such as Bring Your Own Device (BYOD) and Mobile Device Management (MDM) are explored in detail to round out the discussion.
Topics covered
Labs
Overview
In this section, we turn our attention to the various areas within our environment where vulnerabilities can emerge. We begin by defining what constitutes a vulnerability and how to establish an effective vulnerability assessment program.
Since vulnerabilities represent the weaknesses that adversaries exploit, a discussion on this topic must also include an in-depth examination of modern attack methodologies, with real-world examples of compromises. Among the potential areas for vulnerabilities, web applications pose some of the greatest risks, often leading to the most severe consequences. Due to the extensive vulnerabilities associated with web applications, an entire module is dedicated to exploring web application security concepts.
While vulnerabilities may provide adversaries with easy access to systems, it's important to remember that their actions post-compromise can often be detected. By effectively leveraging the logging capabilities of hardware and software, we can detect adversarial activity more quickly. This capability is covered in our penultimate module, which focuses on Security Operations and Log Management.
Finally, it's crucial to have a well-structured response plan for handling any compromises. The methodology for an appropriate incident response is the focus of the final module in this section.
Topics covered
Labs
Overview
There is no single solution that guarantees complete security, but one technology that can address many security challenges--though often improperly deployed--is cryptography. In the first half of this section, we will delve into various cryptographic concepts and explore how they can be effectively used to safeguard an organization's assets.
In the second half, our focus shifts to prevention technologies that can stop adversaries from gaining access to your organization. This includes the use of firewalls and intrusion prevention systems. We will also examine detection technologies, such as intrusion detection systems, which can identify the presence of an adversary. These prevention and detection methods can be deployed at both the network and endpoint levels, and we will discuss the similarities and differences in their implementation.
Topics covered
Labs
Overview
Remember when Windows was simple? Back in the days of Windows XP desktops in small workgroups, things seemed straightforward. But much has changed. Today, we manage Windows tablets, Azure, Active Directory, PowerShell, Microsoft 365 (formerly Office 365), Hyper-V, Virtual Desktop Infrastructure, and more. As Microsoft competes with cloud giants like Google and Amazon, securing the cloud has become a critical challenge.
Windows remains the most widely used and targeted desktop operating system globally. At the same time, the complexities of Active Directory, Public Key Infrastructure (PKI), BitLocker, endpoint security, and user access control present both challenges and opportunities. This course section will guide you through mastering the essentials of Windows security while introducing tools that can streamline and automate your work, whether on-premises or in the cloud with Microsoft Azure. By the end of this section, you'll have a solid foundation in Windows security, including automation and auditing within the Windows ecosystem.
Topics covered
Labs
Overview
While organizations may not have a large number of Linux systems, those they do have are often the most critical and require the highest levels of protection. This course section focuses on providing practical guidance to enhance the security of any Linux system. It offers step-by-step instructions with foundational background for Linux beginners, as well as advanced security advice and best practices for administrators of varying expertise levels.
Given Linux's reputation as a free and open-source operating system, it's no surprise that many advanced security concepts are first developed for Linux. One notable example is containers, which offer powerful and flexible capabilities for cloud computing deployments. Although containers weren't initially designed for security purposes, they are built on the principle of minimization, which can be leveraged as part of a defense-in-depth security strategy. We will explore what containers represent for information security, what they do not, and best practices for their management.
Finally, we conclude this section with a review of Apple's macOS, which is built on a UNIX foundation. Despite its robust hardware and software security features, macOS is often misunderstood regarding what it can and cannot achieve in terms of security.
Topics covered
Labs
Important! Bring your own system configured according to these instructions.
If you do not carefully read and follow these instructions, you will not be able to fully participate in the hands-on exercises. Please arrive with a system meeting all specified requirements.
Back up your system before class and ensure it contains no sensitive or critical data. SANS is not responsible for your system or data.
Mandatory System Hardware Requirements
Mandatory Host Configuration and Software Requirements
Your course media is delivered via download. The media files for class can be large. Many are in the 30 GB range. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.
Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.
Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.
If you have additional questions about the laptop specifications, please contact customer service.
MIL401H is designed for military, government, and defense personnel preparing to perform Host Analyst functions aligned to DCWF 463 / DoD 8140 workforce requirements. The course is built for learners who need practical capability in monitoring, detection, investigation, escalation, and defensive cyber operations, not broad, general cybersecurity awareness.
You should attend if:
This training course aligns to NICE / DCWF workforce roles including:
MIL401H is specifically designed to support workforce development for Host Analyst functions aligned to DCWF 463 and DoD 8140 role requirements, with emphasis on monitoring, detection, investigation, escalation, and defensive cyber operations workflows.
The GIAC Security Essentials (GSEC) certification validates a practitioner's knowledge of information security beyond simple terminology and concepts. GSEC certification holders are demonstrating that they are qualified for hands-on IT systems roles with respect to security tasks.
The MIL401H course covers all the core areas of security and assumes a basic understanding of technology, networks, and security. For those who are new to the field and have no background knowledge, SEC275: Foundations - Computers, Technology and Security would be the recommended starting point. While this course is not a prerequisite for MIL401H, it does provide the introductory knowledge to help maximize the experience with MIL401H training.
MIL401H is part of a role-aligned Host Analyst (DCWF 463) workforce development pathway designed to support defensive cyber operations, monitoring and triage, SOC operations, and incident response functions aligned to DoD 8140 workforce requirements.
The course establishes the foundational operational capability required for Host Analyst roles and prepares learners for progression into more specialized defensive cyber operations training.
Depending on your operational role or workforce development pathway, recommended next steps include:
Cyber Defense Operations / SOC Progression
Incident Response / DFIR
Cloud and Defensive Infrastructure
Advanced Defensive Operations
Modern cyber defense operations depend on analysts who can monitor, detect, investigate, escalate, and respond effectively across network, endpoint, cloud, and hybrid environments. Those capabilities are not built through isolated technical skills alone—they require a structured operational foundation aligned to how defensive cyber operations are actually performed.
MIL401H establishes that foundation by developing the core technical and analytical capabilities required for Cyber Defense Analyst roles aligned to DCWF / DoD 8140 workforce requirements. The course focuses on the operational disciplines that underpin effective cyber defense, including:
These are the capabilities that allow organizations to build scalable analyst readiness across SOC and cyber defense teams. Without them, advanced tooling and specialized capabilities operate without the operational foundation required to use them effectively.
Cyber defense organizations increasingly need analysts who can contribute operationally from day one, not simply understand cybersecurity concepts in theory. MIL401H is designed to build the practical monitoring, detection, investigation, and response capabilities required for Host Analyst roles aligned to DCWF 463 / DoD 8140 workforce requirements.
Here is what that means in practice:

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources