SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions!
A laptop or mobile device with a current web browser is required to access the cloud-hosted course files and CIMTK materials. The CIMTK toolkit is provided on Google Drive, Dropbox or Proton; students must be able to connect to one these services. Corporate machines with VPN, intercepting proxies, or egress filtering must be configured to permit access, or students should bring a personal device.
Microsoft Office and LibreOffice are both supported. Files are maintained in Google first for multi-user collaboration capability; downloads are available in Office-compatible formats.
Students are issued a SANS ChatGPT account for the duration of the course. Other GenAI tools are welcome, but primary support is provided for the OpenAI-based toolset. Some labs use image generation and computer vision features; students relying on non-OpenAI tools should request a SANS ChatGPT account for those specific exercises.
If you have additional questions about the laptop specifications, please contact customer service.
Security Managers
Security Professionals
Managers
Legal, HR, and Communications Staff
The GIAC Cyber Incident Leader (GCIL) certification validates a practitioner’s ability to manage cyber incidents and lead a diverse incident management (IM) team to restore normal operations. GCIL holders demonstrate expertise in preparing for, assessing, handling, tracking, and documenting incidents; developing IM teams; managing vulnerabilities, threats, and attacks; facilitating communication; and improving IM processes.
This course covers the core areas of cyber incident management and assumes a basic understanding of technology, networks, and security concepts. It does not require hands-on technical experience. The focus throughout is management and leadership, not forensics or malware analysis. For those new to the field with no background knowledge, the recommended starting point is SEC401: Security Essentials.
LDR553: Cyber Incident Management is part of the SANS Cybersecurity Leadership curriculum and the Cyber Risk Officer Triad, alongside LDR512: Security Leadership Essentials for Managers and LDR519: Cybersecurity Risk Management and Compliance. Together, these three courses provide a holistic blueprint for modern cyber risk officers—whether stepping into leadership from technical ranks or leveling up within executive roles. The triad develops leaders who not only understand how to build, govern, and respond, but who can unify teams under pressure and steer organizations through complexity with clarity and resilience.
Cyber Incident Management coordinates the response to significant security breaches that exceed the capacity of regular SOC and IR teams. It sits above the technical investigation, handling business impact, stakeholder communications, regulatory obligations, and strategic decisions. An Incident Manager leads cross-functional teams, keeps executives informed, and drives the organization toward recovery while IR handles the technical work. As incidents grow in scale and sophistication, the demand for capable people in this role continues to grow faster than the supply.
No other course covers incident management at this depth, supported by a single continuous real-world scenario where every lab connects to the one before it. LDR553 develops the leadership, communication, and decision-making skills that are genuinely scarce in the market, and that organizations are increasingly willing to pay for. The GCIL certification provides a recognized credential; the CIMTK toolkit provides something you can use from the day you get back. Students regularly apply specific tools and frameworks within days of completing the course.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources