SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Apply your credits to renew your certifications
Attend a live, instructor-led class from a location near you or virtually from anywhere
Course material is geared for cyber security professionals with hands-on experience
Apply what you learn with hands-on exercises and labs
Learn how to prevent, detect, and respond to ransomware and cyber extortion attacks via the only dedicated course crafted 100% from real-world ransomware actor tactics, techniques, and behaviors.
Ryan makes sure the course content is up-to-date and gives us extra tools that are really helpful. Also, he keeps the class energetic and easy to follow, he's a great instructor.
Year after year, the number of reported ransomware and cyber extortion attacks continues to rise. These attacks can shut down operations, expose sensitive data, and force organizations to make critical decisions while systems are still offline. Security teams are expected to quickly determine how attackers gained access, which systems were affected, whether data was stolen, and if the environment is truly safe to restore.
FOR528: Ransomware and Cyber Extortion was redesigned to help responders handle these situations with confidence. This streamlined three-day course gives students practical hands-on experience investigating realistic ransomware and cyber extortion cases using the same attacker techniques, forensic artifacts, and investigative workflows seen in real-world incidents.


Ryan Chapman has redefined ransomware defense through hands-on leadership in major incidents like Kaseya and by arming thousands with proactive threat hunting tactics now standard across the industry.
Read more about Ryan ChapmanExplore the course syllabus below to view the full range of topics covered in FOR528: Ransomware and Cyber Extortion.
Section 1 begins with a review of ransomware’s history, as we deep-dive into the roles, processes, communication methods, and activities related to these threats. After learning how we can apply incident response practices, we begin our deep-dive into the Windows-based forensic artifacts best suited to ransomware campaign analysis.
Section 2 begins our foray into the typical flows of ransomware and cyber extortion attacks. We begin with initial access and then move to tooling and execution. That takes us into persistence used in these cases, followed by an overview of Cobalt Strike. Section 2 labs have a malware analysis focus, integrating script deobfuscation into the mix.
Section 3 continues our deep-dive into the phases of typical ransomware and cyber extortion attacks. In this section, we cover Privilege Escalation, Credential Access, and Lateral Movement, detailing associated tools and methods. We then cover common Active Directory attacks, finally leading into ransomware payload deployment and analysis.
The included extended-access CTF gives students a realistic ransomware investigation scenario to complete after the 3 instructor-led days, reinforcing the skills covered in class while preserving flexibility and focus.
Monitor the organisation’s cybersecurity state, handle incidents during cyber-attacks and assure the continued operations of ICT systems.
Explore learning pathResponsible for identifying and assessing the capabilities and activities of cybersecurity insider threats; produces findings to help initialize and support law enforcement and counterintelligence activities and investigations.
Explore learning pathCollection, preservation, and analysis of digital evidence to trace cybercrime and support prosecution efforts. Technical artefacts are translated into admissible findings in collaboration with legal and law enforcement teams.
Explore learning pathResponsible for analyzing digital evidence from computer security incidents to derive useful information in support of system and network vulnerability mitigation.
Explore learning pathCybercrime Investigators navigate dark web forums, trace cybercriminal activity, and conduct covert investigations. They follow forensic and legal standards to gather evidence and respond to cybercrimes.
Explore learning pathExecute digital forensic operations under demanding conditions, rapidly extracting critical intelligence from diverse devices. Leverage advanced threat hunting and malware analysis skills to neutralize sophisticated cyber adversaries.
Explore learning pathThis expert applies digital forensic skills to a plethora of media that encompasses an investigation. If investigating computer crime excites you, and you want to make a career of recovering file systems that have been hacked, damaged or used in a crime, this may be the path for you. In this position, you will assist in the forensic examinations of computers and media from a variety of sources, in view of developing forensically sound evidence.
Explore learning pathAnalyze network and endpoint data to swiftly detect threats, conduct forensic investigations, and proactively hunt adversaries across diverse platforms including cloud, mobile, and enterprise systems.
Explore learning pathEnroll your team as a group or arrange a private session for your organization. We’ll help you choose the format that fits your goals.
The course presented real-life scenarios and detection mechanisms to enhance your organization's security posture to detect and prevent ransomware before it can cause damage to your operations.
The course is pack filled with highly valuable information that will take your company to the next level of being prepared for ransomware.
The content is engaging, and has shown me plenty of new open-source tools.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources