SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
As cyberthreats grow more sophisticated, it is critical to proactively identify and address vulnerabilities before adversaries exploit them. A SANS survey of ethical hackers found that nearly 60% can breach a corporate environment within five hours of identifying a weakness. SANS Offensive Operations delivers expert-led offensive security training courses across the entire attack surface, covering everything from penetration testing and red teaming to exploit development and hardware hacking. Through hands-on labs and industry-recognized certifications, we equip professionals to master real-world offensive techniques and adversarial tactics.
Offensive security is the practice of thinking and operating like a cyber attacker to uncover security gaps before they can be exploited. Rather than waiting for a breach to reveal weaknesses, offensive security professionals actively test systems, applications, networks, and devices to identify risks and improve defenses. This approach helps organizations better understand how real-world threats operate and where their security posture can be strengthened. Through SANS offensive operations training courses, you can learn the tools, methods, and mindset used by today's top cybersecurity professionals, gaining practical experience that can be applied immediately in real-world environments.
Build offensive security training and penetration testing expertise using real-world tactics, tools, and methodologies to identify, exploit, and remediate security vulnerabilities while gaining hands-on experience with the techniques used by today's attackers and security professionals.
Learn adversary emulation, stealth, and evasion techniques to test and improve an organization's security posture against persistent threats. Through red team certification training and practical offensive security scenarios, develop the skills needed to simulate advanced threat activity, bypass defensive controls, evaluate detection and response capabilities, and help organizations identify and address security gaps before they can be exploited.
Bridge the gap between offense and defense, to foster collaboration between red and blue teams and strengthen detection, response, and overall security resilience. Gain a deeper understanding of attacker behavior, improve threat hunting and incident response processes, and help security teams work together more effectively to identify weaknesses, validate defenses, and reduce organizational risk.
In one week, my instructor built a bridge from typical vulnerability scanning to the true art of penetration testing. Thank you, SANS, for making myself and my company much more capable in information security.














Train with Erik Van Buggenhout, SANS instructor and NVISO co-founder, and develop hands-on skills in purple teaming, adversary emulation, and detection engineering to continuously improve detection, response, and real-world cyber defense.
Learn more

Chris Elgee, SANS instructor and GSE, brings real-world cyber operations into the classroom through immersive NetWars challenges and hands-on labs that teach students to think like attackers and defend with confidence.
Learn more

Red team expert Moses Frost combines decades of offensive security experience with hands-on SANS training, helping students master cloud penetration testing and adversary simulation through real-world labs.
Learn more

Jean-François is based in Portugal, where he is the CEO of Offensive Guardian, a boutique red and purple teaming shop providing freelance services to various organizations. He has worked for other noteworthy firms, including, but not limited to: Neuvik, TrustedSec, Fortra's Cobalt-Strike team, and NVISO.
Learn more

Jeff McJunkin brings decades of systems, network, and offensive security experience to SANS. Founder of Rogue Valley Information Security, he has led enterprise penetration tests, built Core NetWars experiences, and authored SEC580 while co-authoring SEC560.
Learn more

Larry has revolutionized embedded device security with decades of hands-on offensive research, co-authoring SANS's flagship wireless and IoT penetration testing courses, and pioneering SBOM exploitation techniques for supply chain defense strategies.
Learn moreSANS coins aren’t just given…they are earned. Discover the story behind these iconic Offensive Ops challenge coins, where Capture the Flag victories, custom artwork, and hidden puzzles come together in a collectible worth chasing.

Attackers are constantly finding new ways to evade endpoint defenses. Join Bryce Galbraith on 8 July, 5–6 PM, to learn how these techniques work and how to defend against them.

This session walks through a modern web app pentest workflow using OWASP tools, Burp MCP, DefectDojo, and AI-assisted reporting to accelerate recon, scanning, and triage.

Webcast for SANS Abu Dhabi July 2026 Community Night

The session will demonstrate how AI can be applied as both a SAST and DAST capability for discovering and exploiting zero-day vulnerabilities in web applications, as well as its growing role in binary exploitation.

Threat hunting is no longer just a niche skill—it’s a critical pillar of modern defense.

Do you understand Active Directory? Your enterprise, just like the entire Fortune 500, depends on it.




This poster is aimed at newer C developers coming from other operating systems and switching to Windows.




Offensive Operations coins are awarded to top performers in Capture the Flag challenges at the end of some courses. Each coin features unique artwork tied to its course and hides a cipher. When you collect 8 coins and decipher them all, you win the one coin… the One Coin to Rule Them All!
