SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Apply your credits to renew your certifications
Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months
Course material is geared for cyber security professionals with hands-on experience
Apply what you learn with hands-on exercises and labs
Develop essential leadership skills to effectively manage major cyber incidents from discovery to resolution, providing clear direction when your organization needs it most.
Great insights, examples and relevant tools. I applied the 3rd party incident tool within minutes to an ongoing 3rd party incident. So I can't dream of a more relevant and useful course than this.
While technical teams work to identify and remove attackers, they require strategic direction, management, and support to maximize their effectiveness. Cyber Incident Management focuses on the critical non-technical challenges facing leaders during high-pressure security incidents. This course equips you to lead incident management teams by providing a comprehensive understanding of immediate, short, and medium-term challenges organizations face during security breaches.
You will learn to build and manage teams, distill critical data for briefings, and communicate effectively with executives, board members, and other stakeholders. Through nine detailed case studies, you will gain hands-on experience in incident management methodology and practices applicable to various cybersecurity scenarios.
While you cannot predict when a major cyber incident will hit your organization, you can control how ready you are to face it. In the aftermath, when incident response teams are engrossed in unraveling the attacker's moves within your networks, they often find themselves overwhelmed. This is where your incident management team steps in, taking charge of managing findings, communications, regulatory notifications, and remediation. With a multitude of tasks and challenges to address, many teams are unseasoned and unprepared for the magnitude of the responsibilities.
This course equips you to play a leading role in cyber incident management, whether as an incident commander, a manager, a team member, or a stakeholder who needs to guide and support the response. You will gain a comprehensive understanding of the immediate, short, and medium-term issues an organization might encounter. Beyond familiarizing yourself with the terminology, you will grasp preparatory actions at different stages to stay ahead of the situation. LDR553 is designed for efficient management of diverse incidents, with a primary focus on cyber, but you can apply the methodology, concepts, and guidance to various regular major and critical incidents.
Cyber Incident Management (IM) sits above Incident Response (IR) and manages incidents that get too big for the Security Operations Center (SOC) and IR. These tend to be the more impactful or larger scale incidents that IR is not staffed to handle, as these incidents require significant liaison with internal and external partners to coordinate the investigation, forensics, planning, recovery, and remediation, and to brief the corporate comms, C-level staff and board as needed.
A strong IR lead can sometimes fulfill the IM role, but during critical incidents IR teams are often shoulder-deep in malware, systems, logs and images to process, to the point where all technically capable IR staff are kept focused on technical tasks. More business focused than technical, the IM team will take the output from IR and relay it to the necessary teams as they coordinate wider investigations and conduct hardening, hygiene, and impact assessments, planning towards recovery.
"Of my 28 years in cyber security, I've spent over 12 of them in incident response and later incident management. This course is designed to demystify incident management, to provide attendees with a framework to not only deal with the matters at hand, but also to plan for the subsequent phases, so they are technically ready and mentally prepared. When you are prepared and ready, you can respond better and faster, and get control of the situation quicker, facilitating a rapid return to business as usual."
- Steve Armstrong-Godwin


Steve brings 25+ years of cybersecurity experience, including 14+ years in incident response and management. After serving in the UK Royal Air Force, where he led penetration testing teams, he gained expertise in managing cyber incidents globally.
Read more about Steve Armstrong-GodwinExplore the course syllabus below to view the full range of topics covered in LDR553: Cyber Incident Management.
Section 1 focuses on understanding incidents, standardizing language, and defining objectives. You will gather information, set goals for the Incident Management team, and assign responsibilities. The section introduces the Cyber Incident Management Tool Kit (CIMTK), team composition, task tracking, and GenAI support.
Overview
In Section 1 we will focus on understanding the incident, gathering information from different groups, and standardizing our language. To assist in this, students will review some common terms, abbreviations and incident types to ensure we mean communicate accurately. From there we will define what the Incident Management (IM) group will seek to achieve, so we can state and focus on our objectives. The cornerstone of this phase is the Cyber Incident Management Tool Kit (CIMTK), specifically a key component called "The Grid." This comprehensive set of questions and core Incident Management (IM) tasks expedites our response. Identifying these tasks early allows for concurrent activities within support teams (Incident Response, Information Technology, Human Resources, Legal, etc.) and the IM team.
Defining objectives early is important, as retaining focus can be hard when our work gets busy. Once defined, we will leverage the “Commander’s Intent” as a method to brief teams, as we look at how to inform the wider group what our short- and medium-term goals are.
We segway into IM Platforms as we consider what we need to be able to do and where is safest to operate from as we review how attackers access defenders’ infrastructure to prevent their removal from the network.
Recognizing that effective Incident Management hinges on a strong team, we delve into assessing team composition and the unique contributions required from different groups to fulfill the mission. New for 2025, we are then including GenAI on the team bench, and throughout the course we will show how GenAI can augment and support the team. As we close off Section 1, we will consider the contribution from GenAI as we also build our first GPT for class use.
Note: The class uses a SANS provided OpenAI ChatGPT UI for the student’s use. We will extensively leverage this during the course. Students may use their own or different GenAI tools, but we will focus on and support ChatGPT.
Full Lab Details
Full Topic Details
Section 2 explores communications in great depth as we look at interactions with executives, attackers, our staff and the public/customers. You will learn approaches that can buy time to address issues and prevent data leaks. You will categorize network and data damage, prioritize remediation tasks, and eliminate vulnerabilities.
Overview
Following a quick recap, we commence a focused exploration of crisis communications, beginning with executive briefings on incident scope, objectives, and forward plans, using the Three What’s approach. From there, we examine strategies for managing communications with threat actors. While ransom payment may not feature in an organization’s plans, engaging in dialogue can sometimes buy valuable time to address vulnerabilities they have exposed or to avert potential data leaks. This is, of course, a contentious practice, with varying opinions across the industry; nonetheless, understanding the available options is essential. Lessons and labs will guide students through how such dialogue might occur, and the factors influencing both decision-making and process design.
We then turn to the remediation of network and data damage. Students will receive in-depth training in categorizing the impact of attacker activity, mapping the required remediation work, prioritizing actions, and ensuring all vulnerabilities are addressed. Particular attention will be paid to the often-overlooked presence of secrets within stolen data or compromised systems, and the implications these may have for future operations.
In the reporting and documentation phase, we review outputs from the Incident Management (IM) process. While a strong Incident Response (IR) report is important, students will explore additional elements needed to adapt it for IM purposes. This integration is vital, as Incident Management frequently guides the direction of Incident Response, allowing for a more coherent report and enabling the delegation of certain aspects to appropriate teams.
Finally, when planning for incident closure, we examine which remediation and vulnerability management tasks should transition into standard operational projects rather than remain under incident status. We will define effective reflection sessions to capture Root Cause Analysis (RCA) outputs and lessons learned, introducing the Five Whys method with examples of both strong and flawed applications.
The GenAI support on Section 2 is focused on producing briefs and formatting unstructured text for a consistent style and layout. Additionally, we use it for parsing information for a second opinion on received communications and ours before transmission to wider groups. More importantly we show how to cross-check before releasing work under our own name and reputation.
Full Lab Details
Full Topic Details
Section 3 explores training IR teams and the broader organization. You will learn to develop effective training programs based on organizational maturity and specific needs. We examine integrating Cyber Threat Intelligence (CTI) into IR efforts and deep dive into developing strategies for managing supply chain and third-party compromises.
Overview
In this section, we dive deep into the training of Incident Response (IR) and Incident Management (IM), not only within our own teams but extending to the wider organization. We will explore the imperative need for training, considering the type of training required based on organizational maturity. Students will gain practical insights engaging in hands-on labs, including an exercise exemplifying the onboarding of non-IR personnel to cyber incidents.
Turning our attention to team training, we assess historical practices and their limitations in fostering individual growth and development. Emphasizing both long-term training strategies and engaging tactical exercises, we address specific gaps and areas where practical experience is needed, moving beyond mere frequency compliance.
Delving into the realm of Cyber Threat Intelligence (CTI), often featured prominently in the press, we address the common challenge of integrating CTI effectively into IR/IM efforts. Beyond its acquisition, we tackle the issue of maintaining CTI availability during an incident. Equipping participants with critical knowledge and a prep list, we empower them to leverage high-quality CTI during a Ransomware incident, supporting IR/IM efforts and executive decision-making. Furthermore, we explore how to provide input to the CTI team to optimize their skills and tools for local and strategic needs.
With the increasing prevalence of supply chain or third-party compromises, we extensively dissect the limitations when handling these incidents and strategies to improve our position. Through an in-depth case study of our Submarine Studios, we guide students to understand the scope, impact, and immediate remediation options, as well as investigative actions falling within our purview. We unravel the intricacies of planning a call with the third party, ensuring clarity of objectives, and navigating scenarios where required information may not be readily available. Lastly, we tackle the crucial aspect of when and how to effectively close a third-party incident.
The GenAI elements of Section 3 again fall into either validating the Incident Commanders ideas or parsing external information to simplify and clarify the meaning. This significantly unburdens the leaders allowing them time to focus on response. We will again build several bespoke GPTs to further enhance the tuning of our needs and to speed up future use of the configuration.
Full Lab Details
Full Topic Details
In section 4 you will gain a comprehensive view, visualize incident timelines and address complex attack scenarios. You will learn to create timelines tailored to different audiences, understand credential theft attacks and the MITRE framework, and explore Business Email Compromise (BEC), as well as cloud-based attacks and management console breaches.
Overview
In response to the escalating complexity of incidents, our focus turns to visualizing key facts, with timelines as a powerful tool. However, we stress the importance of careful scoping, because a poorly conceived timeline that is not tailored to the target audience risks confusion and fails to convey the intended message. Our exploration delves into the art of scoping timelines, exploring various styles, and drawing insights from case studies that exemplify different perspectives on the same incident.
Before delving into Business Email Compromise (BEC) and other Cloud-focused attacks, we clarify aspects of responsibility and attack focuses, referring to prevalent cloud and MITRE models. Credential attacks take center stage, probing what attackers seek to obtain and how they leverage credentials, intricately linking back to the MITRE framework. We analyze attacker options, from breaking in and harvesting credentials to purchasing access. We scrutinize concepts like Initial Access Brokers, Underground Marketplaces, and various user targeting strategies, including MFA fatigue and Illicit Consent Attacks.
With stolen credentials as our foundation, we embark on an in-depth exploration of BEC, elucidating its stages and examining the crucial Incident Management (IM) support it necessitates. This extends to supporting legal arguments, determining liability, and directing Incident Response (IR) efforts for forensics. Addressing the aftermath of a third-party compromise, we unravel the complexities of discussions where a supplier's compromise impacts the client's financial loss.
We continue by dissecting the nuances of the six-plus types of BEC attacks, delineating the attacker's position and the affected parties. Our detailed breakdown serves as a template for easier BEC investigations, complemented by a hands-on lab in which we challenge participants with an underrated investigative influence: Doubt in everything you see and are told.
Navigating the cloud model, our focus shifts to Infrastructure as a Service (IaaS) host compromise, examining vectors, impacts, investigation requirements, and the nuanced management of cleanup for completeness.
We explore cloud management console compromises, assessing their impact, investigative approaches, and the requisite cleanup strategies. We also touch on preventive controls and the origins of the attacker's credentials, emphasizing that, for certain attackers, the management console is a means to an end, shaped by attacker motivation rather than the defensive measures of the blue team.
We conclude this section by looking at how to improve the team by working with others, linking to other teams and groups. We will consider KPIs and internal metrics: what they can show you, and what they can hide. As IM is largely focused on big impact incidents, we will look at the wider DR for the organization and how you can tap into those teams, processes and exercises for a smoother operation.
There are no set GenAI labs for this Section as the labs focus around updating and reviewing progress in various trackers, something that GenAI struggles with. Additionally, the BEC is too complex for GenAI to reliably identify the attacker or the altered documents. This reinforces the fact that GenAI is a great support tool but cannot replace all the activities of a capable IR and IM team.
Full Lab Details
Full Topic Details
Section 5 examines AI applications, including Large Language Models and Generative AI. You will gain in-depth knowledge of ransomware incidents from examining historic cases and considering how to prepare and train to deal with encryption events.
Overview
In this final section, we will address some of the wider issues organization’s face when dealing with ransomware. Before doing so, we conclude our Submarine Studios scenario by considering a return to the public domain with a final press statement announcing the arrest of our attackers. This transitional lab challenges students to consider the notion that “there is no such thing as bad PR.”
Having made extensive use of Generative AI throughout the course, it is essential to conclude by examining the potential pitfalls and threats associated with its use. We begin by unpacking the often loosely applied term Artificial Intelligence, breaking it into its distinct categories — including Natural Language Processing (NLP), Neural Networks, Generative AI, Machine Learning, and Robotics — before narrowing our focus to Large Language Models (LLMs) and Generative AI tools (such as ChatGPT).
With this clearer understanding, we can make more informed decisions about where, when, and how to apply these technologies effectively. We will also address the inherent risks of AI, with particular attention to the issue of hallucinations, and explore strategies to minimize their impact.
Finally, as part of our LLM exercise, students will engage with a deliberately compromised chatbot to assess its behavior, identify indicators of compromise, and determine whether vulnerabilities are present. This hands-on investigation mirrors the real-world incident in which Submarine Studios’ third-party provider was compromised, enabling participants to connect theoretical learning with a practical case study.
Ransomware dominates cybersecurity headlines and remains one of the most significant threats keeping CISOs and Boards awake at night. In this section, we will explore its evolution — from early attacks to the sophisticated operations of today — and dissect the stages of a ransomware compromise. Students will examine where detection opportunities were missed as attackers progressed from initial access to the final stage of encryption.
We will discuss how to direct the Incident Response (IR) team in investigating the attack, while examining the Incident Manager’s (IM) role in coordinating efforts, maintaining context, and pressing executives for timely decisions. Building on knowledge from earlier sessions — including team exercises, planning, cloud compromises, and credential-based attacks — we will develop strategies to reduce the impact of ransomware incidents and preserve both network integrity and organizational operations.
Students will analyze the alerts commonly signaling the onset of a ransomware event, linking them to specific stages of the attack and clarifying what has occurred. We will cross-map these indicators with potential “instant checks” and consider how automation could provide early warning during an adversary’s preparatory phase.
Clear, decisive communication will be a recurring focus — ensuring that executives fully understand the available options and their consequences. We will introduce the concept of “no-regret” options and discuss the operational implications of “going dark.” Building on earlier discussions of attacker engagement, we will explore the planning and execution of ransom negotiations, supported by practical exercises.
Finally, we will address the importance of conducting investigations in parallel with remediation, enabling the organization to prevent repeat compromises regardless of the decision to pay or refuse a ransom. We will consider the technical and procedural requirements for network rebuilding and identify the records and evidence needed to support recovery. Students will also recognize the critical value of documenting all decisions, recording impacts, and maintaining detailed system and availability data — ensuring that in the inevitable hindsight review, there is a complete and accountable record of who knew what, when, and where.
Full Lab Details
Full Topic Details
Important! Bring your own system configured according to these instructions!
A laptop or mobile device with the latest web browser is required to access the Cloud stored files (Google Docs or Dropbox) that form the Cyber Incident Management Tool Kit (CIMTK) used in the course.
The CIMTK used in this course was built and is hosted on Google Drive and Google Suite. Students must have a computer that can connect to either Dropbox or Google Suite services. Corporate machines may have a VPN, intercepting proxy, or egress firewall filter that causes connection issues communicating with AS. Students must be able to configure or disable these services to be able to access Google Suite.
Due to the interoperability between MS Office and Google Docs and Google Spreadsheets, students will be able to complete all course labs using MS Office. Some of the takeaway files and components of the CIMKT were built on Google Spreadsheets, and we are 99% confident that they will work on MS Office. However, due to the frequent updates and changes to both platforms we cannot guarantee this, so students will be asked to use Google Docs if they find their Office-based program is not functioning as expected.
Students will be issued a SANS ChatGPT account for use during the course. While they are welcome to use other Generative AI tools, primary support will be provided for the OpenAI-based toolset.
If you have additional questions about the laptop specifications, please contact customer service.
LDR553 training is recommended for a diverse range of individuals, including:
The GIAC Cyber Incident Leader (GCIL) certification validates a practitioner’s ability to manage cyber incidents and lead a diverse incident management (IM) team to restore normal operations. GCIL holders demonstrate expertise in preparing for, assessing, handling, tracking, and documenting incidents; developing IM teams; managing vulnerabilities, threats, and attacks; facilitating communication; and improving IM processes.
This course covers the core areas of cyber incident management and assumes a basic understanding of technology, networks, and security. For those new to the field with no background knowledge, the recommended starting point is SEC401: Security Essentials – Network, Endpoint, and Cloud.
LDR553: Cyber Incident Management is part of the SANS Cybersecurity Leadership curriculum and the Cyber Risk Officer Triad, alongside LDR512: Security Leadership Essentials for Managers and LDR519: Cybersecurity Risk Management and Compliance. Together, these three courses provide a holistic blueprint for modern cyber risk officers—whether stepping into leadership from technical ranks or leveling up within executive roles. The triad develops leaders who not only understand how to build, govern, and respond, but who can unify teams under pressure and steer organizations through complexity with clarity and resilience.
Cyber Incident Management coordinates the response to significant security breaches that overwhelm regular SOC/IR teams. It focuses on business impacts, stakeholder communications, and strategic decisions rather than on technical details. Managers lead cross-functional teams, communicate with executives, and orchestrate recovery while IR handles technical investigation.
This is a unique offering, no other vendor covers Incident Management in such depth, supported by an entire-course real-world scenario where every lab is based upon a real case handled by the author a veteran of IR and IM. This course develops highly in-demand leadership skills for managing critical incidents. You will gain expertise in team coordination, executive communication, and strategic decision-making during cyber crises—capabilities increasingly needed as organizations face sophisticated attacks. The practical case studies provide confidence in handling real-world scenarios, positioning you for advancement to security leadership roles.
Lead cybersecurity risk strategy at the highest level.
Explore learning pathCo-ordination of detection, response, and recovery activities across teams and systems. Emphasis is placed on minimising impact, restoring services, and maintaining clear communication during disruptions.
Explore learning pathMonitor the organisation’s cybersecurity state, handle incidents during cyber-attacks and assure the continued operations of ICT systems.
Explore learning pathResponsible for managing the cybersecurity of a program, organization, system, or enclave.
Explore learning pathDaily focus is on the oversight of technical teams while aligning them to overall business strategies. Includes titles such as Technical Director, Information Security Officer, and CISO.
Explore learning pathDevelopment of frameworks that align technology use with business objectives and regulatory requirements. Focus areas include policy design, risk controls, and enterprise accountability structures.
Explore learning pathResponsible for developing and conducting cybersecurity awareness, training, or education.
Explore learning pathSecurity Operations Center (SOC) managers bridge the gap between business processes and the highly technical work that goes on in the SOC. They direct SOC operations and are responsible for hiring and training, creating and executing cybersecurity strategy, and leading the company’s response to major security threats.
Explore learning pathEnroll your team as a group or arrange a private session for your organization. We’ll help you choose the format that fits your goals.
It was awesome to have the opportunity to apply existing and newly learned skills to the labs. It was obvious that a significant amount of time had been invested in these.
The hands-on experiences and assignments have been exceptional and have significantly contributed to my learning experience.
This is a great course for incident managers or anyone that could be put into the firing line of dealing with incidents.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources