Master advanced penetration testing techniques that bypass modern security controls. Develop custom exploits, evade defenses, and attack hardened environments.
Standard penetration testing techniques fail against mature security programs. SEC660 teaches the advanced skills required to assess organizations with sophisticated defensive capabilities.
Execute advanced attacks:
Exploit Development
Develop exploits for modern operating systems
Bypass DEP, ASLR, and other mitigations
Write shellcode for multiple architectures
Create reliable exploits from vulnerabilities
Defense Evasion
Evade endpoint detection and response
Bypass application whitelisting
Avoid network detection systems
Operate without triggering alerts
Advanced Network Attacks
Exploit network protocols and services
Attack Active Directory at scale
Pivot through segmented networks
Maintain persistent access undetected
Python programming experience and solid penetration testing fundamentals required. This is not an introductory course.
Hands-on labs develop and deploy custom exploits against hardened targets.
Earn GIAC GXPN certification (exam sold separately). 46 CPE credits across 6 intensive days.
Highlights
Advanced network attack methodologies. Custom exploit development techniques. Exploit mitigation bypass strategies. Modern fuzzing implementations
Comprehensive hands-on training with 30 practical labs covering: Captive Portal Bypass, Detecting Cryptography Implementations, Detecting Cryptography Implementations, Custom packet manipulation, Custom packet manipulation, Linux buffer overflow exploitation, Linux buffer overflow exploitation, Windows 11 vulnerability analysis and 3 more exercises
Certification: Prepares for Exploit Researcher and Advanced Penetration Tester (GXPN). Earn 46 CPE credits. 6 days of intensive training. Business outcomes: Enhanced threat detection capabilities
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing offers one pricing option: a single-user license for the SEC660 course. You pay per user, billed as a contract. Pricing scales by the number of licenses you buy — one license covers one person. There are no tiers or add-ons in this listing. To train more people, you add more single-user licenses.
Top-of-mind questions for buyers
What does one single-user license cover, and how do I train several people?
One single-user license grants access for one individual. Each person you want to train needs their own license. To cover a team, you add one license per learner. Licenses are counted per user, so the total scales directly with the number of people enrolled.
What does the SEC660 license include for the enrolled user?
The license covers the SEC660 course content: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking. The course spans instructor-led days with hands-on labs and self-paced hours. Access applies to the single enrolled user assigned to that license.
Is this billed once as a contract, or does it renew or meter usage over time?
This is a contract-based purchase priced per single-user license. You pay for the license quantity you select rather than metered usage. Cost changes only when you add or remove licenses, not based on how many hours the user spends in the course.
www.sans.org
Helpful?
Vendor refund policy
Refund requests must be submitted by the deadline date specific to User's training event. To find the specific deadline date for User's training event, please go to training event link at <www.sans.org> and click on the cancellations link.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Bishop Fox Offensive Security Services
Strengthen your security posture with Bishop Fox, the leader in offensive security testing. Our expert-driven services help you proactively identify and remediate vulnerabilities before attackers can exploit them. Delivered through the Bishop For portal, hosted on AWS, you can real-time visibility into assessment findings, secure access to detailed reports, and on-demand remediation. Whether securing your applications, cloud environments, networks, AI initiatives, or products, Bishop Fox helps you stay ahead of threats.
Invinsense OXDR is a threat exposure management suite which helps organizations to run remediation focused Continuous Threat Exposure Management Program. It consolidates various tools like Attack Surface Monitoring, Vulnerability Management, Breach and Attack Simulation, Continuous and Automated Red Teaming and RedOps. It helps organisations to reduce risk through proactive threat exposure management that results in remediation.
Leverage cutting-edge AI tools and techniques to enhance offensive security operations. Learn to automate reconnaissance, exploit development, and post-exploitation activities using machine learning and large language models. 18 CPEs.
Advanced purple team training to simulate sophisticated threat actor techniques through comprehensive adversary emulation. Learn to plan and execute realistic attack scenarios that test and improve defensive capabilities across complex enterprise environments. 36 CPEs.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.