Hey all,
I’m writing up a quick review of the course i’ve just completed, SEC560 Network Penetration Testing and Ethical Hacking. This course aligns to the GIAC GPEN certification
This course is pretty well reviewed so I won’t take to much of your time. I’d ask you to check out a few links, do some searches. One good review is here:
https://www.ethicalhacker.net/forums/viewtopic.php?f=64&t=2177&p=9126&hilit=sec560#p9126. It is an old thread but much of the basics are the same, the daily format/schedule is the same, but the tools and techniques in many cases have been updated.
Now given my work schedule and a lack of desire to spend additional funds on travel (I paid out of pocket), I took the course via Simulcast a format that allows the student to watch the SANS training from home over the internet. On simulcast, i’ll say it is well done, they’ve obviously well prepared for the format and it integrates well into the course. You can ask questions in the simulcast software (A Citrix Go To Training /GTM setup) and they will ask the instructor in near real time so you can actually participate in class, there are moderators online to assist and answer questions. The issue I had with this was that there was rarely confirmation that a question would be asked or when. So i’d ask a question in chat and no one would respond, a minute or two later the moderator would (I suspect) signal the instructor and ask the question. So while I understand not interrupting the class to ask questions, I wish they would acknowledge the question was received and would be asked.
As far my reasons for taking the course, while I have a few hacking certifications the CEH and CPT, I did not feel comfortable with the skillset. I felt like there were large gaps in my knowledge. At my company we may be developing a PT capability so I want to pick up that capability if I can. I want a wide skillset to provide to any employer.
I feel that the SEC560 course provided me some benefit. While it didn’t cover much that was new in terms of the overall process, I was able to understand a little better how a PT works for his client and I got plenty of hands on using techniques and tools that are relevant. Do I still have a lot to learn? Yes, absolutely. My advice for the course is this, get your books out as early as possible and endeavor to go through them before class. At the very least, read up on the content for the next day the night before. Make sure you are not... distracted, either by work or needing sleep, ect. I was working for the first two days so I had to rack out about halfway through, though I had the benefit of having read what we were doing, and I was able to wake up and do the labs I missed.
Course access includes VPN Lab access and the opportunity to participate in Netwars, a CTF, and in our case CyberCity, a new offering from SANS. Also, before I forget, we were able to test a new capability that SANS is deploying that you will all love after having to lug all of your books around.

So NetWars. NetWars is a unique offering by SANS and let me tell you its very fun to get into the lab and start finding answers, especially if they come easily. If they don’t it can be frustrating. Same for cybercity I expect and of course in the Ctf. Make sure you have attack plan when you begin the CTF, my team finished well, but I didn’t feel like I had the biggest impact on that though I had a few ideas that were on the right track.
So all in all, SEC560 is a useful course that I feel will be a benefit to me, my company and my career. I don’t have a date yet for the GPEN exam, I expect to take some time to go through the books, and through the labs until these attacks and the process becomes second nature to me. Thanks for reading.