本文整理日期:2026 年 7 月 16 日。
SEC598 課程與 GASAE 考試仍可能持續更新,報名及考試前請再次確認 SANS、GIAC 官方頁面。
最近社群裡有人詢問:
大家早安,抱歉打擾了,請問有大大考過 SANS 的 SEC598: AI and Security Automation for Red, Blue, and Purple Teams 這張證照嗎?
這個問題裡有一個容易混淆的地方:
- SEC598 是 SANS 的課程名稱。
- GASAE 才是對應的 GIAC 證照名稱。
- GASAE 全名是 GIAC AI Security Automation Engineer。
這篇文章會整理:
- SEC598 與 GASAE 的定位。
- 官方公布的課程及考試資訊。
- 網路上實際考生與學員的討論。
- 課程每天可能接觸的工具與能力。
- GASAE 的準備方式。
- Index、Lab Index 與 CyberLive 準備方法。
- 8 週讀書計畫。
- 適合與不適合報考的人。
- 原始討論內容及來源網址。
一、SEC598 與 GASAE 到底是什麼?
SANS SEC598 的完整名稱是:
AI and Security Automation for Red, Blue, and Purple Teams
對應證照是:
GIAC AI Security Automation Engineer(GASAE)
根據 GIAC 官方定位,GASAE 驗證的是考生能否把自動化與人工智慧實際運用在:
- Offensive Security
- Defensive Security
- Cloud Security
- Incident Response
- Security Orchestration
- Infrastructure Automation
- Adversary Emulation
- Detection Engineering
換句話說,這不是一張只考 AI 名詞、Prompt Engineering,或單純介紹 LLM 的證照。
它真正關心的是:
你能不能把腳本、IaC、SOAR、雲端服務、攻擊模擬、偵測工程與 AI Agent,組合成可以實際運作的資安流程?
GIAC 官方列出的能力包含:
- 自動化資產探索、組態管理與事件應變流程。
- 使用自動化攻擊工具與 Adversary Emulation 找出弱點。
- 部署腳本與設定,修復 Windows、Linux 主機。
- 將 LLM、RAG、Agentic AI 應用於偵測及回應。
- 使用腳本、Infrastructure as Code 與紅藍隊協作工具建立自動化。
- 分析主機 Artifact,並把自動化整合進 SOC。
- 建立 Azure、AWS 的安全監控及事件回應流程。
- 使用攻擊鏈與 Breach and Attack Simulation 驗證防禦能力。
官方網址:
- SANS SEC598
https://www.sans.org/cyber-security-courses/ai-security-automation - GIAC GASAE
https://www.giac.org/certifications/ai-security-automation-engineer-gasae
二、課程與考試的基本資料
SEC598 課程資訊
依 SANS 官方頁面目前公布的資訊:
| 項目 | 內容 |
|---|---|
| 課程名稱 | SEC598: AI and Security Automation for Red, Blue, and Purple Teams |
| 對應證照 | GIAC AI Security Automation Engineer(GASAE) |
| 課程長度 | 6 天講師課程/36 小時 Self-Paced |
| 難度 | Intermediate |
| CPE | 36 CPEs |
| 實驗數量 | 25 個 Hands-On Labs |
| 授課形式 | 實體、Live Online、Self-Paced |
| 課程作者 | Jeroen Vandeleur、Jason Ostrom |
官方特別標示,這門課是給已經具備資安實作經驗的人,並不是完全從零開始的入門課。
GASAE 考試資訊
依 GIAC 官方頁面,GASAE 為 Practitioner Certification,並包含 CyberLive。
| 項目 | 官方資訊 |
|---|---|
| 考試形式 | 1 場監考考試 |
| 題數 | 82 題 |
| 時間 | 3 小時 |
| 及格標準 | 70% |
| 實作形式 | CyberLive Performance-based Challenges |
GIAC 說明,70% 的及格標準適用於取得 2026 年 4 月 10 日或之後發布之考試版本的考生。GIAC 仍可能透過 psychometric standard-setting study 調整考試規格,因此實際考試前仍應以個人 GIAC 帳戶顯示內容為準。
GIAC 對 CyberLive 的說明包括:
- 在完整虛擬機環境中操作。
- 使用業界真實安全工具。
- 操作真實程式碼、服務及攻防情境。
- 以 Performance-based Challenge 驗證實際能力。
因此,GASAE 並不是只靠紙本教材與 Index 就能處理的傳統選擇題考試。
官方網址:
https://www.giac.org/certifications/ai-security-automation-engineer-gasae
Open Book、跳題與休息規則
GIAC Practitioner 考試採 Open Book 形式,考生可攜帶紙本教材、紙本書籍、手寫或列印筆記及 Index,但不得使用電子文件、網路、手機、平板、智慧手錶、USB 裝置或額外電腦。外觀類似練習題、考題與答案整理的紙本資料也禁止攜入。
考試操作上還要注意:
- 已送出的答案不能返回修改。
- 依考試版本可跳過約 10–15 題。
- 可使用
Answer Skipped回答先前跳過的題目。 - 若時間允許,跳過的題目會在考試結束前自動再次顯示。
- 最終未作答的題目會計為錯誤。
- 考試提供共 15 分鐘休息時間,可一次使用或分成兩次較短休息。
官方規則:
https://www.giac.org/knowledge-base/proctor
考試費用與續證成本
依 GIAC 目前官方價格表,GASAE 費用如下。價格可能調整,付款前應再次確認官方頁面。
| 項目 | 費用(USD) |
|---|---|
| Certification Attempt | $999 |
| Exam Retake | $899 |
| Attempt Extension | $479 |
| Certification Renewal | $499 |
| Practice Exam | $399 |
官方價格頁:
https://www.giac.org/pricing
GASAE 與其他 GIAC 證照一樣,證照有效期為四年。續證註冊會在到期前兩年開放;持證者需在四年有效期內累積並提交符合規定的 CPE,並支付續證維護費。GIAC 課程、新取得的 GIAC 證照及部分專業活動可提供 CPE;實際可計入的數量與證明文件要求應依 GIAC Renewal 規則辦理。
官方續證資訊:
https://www.giac.org/knowledge-base/renewal
三、為什麼網路上的 GASAE 心得很少?
GASAE 是一張很新的證照。
Reddit 上 2026 年初的討論指出:
- 搭配 SEC598 課程購買的考試於 2026 年 2 月開始提供。
- GASAE 於 2026 年 4 月 10 日開放一般購買。
- 早期有部分完成 SEC598 的學員受邀參加 Beta Exam。
因此,截至 2026 年 7 月,網路上還沒有像 OSCP、GSEC、GCIH 那樣累積大量考試心得。
目前能找到的內容主要分成四類:
- SANS 與 GIAC 官方課綱。
- 課程作者的介紹。
- 上過 SEC598 的學員分享。
- 少數 GASAE Beta/正式通過者的短篇心得。
這代表本文可以整理出準備方向,但不能可靠地提供:
- 題型精確比例。
- 哪一本教材占幾成。
- 必考哪幾個 CyberLive Lab。
- Practice Test 與正式考試固定難度差。
- 通過率。
- 題庫重複程度。
任何人在目前階段給出非常精確的「必考題型比例」,都應保留看待。
四、網路上大家怎麼討論 SEC598/GASAE?
討論一:已通過 GASAE 的考生心得
Reddit 上一位使用者表示,自己在前一年 10 月完成 SEC598,後來受邀參加 GASAE Beta Exam,並收到通過通知。
他的原文重點是:
“Out of all the courses I’ve done so far – this has been my favourite.”
在留言中,他補充:
“Favourite course out of the 9 I’ve done.”
他認為 Security Automation 是必要能力,也已經在工作中看到課程 Lab 的應用情境。
被問到什麼背景對課程與考試最有幫助時,他表示:
“if you have experience on doing IaC, scripting and used SOAR before – you’re in a very good spot.”
至於考試,他的個人感受是:
“Exam was good and nothing too complicated.”
如何解讀這篇心得?
可以整理出三個訊號:
- IaC、腳本與 SOAR 是重要先備能力。
- 課程的 Lab 有機會直接轉換成工作中的使用案例。
- 對已有相關經驗的人,考試可能不至於過度刁鑽。
但必須注意:
- 這是單一考生的個人經驗。
- 他參加的是 Beta Exam。
- 他已經完成過九門 SANS 課程,GIAC 考試經驗可能遠高於一般考生。
- 「不複雜」不等於「完全沒有基礎也容易」。
原始討論:
討論二:新證照公開時的社群反應
另一篇 Reddit 討論整理了 GASAE 推出時的官方範圍,包括:
- 資產探索。
- 組態管理。
- Incident Response Automation。
- 自動化攻擊工具。
- Adversary Emulation。
- Windows/Linux 修復。
- LLM、RAG、Agentic AI。
- IaC。
- SOC Integration。
- Azure/AWS Security Automation。
- Automated Attack Chaining。
- Breach and Attack Simulation。
留言中有已上過課、收到 Beta Exam 邀請的人表示:
“Really liked the course.”
這篇討論的價值比較偏向確認證照推出時程與官方範圍,對實際考試難度沒有太多資訊。
原始討論:
討論三:課程廣度是否太大?
早期 SEC598 還沒有 GASAE 證照時,Reddit 上就有人討論這門課值不值得上。
其中一個較批判的意見認為:
- Security Automation 涵蓋的技術太廣。
- 與其每一種工具都學一點,不如先深入學 Terraform,再搭配 Ansible、Puppet 或 Chef。
- 如果完全自費,以 SANS 的價格上廣泛介紹型課程,是否值得需要評估。
- 有人可能更傾向選 SEC540,再自行補自動化技術。
這個意見的核心不是否定 Security Automation,而是質疑:
課程會不會因為範圍太大,導致每個工具只能學到入門?
原文部分內容:
“the spread of automation technology is way too wide.”
“I’d pick terraform and one of the other automation techs … and then become good at that.”
課程作者的回應
SEC598 課程作者在同一篇討論中回應:
- 課程來自真實的安全自動化與 Orchestration 導入經驗。
- 不只是比較工具。
- 會把工程能力轉成 Offensive、Defensive Playbook。
- 課程希望實現 Continuous Purple Teaming。
- 當時約 50% 的內容是 Hands-On Lab。
- 會使用 Terraform、Ansible 與 User Data Services 建立可重複使用的 Firing Range。
換句話說,作者對課程的定位是:
不是把每個自動化工具介紹一遍,而是教你如何把不同技術整合成可執行的資安情境。
原始討論:
如何解讀這場爭論?
兩邊其實都合理。
如果你的需求是:
- 深入成為 Terraform 專家。
- 深入學習 Ansible。
- 專精某一套 SOAR。
- 專攻 AWS 或 Azure。
- 專攻 LLM Application Security。
SEC598 不一定是最有效率的單一技術深挖課程。
但如果你的需求是:
- 了解完整 Security Automation 架構。
- 把紅隊、藍隊、雲端與 AI 串在一起。
- 建立 Continuous Purple Team。
- 把 Detection、Attack Simulation、SOAR、IaC 接進 CI/CD。
- 從實際情境理解各工具如何協作。
SEC598 的廣度反而就是它的價值。
討論四:開發者適不適合上?
有開發者在 Reddit 詢問:
- SEC598 是否適合 Developer 往資安應用發展。
- Red Team Agent 會教到多深入。
- 因為證照太新,找不到足夠評論。
這個問題目前沒有累積足夠完整的學員回答,但從官方課綱可以做出合理判斷:
開發者若已經具備以下能力,會有明顯優勢:
- Python 或 PowerShell。
- REST API。
- JSON、YAML。
- Git。
- CI/CD。
- 雲端基礎。
- Terraform 或其他 IaC。
- 基本資安與攻防觀念。
但開發能力不能完全取代:
- SOC 流程。
- Incident Response。
- Detection Engineering。
- MITRE ATT&CK。
- Adversary Emulation。
- Windows/Linux Artifact。
- SOAR Playbook 設計。
原始討論:
五、2025 年課程曾大幅改版
SANS 在 2025 年介紹 SEC598 更新時,表示課程有約 40% 的內容調整,更深入整合:
- Generative AI
- Large Language Models
- Agentic AI
- Autonomous Red Team Agents
- Cloud-native Detection Pipelines
- SOAR Automation
- LLM-powered Detection as Code
- Continuous Adversary Emulation
- AI-driven Response Workflows
因此,閱讀舊心得時必須注意年份。
2022~2024 年的 SEC598 討論仍可用來理解:
- Security Automation。
- IaC。
- SOAR。
- Cloud Automation。
- Purple Team。
但不能直接代表 2025 改版後的 AI、RAG、Agentic AI 比重。
官方 Webcast:
https://www.sans.org/webcasts/update-sec598-automate-security-generative-ai
YouTube 版本:
六、SEC598 六個 Section 的完整整理
以下依 SANS 官方課綱整理。
Section 1:Foundations of GenAI, LLMs, & Security Automation
第一部分建立 Security Automation 與 AI 的共同基礎。
主題
- 為什麼現代資安需要自動化與 AI。
- Security Engineering 與 CI/CD。
- Configuration Management。
- Policy as Code。
- Automation Trigger。
- SOAR Workflow。
- Detection as Code。
- Generative AI。
- LLM。
- RAG。
官方列出的 Lab
- One Bucket Is All It Takes
- OS Hardening Baselines with Ansible
- Link Triggers to Automation Scripts
- Intro to LLM and RAG
- Detection as Code I: Write a Detection Using LLM
應準備的能力
- Automation 與 Orchestration 的差異。
- Trigger、Action、Condition、Workflow、Playbook。
- Policy as Code 與 Configuration as Code。
- LLM、Token、Context Window。
- Embedding、Vector Database、Retrieval。
- RAG 與 Fine-tuning 的差異。
- Hallucination 與 Grounding。
- 使用 LLM 產生 Detection 時的驗證方式。
Section 2:Security Automation Engineering & AI Workflows
第二部分是整門課重要的工程基礎。
官方提到的工具
- PowerShell
- Terraform
- Ansible
- Python
- Jupyter Notebook
- Tines
官方列出的 Lab
- OS Hardening Baselines with PowerShell
- Cloud Management with Terraform
- Deploying a Firing Range with Terraform and Ansible
- Email Threat Analysis with Jupyter Notebook
- Creating a Tines Story
應準備的能力
PowerShell
- Cmdlet 與 Pipeline。
- Object-based Pipeline。
- 執行 Script。
- 錯誤訊息判讀。
- Windows 組態與修復。
- Execution Policy 與權限概念。
Terraform
- Provider。
- Resource。
- Variable。
- Output。
- Module。
terraform initterraform planterraform apply- State 的用途。
- Credential 與 Secret 管理。
- Infrastructure Drift。
Ansible
- Inventory。
- Playbook。
- Task。
- Role。
- Module。
- Idempotency。
- Windows/Linux Host Management。
- 與 Terraform 的分工。
Python/Jupyter
- HTTP Request。
- JSON 解析。
- IOC 擷取。
- Email Header 或內容分析。
- Data Enrichment。
- Notebook Cell 與執行順序。
- 套件與環境錯誤。
Tines
- Story。
- Event。
- Action。
- Trigger。
- Webhook。
- Credential。
- JSON Path。
- API Integration。
- Human Approval。
- Retry 與 Error Handling。
Section 3:Cloud Automation & AI Security Services
第三部分聚焦 Azure、AWS 與 Cloud-native Security Automation。
主題
- Azure、AWS 安全治理。
- Cloud-native Security Monitoring。
- Automated Enforcement。
- Microsoft AI Services。
- AWS Bedrock。
- Cloud-native Incident Response。
- 第三方 API 整合。
- AI Agent 對 Kubernetes 的攻擊模擬。
- Continuous Security Testing。
AWS 建議準備
- IAM。
- CloudTrail。
- CloudWatch。
- EventBridge。
- Lambda。
- Step Functions。
- AWS Config。
- Security Hub。
- GuardDuty。
- Systems Manager。
- S3。
- Bedrock。
- EKS/Kubernetes。
典型流程:
GuardDuty Finding
→ EventBridge
→ Lambda 或 Step Functions
→ 查詢 CloudTrail
→ Enrichment
→ 隔離、標記或修復資源
→ 通知 SOC
→ 保存處理紀錄
Azure 建議準備
- Microsoft Sentinel。
- Analytics Rule。
- Incident。
- Automation Rule。
- Playbook。
- Logic Apps。
- Microsoft Defender for Cloud。
- Azure Policy。
- Azure Monitor。
- Log Analytics。
- Microsoft Entra ID。
- Managed Identity。
- Azure Functions。
- Event Grid。
典型流程:
Sentinel Alert
→ Incident
→ Automation Rule
→ Logic Apps Playbook
→ Enrichment
→ 人工核准或自動回應
→ 更新 Incident
Section 4:Offensive Security Automation
第四部分把自動化工程能力套用到 Offensive Security。
工具與方向
- Atomic Red Team。
- MITRE Caldera。
- Adversary Emulation。
- Attack Chaining。
- Cloud Attack Simulation。
- CrewAI/Red Team Agent。
- Tines。
- GitHub。
- Adversary Emulation as Code。
應理解的概念
- MITRE ATT&CK Tactic、Technique、Procedure。
- Atomic Test。
- Adversary Profile。
- Caldera Agent。
- Operation。
- Automated Attack Chain。
- Breach and Attack Simulation。
- Adversary Emulation 與 Penetration Testing 的差異。
- 攻擊成功不代表偵測成功。
- Cleanup 與環境重設。
- 將攻擊測試整合進 CI/CD。
- 自動化攻擊工具的安全邊界。
典型 Purple Team 閉環:
選擇 ATT&CK Technique
→ 執行 Atomic Test 或 Caldera Operation
→ 確認 Endpoint/Cloud Telemetry
→ 驗證 Detection Rule
→ 調整規則
→ 重新執行攻擊
→ 記錄 Coverage
Section 5:Defensive Security Automation
第五部分把自動化用於 SOC、DFIR、Incident Response 與 Detection Engineering。
官方課綱涉及的工具及方向
- Velociraptor。
- Timesketch。
- PowerShell IR Playbook。
- Tines IR Playbook。
- LLM-assisted Detection Testing。
- Detection as Code。
- Purple Team Detection Playbook。
- Artifact Collection。
- Data Enrichment。
應準備的能力
- Event、Alert、Incident 的差異。
- Process、Network、File、Registry、Event Log Artifact。
- Triage 與完整鑑識的差異。
- Velociraptor Artifact/Query 的基本概念。
- Timeline Analysis。
- IOC Enrichment。
- 證據保存。
- 自動隔離的風險。
- 自動刪除可能破壞證據。
- False Positive、False Negative。
- Detection Rule Testing。
- CI/CD 中的 Detection Validation。
Detection as Code 可整理成:
攻擊技術或偵測需求
→ 撰寫規則
→ 語法檢查
→ 單元測試
→ 產生測試資料
→ 執行 Adversary Emulation
→ 確認遙測
→ 驗證規則
→ Code Review
→ 部署
→ 持續監控及調整
Section 6:Security Automation Capstone
第六天是完整 Capstone。
官方說明指出,學員會以團隊形式完成多個關卡與任務,驗證環境中是否具備偵測與防禦能力。
Capstone 最值得記錄的不是單一 Flag 或答案,而是:
- 任務目標如何拆解。
- 用到哪些工具。
- 資料如何跨工具流動。
- 哪一個步驟失敗。
- 如何定位錯誤。
- 如何證明攻擊成功。
- 如何證明偵測成功。
- 如何證明修復完成。
- 如何重複執行並得到一致結果。
七、GASAE 官方能力領域整理
GIAC 官方目前列出的考試目標可歸納為以下十類。
1. Security Automation Fundamentals
要理解:
- 什麼工作適合自動化。
- 什麼工作不應完全自動化。
- Human-in-the-loop。
- Retry、Rollback、Error Handling。
- 自動化風險。
- 權限最小化。
- Secret 管理。
- 可觀測性與稽核紀錄。
2. Automating Workflows
要理解:
- Python、PowerShell。
- JSON、YAML。
- REST API。
- Webhook。
- Git。
- CI/CD。
- Terraform。
- Ansible。
- Jupyter Notebook。
3. SOAR
要理解:
- Trigger。
- Action。
- Event。
- Playbook。
- Credential。
- API Integration。
- Enrichment。
- Case Management。
- 人工核准。
- 防止重複執行。
4. Artificial Intelligence Fundamentals
要理解:
- LLM。
- Token。
- Context Window。
- Prompt。
- Embedding。
- Vector Database。
- Chunking。
- RAG。
- Hallucination。
- Grounding。
- Tool Calling。
- Agent Loop。
- Agent Memory。
- Guardrail。
- Model 與 Agent 的差異。
5. Automating Offensive Workflows
要理解:
- Autonomous Red Team Agent。
- Attack Simulation。
- Attack Chaining。
- Cloud Adversary Emulation。
- Control Validation。
- 攻擊流程的安全限制。
6. Adversary Emulation Fundamentals
要分清楚:
- Vulnerability Scanning。
- Penetration Testing。
- Red Teaming。
- Adversary Emulation。
- Breach and Attack Simulation。
- Purple Teaming。
7. Defensive Security Automation
要理解:
- Agent Deployment。
- Artifact Collection。
- Triage。
- Enrichment。
- Automated Containment。
- SOC Integration。
- Evidence Preservation。
8. Detection Engineering 與 Incident Response
要理解:
- IR Lifecycle。
- Detection as Code。
- Rule Testing。
- LLM-assisted Detection。
- SOAR Playbook。
- Threat Intel Enrichment。
- Automated Response。
- Revalidation。
9. AWS Security Automation
要理解:
- Finding 如何觸發 Workflow。
- AWS Service 間如何串接。
- IAM Role 與最小權限。
- Logging。
- Automated Remediation。
- Bedrock Agent 與安全流程。
10. Azure Security Automation
要理解:
- Sentinel Incident。
- Automation Rule。
- Logic Apps Playbook。
- Defender for Cloud。
- Azure Policy。
- Managed Identity。
- Monitoring 與回應。
八、哪些先備能力最重要?
根據官方課綱與通過者心得,建議把先備能力分成五組。
1. 程式與資料格式
至少要能:
- 閱讀簡單 Python。
- 閱讀 PowerShell。
- 修改 JSON。
- 修改 YAML。
- 看懂 HTTP Request/Response。
- 使用 REST API。
- 判斷 API Token、Header、Body、Status Code。
- 從錯誤訊息定位問題。
不一定要能從零寫出大型工具,但至少不能看到腳本就完全無法理解。
2. IaC 與系統管理
至少要知道:
- Terraform
init、plan、apply。 - Terraform State。
- Provider、Resource、Variable。
- Ansible Inventory、Playbook、Task。
- Windows、Linux 基本系統管理。
- Git Commit、Branch、Pull Request。
- CI/CD 基本概念。
3. SOC 與 Incident Response
至少要理解:
- SIEM 與 SOAR。
- Alert 與 Incident。
- IOC 與 Artifact。
- Triage。
- Enrichment。
- Containment。
- Eradication。
- Recovery。
- 自動隔離與人工核准。
4. Red/Purple Team
至少要理解:
- MITRE ATT&CK。
- Atomic Red Team 的用途。
- Adversary Emulation。
- Attack Chain。
- 防禦驗證。
- 攻擊成功與偵測成功是不同事情。
- 如何建立測試、偵測、修正、重測的閉環。
5. AI 與 Agent
至少要能解釋:
- LLM。
- RAG。
- Embedding。
- Agent。
- Tool Calling。
- Hallucination。
- Prompt Injection。
- Agent 權限風險。
- AI 產生程式碼及 Detection Rule 為什麼需要驗證。
八之一、補先備能力的免費資源
還沒有完整先備能力的人,可以先利用官方或開源資源確認自己是否喜歡這類工作,再決定是否投入 SEC598。
| 能力 | 免費起點 |
|---|---|
| Terraform | HashiCorp Developer Tutorials:https://developer.hashicorp.com/terraform/tutorials |
| Ansible | Ansible Community Documentation:https://docs.ansible.com/ansible/latest/getting_started/index.html |
| MITRE ATT&CK | ATT&CK 官方網站:https://attack.mitre.org/ |
| Atomic Red Team | GitHub 專案:https://github.com/redcanaryco/atomic-red-team |
| MITRE Caldera | 官方文件:https://caldera.readthedocs.io/ |
| Tines | Community Edition:https://www.tines.com/product/community-edition/ |
| Velociraptor | 官方文件:https://docs.velociraptor.app/ |
| Timesketch | 官方文件:https://timesketch.org/ |
| AWS Security | AWS Skill Builder:https://skillbuilder.aws/ |
| Microsoft Sentinel/Azure | Microsoft Learn:https://learn.microsoft.com/training/ |
這些資源不能取代 SEC598 教材與 Lab,但可用於補足名詞、工具介面與基本操作,避免上課後才第一次看到 Terraform、SOAR 或 Adversary Emulation。
九、如何製作 GASAE Index?
GIAC 考試常見的 Index 格式是:
| Keyword | Book | Page |
|---|---|---|
| RAG | Book 1 | 145 |
| Terraform State | Book 2 | 88 |
| Caldera Operation | Book 4 | 112 |
但 GASAE 有 CyberLive,建議擴充欄位。
| 關鍵字 | 書/頁 | 工具 | 用途 | 對應 Lab | 常見問題 |
|---|---|---|---|---|---|
| RAG | B1 P145 | LLM | 外部知識檢索 | Intro to LLM and RAG | Retrieval 錯誤 |
| Terraform State | B2 P88 | Terraform | 追蹤資源狀態 | Cloud Management | State 不一致 |
| Tines Story | B2 P210 | Tines | 建立 SOAR Workflow | Creating a Tines Story | JSON Path |
| Caldera Operation | B4 P112 | Caldera | 執行攻擊鏈 | Breach Exercise | Agent 未連線 |
| Velociraptor Artifact | B5 P74 | Velociraptor | Endpoint Triage | DFIR Lab | 查詢錯誤 |
Index 製作原則
- 一個概念可以有多個查找詞。
- 同義詞與工具名稱分開列。
- 不要把整段教材抄進 Index。
- 用顏色或分頁區分:
- AI
- Automation
- SOAR
- Cloud
- Offensive
- Defensive
- 每個工具都記錄用途,不只記頁碼。
- Practice Test 後再補充查不到的詞。
- Index 的目標是「快速定位」,不是製作第二份教材。
十、CyberLive 要怎麼準備?
CyberLive 是 GASAE 與只考選擇題證照最大的差異之一。
官方 CyberLive 示範資源
SANS 於 2026 年 7 月 7 日推出 GIAC Insider: Demo of Hands-On, CyberLive Exams。這場一小時 Webcast 公開展示 CyberLive 的虛擬機環境、情境式任務及準備思路。它不是 GASAE 題目展示,也不應被視為題庫,但很適合尚未參加過 GIAC CyberLive 的考生了解操作體驗。
網址:
https://www.sans.org/webcasts/experience-giac-cyberlive-hands-on-certification-demo
不要只記操作步驟
每個 Lab 都應回答:
- 這個 Lab 要解決什麼問題?
- 輸入資料從哪裡來?
- 資料經過哪些元件?
- 使用什麼 Credential?
- 成功時會看到什麼?
- 失敗時會看到什麼?
- Log 在哪裡?
- 如何驗證結果?
- 如何重設環境?
- 哪些步驟需要人工核准?
建立 Lab Index
| Lab | 目標 | 工具 | 啟動方式 | 成功證據 | 常見錯誤 |
|---|---|---|---|---|---|
| Terraform Cloud Management | 部署安全雲端資源 | Terraform | init/plan/apply | Resource 建立 | Provider、Credential |
| Tines Story | 建立 SOAR 流程 | Tines | Web UI/Webhook | Event 正確流動 | JSON Path |
| Atomic Red Team | 執行攻擊測試 | Atomic Red Team | Atomic Test | Technique 成功 | Dependency |
| Caldera | 執行攻擊鏈 | Caldera | Server+Agent | Operation 完成 | Agent 未連線 |
| Endpoint Triage | 蒐集 Artifact | Velociraptor | Query/Artifact | 取得資料 | Client、Query |
建立工具速查表
工具名稱
用途
設定檔位置
啟動方式
登入或 Credential 類型
Log 位置
常用指令
成功驗證方式
常見錯誤
重做 Lab 時刻意製造錯誤
例如:
- 改錯 API Token。
- 改錯 JSON Path。
- 移除 Terraform Variable。
- 讓 Ansible Inventory 指向錯誤主機。
- 停止 Caldera Agent。
- 使用錯誤 IAM Role。
- 讓 Tines Action 收不到前一步欄位。
這樣才能練習真正的故障排除,而不是只會照講義複製貼上。
十一、建議的 8 週準備計畫
以下是一個適合全職工作的準備版本。
第 1 週:建立全貌
目標:
- 快速看過全部教材架構。
- 建立第一版 Index。
- 列出完全陌生的工具。
- 畫出課程技術地圖。
優先確認:
- Python/PowerShell 是否看得懂。
- Terraform/Ansible 是否完全陌生。
- 是否有 SOAR 經驗。
- AWS/Azure 哪一邊比較弱。
- 是否理解 MITRE ATT&CK。
第 2 週:Section 1 與 AI 基礎
複習:
- Automation、Orchestration、SOAR。
- LLM、RAG、Embedding。
- Agent、Tool Calling。
- Hallucination、Guardrail。
- Detection as Code。
重做:
- Intro to LLM and RAG。
- LLM Detection Lab。
- Trigger/Automation Script Lab。
第 3 週:Section 2 工程工具
重點:
- PowerShell。
- Terraform。
- Ansible。
- Python。
- Jupyter。
- Tines。
本週至少完成:
- Terraform 從 init 到 apply。
- Ansible 執行一次 Playbook。
- Jupyter 解析一份資料。
- Tines 建立一個有 Trigger、Condition、Action 的 Story。
第 4 週:AWS 與 Azure
建立兩張架構圖:
AWS Finding → Trigger → Function → Investigation → Response
Azure Alert → Incident → Automation Rule → Logic Apps → Response
重點不是背全部服務,而是理解事件如何流動、權限如何授予,以及結果如何被驗證。
第 5 週:Offensive Automation
重做:
- Atomic Red Team。
- Caldera。
- Attack Chaining。
- Cloud Adversary Emulation。
- Red Team Agent。
- Adversary Emulation as Code。
每個測試都記錄:
- ATT&CK Technique。
- 前置條件。
- 攻擊動作。
- 預期 Telemetry。
- 預期 Detection。
- Cleanup。
第 6 週:Defensive Automation
重做:
- Artifact Collection。
- Velociraptor。
- Timesketch。
- PowerShell IR。
- Tines IR。
- Detection Testing。
- Purple Team Playbook。
把每個事件寫成:
偵測
→ 蒐證
→ Enrichment
→ 判斷
→ 回應
→ 驗證
→ 紀錄
第 7 週:第一次 Practice Test 與弱點修正
第一次模擬考不要只看分數,要把錯誤分成:
- 教材沒讀到。
- Index 找不到。
- 名詞混淆。
- 情境判斷錯誤。
- CyberLive 操作不熟。
- 查找速度太慢。
- 時間管理失敗。
接著:
- 補 Index。
- 重做失敗 Lab。
- 為常錯工具增加速查頁。
- 練習跳題,不要卡在單一題目。
第 8 週:第二次模擬與考前整合
本週目標:
- 執行第二次 Practice Test。
- 確認時間配置。
- 重做高風險 Lab。
- 整理 Index 順序。
- 確認紙本是否容易翻找。
- 模擬三小時不中斷操作。
- 不再大規模重做 Index。
十二、建議的工具優先順序
依官方課綱與目前通過者提到的先備能力,建議優先順序如下:
- Terraform。
- Ansible。
- Tines/SOAR。
- PowerShell。
- Python/Jupyter。
- Atomic Red Team。
- MITRE Caldera。
- AWS Security Automation。
- Azure Security Automation。
- Velociraptor。
- Timesketch。
- RAG/Agentic AI。
- Detection as Code。
- CI/CD 中的持續防禦驗證。
這不是官方公布的考試配分,而是基於課綱廣度與社群心得所做的準備排序。
十三、適合考 GASAE 的人
很適合
- SOC Analyst。
- Incident Responder。
- Detection Engineer。
- Threat Hunter。
- DFIR Analyst。
- Red Team Operator。
- Purple Team Engineer。
- Cloud Security Engineer。
- DevSecOps Engineer。
- Security Automation Engineer。
- 已會 Python/PowerShell,想進入資安自動化的開發者。
- 想把 AI Agent 實際導入 SOC 或 Purple Team 的人。
可能不適合直接開始
- 完全沒有 Linux、Windows、網路基礎。
- 完全沒有資安事件處理概念。
- 看不懂任何腳本。
- 沒使用過 API、JSON、YAML。
- 只想學 Prompt Injection。
- 只想學模型訓練。
- 只想深入 Web Penetration Testing。
- 只想取得入門級 AI 證照。
- 只需要深入一項工具,卻完全不需要跨領域整合。
十四、自費前應該考慮什麼?
SANS 課程費用高,因此自費前可以問自己:
- 公司是否願意補助?
- 工作中是否真的會用到 SOAR、IaC、Cloud Automation?
- 自己需要廣度還是單一技術深度?
- 是否已經具備足夠基礎,能吸收 6 天高密度內容?
- 是否有時間在課後重做 25 個 Lab?
- 是否真的需要 GASAE 證照,還是只需要技能?
- 是否可以先使用免費資源驗證興趣?
若完全自費,而且目前只想學 Terraform 或 Ansible,先上專門課程可能更划算。
另外,GIAC 官方目前單獨列出的 GASAE Certification Attempt 為 999、Practice Exam 為399、Retake 為 899;續證則為每四年499。若再加上 SANS SEC598 課程本身、交通住宿或請假成本,整體投入可能相當高。讀者應將「取得證照」與「長期維護證照」一起納入預算,而不是只計算第一次報名費。
若公司正在推動:
- SOC Automation。
- SOAR。
- Detection as Code。
- Continuous Purple Team。
- AI Agent for Security Operations。
- Cloud Incident Response。
- Infrastructure as Code。
SEC598 的整合價值就會更明顯。
十五、與其他 SANS/GIAC AI 課程的差異
SEC598/GASAE
核心:
AI、SOAR、IaC、Cloud、Attack Simulation、Detection Engineering 的跨領域整合。
適合:
- Security Automation。
- Purple Team。
- SOC Engineering。
- Cloud Security Automation。
- Detection as Code。
SEC573/GPYC
核心更偏:
- Python。
- 使用 AI 協助開發資安工具。
- Security Automation Coding。
適合想強化程式開發的人。
SEC535/GOAA
核心更偏:
- Offensive AI。
- AI 輔助偵察與利用。
- Phishing、Vishing。
- Malware。
- Security Control Evasion。
- Agentic Malware。
適合想研究 AI Offensive Techniques 的人。
SEC545/GAIPS
核心更偏:
- GenAI Application Security。
- LLM Pipeline Security。
- AI Application Audit。
- Prompt Injection 與 Agentic System Security。
適合想保護 AI 應用與平台的人。
SEC595/GMLE
核心更偏:
- Data Science。
- Statistics。
- Machine Learning。
- Security Analytics。
- Threat Hunting 模型。
適合想進入 AI/ML 模型與資安資料科學的人。
關於時效性優惠與未正式公布的新證照
GIAC 偶爾會針對特定 Applied Knowledge Certification 推出限時折扣,但 GASAE 是 Practitioner Certification,兩者不應混為一談。除非優惠頁面明確列出 GASAE 適用,否則不建議把 Applied Knowledge 折扣碼寫成 GASAE 報名優惠。
同樣地,GIAC 的 AI 證照版圖仍在擴展,但文章只應列入官方網站已正式命名及公開的證照。對於「稍後將推出第四張 AI 證照」等預告,若官方頁面沒有穩定公告,建議不要放進長期文章,以免很快過時。
十六、對準備者最重要的結論
整理官方資料與目前社群討論後,可以得到以下結論。
1. SEC598 不是單純的 AI 課
它是一門 Security Automation 與 Purple Team Engineering 課程,AI 是其中的重要能力,但不是全部。
2. GASAE 不只考理論
CyberLive 代表你必須能操作工具、閱讀程式碼、理解工作流程與處理錯誤。
3. 最值得先補的是 IaC、腳本與 SOAR
這一點同時符合:
- 官方課綱。
- Lab 工具。
- 已通過考生的回覆。
4. 課程廣度非常大
這是它的優點,也是缺點。
- 想學跨工具整合:很適合。
- 想單一技術深挖:不一定適合。
5. 不要把舊心得直接套用到新版
2025 年 SEC598 有大幅更新,增加 LLM、RAG、Agentic AI、Autonomous Red Team Agent 與 Detection as Code。
6. Index 仍然重要,但 Lab Index 更重要
準備 GASAE 時至少要有:
- 一般教材 Index。
- Lab Index。
- 工具速查表。
- 雲端事件流圖。
- AI 名詞及風險表。
7. 目前心得樣本仍然有限
公開通過心得很少,無法可靠推斷通過率與精確難度。
因此最安全的準備策略不是猜題,而是:
完整重做 Lab、理解資料流、練習故障排除,並把每個工具放回實際的攻擊、偵測或回應情境。
十七、給社群詢問時可以使用的版本
大家早安,想請教一下,有沒有前輩上過 SANS SEC598:AI and Security Automation for Red, Blue, and Purple Teams,或考過對應的 GASAE(GIAC AI Security Automation Engineer)證照?
最近正在評估這門課與證照,想了解:
- 課程與考試比較著重哪些領域?
- IaC、Python/PowerShell、SOAR 大概要熟到什麼程度?
- CyberLive 實作題準備時,哪些 Lab 最值得重做?
- Index 與 Lab Index 建議怎麼整理?
- Practice Test 與正式考試的體感差異如何?
- AWS、Azure、Tines、Terraform、Caldera、Velociraptor 等工具需要熟到什麼程度?
- 大約安排多久準備比較合理?
因為 GASAE 是相對新的證照,目前中文心得不多,希望上過課、參加過 Beta Exam,或已經通過的前輩可以分享經驗,謝謝!
原始資料與來源網址
官方資料
SANS SEC598 課程頁面
內容包括:
- 課程定位。
- 6 天/36 小時。
- Intermediate。
- 25 個 Hands-On Labs。
- 六個 Section。
- Lab 名稱。
- 工具與學習成果。
網址:
https://www.sans.org/cyber-security-courses/ai-security-automation
GIAC GASAE 官方頁面
內容包括:
- GASAE 證照定位。
- Areas Covered。
- 適合職務。
- CyberLive 說明。
- Exam Objectives。
網址:
https://www.giac.org/certifications/ai-security-automation-engineer-gasae
SEC598 2025 課程更新 Webcast
內容包括:
- 約 40% 課程更新。
- GenAI、LLM、Agentic AI。
- Autonomous Red Team Agent。
- Cloud-native Detection Pipeline。
- SOAR。
- Detection as Code。
網址:
https://www.sans.org/webcasts/update-sec598-automate-security-generative-ai
YouTube:SEC598 課程更新
網址:
GIAC 價格頁面
考試、重考、延期、續證與 Practice Exam 價格可能變更,應以官方頁面為準。
網址:
https://www.giac.org/pricing
Reddit 討論
GASAE certified! (SEC598)
目前最具體的通過者短篇心得之一。
重點:
- 完成 SEC598 後參加 Beta Exam。
- 認為是上過九門 SANS 課程中最喜歡的一門。
- 認為 Automation 很重要。
- 已看到 Lab 在工作上的使用情境。
- IaC、Scripting、SOAR 經驗會有很大幫助。
- 個人認為考試沒有過度複雜。
網址:
New Cert coming – SEC598 (GASAE)
重點:
- GASAE 推出時程。
- 官方 Areas Covered。
- Beta Exam 邀請。
- 已上課學員表示喜歡課程。
網址:
Sans Sec598
重點:
- 有人質疑課程範圍太廣及自費價值。
- 建議深入 Terraform 加另一套自動化工具。
- 課程作者回應課程來自實際導入。
- 課程重點是跨工具整合與 Continuous Purple Team。
- 當時約 50% 為 Hands-On Lab。
網址:
SANS Course SEC598 (GASAE)
重點:
- 開發者詢問是否適合往 Security Application 發展。
- 詢問 Red Team Agent 深度。
- 反映新證照公開心得不足。
網址:
SEC573 (GPYC) vs SEC598 (GASAE)
可用於比較 Python-oriented Security Automation 與跨領域 Security Automation。
網址:
其他參考
SANS Japan SEC598 頁面
可查看部分 Lab 與課程內容的日文整理。
網址:
https://www.sans-japan.jp/courses/sans_active_cyber_defence_japan_2026/sec598
AWS Marketplace SEC598
提供課程商業定位及企業學習成果說明。
網址:
https://aws.amazon.com/marketplace/pp/prodview-bjkblex2mleey
資料使用與限制聲明
本文引用的社群心得來自公開 Reddit 討論,僅摘錄少量必要原文,其他內容均以中文摘要與分析呈現。
請注意:
- Reddit 留言不代表 SANS 或 GIAC 官方立場。
- 單一考生經驗不能代表所有人的考試難度。
- Beta Exam 可能與後續正式考試版本不同。
- 課程、Lab、價格、考試格式與及格標準都可能更新。
- 不應把本文當成題庫、洩題或官方考試保證。
- 報名前請再次檢查官方頁面。
- 本文沒有取得或提供任何受保護的考試題目。
