SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsConfront emerging threats, secure your environment, and strengthen cyber resilience with SANS
Equip yourself or your team with comprehensive hands-on cybersecurity training. Explore 85+ courses covering technical skills, leadership, and real-world defense against evolving cyber threats.







Most incident response training still teaches a straight line: prepare, identify, contain, eradicate, recover. Real incidents don't move that way, scopes expand mid-investigation, and eradication often surfaces systems nobody accounted for.
This Dynamic Incident Response book from SANS Faculty Fellow Joshua Wright introduces the DAIR model, an iterative framework built around a continuous Scope, Contain, Eradicate, and Recover loop, with dedicated chapters on ransomware, cloud, and OT/ICS.
It is free to read, share, and adapt.

SANS AI Cybersecurity Summit Fall 2026
Nov. 2-3 | Arlington, VA & Live Online
The SANS AI Cybersecurity Summit Fall 2026 brings together practitioners building, securing, evaluating, and governing AI to share what they're learning now.
Explore what's working, where the hard problems remain, and how teams are tackling AI governance, agentic systems, security controls, and emerging threats through technical talks, real-world case studies, and hands-on workshops.

Late August was a wild stretch for frontier AI and cyber security, capped by more than 100 companies, led by OpenAI, warning of "a limited window to strengthen cyber defenses." In this special hosts-only episode, Ciaran and James take stock. Ciaran walks through how we got here, James asks who is actually going to do all this defending, and Ciaran calls a 4,000-year-old witness on who should answer for the actions of AI agents. They close on the harder question: is trust between the AI labs and the security community fraying, and can it be repaired?

Close critical team skill-gaps across all cyber disciplines in one building at Cyber Defense Initiative 2026 (Dec 14-19, Washington D.C. and online)
Can't Miss Keynote: Our CEO, James Lyne sits down with Brett Leatherman, Assistant Director, FBI Cyber Division, to discuss the FBI’s evolving cyber mission.
Included with any CDI course: 120 days of OnDemand access plus a GIAC exam attempt. Worth up to $2,000. Register by Nov 15.

Whether you're getting started or advancing your skills, choose from world-class training, industry-recognized certifications, or explore with free course demos. Start building your path with SANS.
Learn your way, whether in person, live instruction delivered in an online format, or self-paced, on your own schedule, with cybersecurity courses from top industry experts.
Master the skills to earn GIAC certifications, the industry's most rigorous credentials, with expert exam preparation from SANS.
Preview 70+ SANS courses, assess course difficulty, watch expert instructors, and experience the SANS OnDemand training platform firsthand.
The real value of this training lies at the intersection of quality content and delivery by a subject-matter expert actively working in the field, making it incredibly relevant and immediately applicable to my job.
You cannot beat the quality of SANS classes and instructors. I came back to work and was able to implement my skills learned in class on day one. Invaluable.
SANS is the best information security training you’ll find anywhere. World-class instructors, hands-on instruction, actionable information you can really use, and NetWars.
Effective cybersecurity operations rely on layers of offensive testing, defensive architecture and monitoring, forensics and incident response, cloud security, and leadership. Advancing your capabilities in these focus areas is our mission because it furthers your ability to protect us all.
Artificial Intelligence (AI) Cyber Security Training and Resources Ensure professionals at every level are prepared to navigate the complexities of an AI-driven future, equipping them with critical understanding of AI-powered threats and the skills to leverage AI to enhance security operations.
Learn moreTraining in penetration testing, red teaming, purple teaming, and exploit development, provides the skills needed to simulate real-world attacks, evade defenses, and enhance security through adversary emulation and improving defense strategies.
Learn moreEffective Cyber Defense enables organizations to anticipate, withstand, and recover from cyber-attacks through proactive monitoring, threat detection, and incident response. It combines security operations, automation, and resilient architecture to reduce risk and minimize attack impact.
Learn moreVulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline.



Governments around the world rely on SANS for best-in-class training, equipping local and international cybersecurity teams with the skills necessary to protect critical infrastructure and stay ahead of adversaries

Cybersecurity professionals of all skill levels train with SANS to learn from industry experts and gain hands-on, practical knowledge that can be applied immediately, effectively preparing them for real-world threats.

SANS Institute is GIAC’s preferred partner for exam preparation, offering focused curriculums that help individuals pass with confidence and validate their expertise in various cybersecurity domains.

Fortune 500 companies partner with SANS to recruit, build, and retain high-performing, outcome-driven teams through industry-leading training solutions that bolster cyber resilience.
Equip your team with cutting-edge cybersecurity skills, designed to address your organization’s most critical security needs.
Empower your leaders with strategies that drive better decision-making, stronger risk management, and improved cyber resilience.
Mitigate human risk and ensure compliance with advanced training that addresses evolving threats and security regulations.
Adapt to new SEC mandates with a 10-module training course designed to expand cyber literacy and help leaders facilitate an engaged, united cybersecurity culture.

Join the SANS Cyber Leaders Network, exclusively for senior security executives. Connect with experts and thought leaders, share ideas and lessons learned and help drive industry breakthroughs.

Gain exclusive access to free resources, tools, and expert content—news, training, podcasts, whitepapers, and more. Explore unique member benefits designed for cybersecurity professionals that you won’t find anywhere else.

When you join the SANS community, you gain access to free cybersecurity resources, including free training, 150+ instructor-developed tools, the latest industry updates, and more.
The session will demonstrate how AI can be applied as both a SAST and DAST capability for discovering and exploiting zero-day vulnerabilities in web applications, as well as its growing role in binary exploitation.

Threat hunting is no longer just a niche skill—it’s a critical pillar of modern defense.

We've all got two things in common. First, we know AI is powerful. Second, we all have investments, and every one of us would like them to do a little better.

Do you understand Active Directory? Your enterprise, just like the entire Fortune 500, depends on it.

This talk is the story of how I went from skeptic to believer by building Plan R, an IoT-focused MCP server that gives AI agents direct access to real pentesting tools.

Your Incident Response plan is lying to you. Not deliberately—it just hasn't met the incident yet. Steve unpicks the gap between the plan your board signed off and the ransomware incident your team is actually fighting at three in the morning.

In this presentation, James Tarala, Senior Faculty at the SANS Institute and Managing Partner at Cyverity, will delve into the core principles of effective cyber risk management, emphasizing the necessity of making informed decisions when allocating limited resources among good, better, and best safeguards.

Crowley will review findings from the 2026 survey: AI use, technology satisfaction, staffing, metrics, funding, and security operations capabilities.

This talk goes below the prompt into the logs — what Azure, AWS, Google Cloud, and Kubernetes record when an agent, not a human, acts. Anchored on a real July 2026 intrusion, we pull each platform’s own logs and find the same shape of logs that ground our investigations.

Join us for an exciting, hands-on exploration where we transform a humble chat completion script into a sophisticated, fully agentic AI system, all through a series of live, iterative demonstrations.

This session unpacks how those forces are reshaping OT security in practice, and why post-quantum resilience is a programme to start now rather than a problem to schedule later. OT assets have refresh cycles measured in decades, which means the cryptographic decisions made this year will still be live when quantum capability arrives.

AI transformed business and IT security. Now it's crossing into OT, bringing the same efficiency gains, the same defensive potential, and the same adversarial capabilities into environments that were never designed to absorb them.

The role of the security awareness professional is shifting. It's no longer enough to educate people on security, the real work is learning to understand people, and using that understanding to change how they think and behave.

Make sense of the 2026 cybersecurity standards landscape. Join Senior Instructor James Tarala for a research-based scorecard comparison of popular frameworks and learn how to use a Cyber Rosetta Stone to simplify control selection and prioritization.

This talk will explore the latest news and developments at the intersection of AI and cybersecurity, including emerging AI-powered threats, evolving attack techniques, and new capabilities for threat detection, prevention, and incident response.

Descubre los resultados de la Encuesta SANS SOC 2026 con Ismael Valenzuela y un panel de líderes de España y América Latina. IA, talento, fatiga de alertas e inversión: claves para entender la evolución de los SOC.

Cloud sprawl, misconfigurations, shadow IT, third-party risk, and identity-driven threats—exposure management is now a defining challenge in cybersecurity. As digital environments expand, so does the complexity of defending them.

Cyber42 puts CISOs and security leaders in AI-era scenarios where they must act on limited data, weigh competing views, and leave with takeaways they can use immediately.

Linux isn't just the majority of web servers in the world, it also lives inside infrastructure devices you might not think about, like routers, switches, firewalls, and most IOT devices.

This session walks through the findings: where AI and automation are genuinely changing analyst workflows and where they are not, which CTI practices are gaining ground, the challenges analysts report most often, and how teams are measuring the value and effectiveness they deliver back to the business.
