SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsConfront emerging threats, secure your environment, and strengthen cyber resilience with SANS
Equip yourself or your team with comprehensive hands-on cybersecurity training. Explore 85+ courses covering technical skills, leadership, and real-world defense against evolving cyber threats.







AI has changed vulnerability management forever, with frontier models now finding software vulnerabilities at velocity and scale. If your security program is still built around finding, scoring, and patching vulnerabilities the way it was two years ago, you are already behind.
In this session, Ed Skoudis, President, SANS Technology Institute presents a VulnOps operating model that continuously reduces exploitability before attackers can pounce. You will leave with practical strategies for transforming vulnerability management into a business-driven capability that can operate in the AI-driven vulnerability deluge.

Where Attackers Think. Defenders Evolve.
SANS Network Security 2026 trains you to hunt threats, not chase alerts. Attackers linger 11 days undetected before discovery (Mandiant M-Trends 2025), so train to close the gap.
Choose from 30 courses, compete in Core + DFIR NetWars, and a keynote from offensive security legend, Stephen Sims.
Sept 21–26 · Caesars Palace, Las Vegas.
Know the exploit. Own the outcome.

New research from 536 security professionals shows AI adoption jumped from 50% to 78% in a year, the largest single-year increase the survey has recorded. Governance, detection reliability, and workforce readiness are all struggling to keep pace. Senior SANS Instructor Dave Shackleford breaks down the findings in an on-demand webcast.

Join this virtual webcast to hear cloud security experts share practical strategies for defending environments across Google Cloud, AWS, and Microsoft Azure. Explore emerging threats, security best practices, and real-world lessons for protecting cloud infrastructure, identities, applications, and data.

Go beyond the numbers with report authors Lance Spitzner and Rachael Saffer as they walk through the complete 2026 findings, where programs stand, the impact of AI, and what the most effective teams are doing differently.

Whether you're getting started or advancing your skills, choose from world-class training, industry-recognized certifications, or explore with free course demos. Start building your path with SANS.
Learn your way, whether in person, live instruction delivered in an online format, or self-paced, on your own schedule, with cybersecurity courses from top industry experts.
Master the skills to earn GIAC certifications, the industry's most rigorous credentials, with expert exam preparation from SANS.
Preview 70+ SANS courses, assess course difficulty, watch expert instructors, and experience the SANS OnDemand training platform firsthand.
The real value of this training lies at the intersection of quality content and delivery by a subject-matter expert actively working in the field, making it incredibly relevant and immediately applicable to my job.
You cannot beat the quality of SANS classes and instructors. I came back to work and was able to implement my skills learned in class on day one. Invaluable.
SANS is the best information security training you’ll find anywhere. World-class instructors, hands-on instruction, actionable information you can really use, and NetWars.
Effective cybersecurity operations rely on layers of offensive testing, defensive architecture and monitoring, forensics and incident response, cloud security, and leadership. Advancing your capabilities in these focus areas is our mission because it furthers your ability to protect us all.
Artificial Intelligence (AI) Cyber Security Training and Resources Ensure professionals at every level are prepared to navigate the complexities of an AI-driven future, equipping them with critical understanding of AI-powered threats and the skills to leverage AI to enhance security operations.
Learn moreTraining in penetration testing, red teaming, purple teaming, and exploit development, provides the skills needed to simulate real-world attacks, evade defenses, and enhance security through adversary emulation and improving defense strategies.
Learn moreEffective Cyber Defense enables organizations to anticipate, withstand, and recover from cyber-attacks through proactive monitoring, threat detection, and incident response. It combines security operations, automation, and resilient architecture to reduce risk and minimize attack impact.
Learn moreLearn why AI workflows, not AI models, are becoming the real cybersecurity battleground. Sean O'Connor explores AI agents, model risk, observability, shadow AI, and practical steps defenders can take to build more resilient security programs.





Governments around the world rely on SANS for best-in-class training, equipping local and international cybersecurity teams with the skills necessary to protect critical infrastructure and stay ahead of adversaries

Cybersecurity professionals of all skill levels train with SANS to learn from industry experts and gain hands-on, practical knowledge that can be applied immediately, effectively preparing them for real-world threats.

SANS Institute is GIAC’s preferred partner for exam preparation, offering focused curriculums that help individuals pass with confidence and validate their expertise in various cybersecurity domains.

Fortune 500 companies partner with SANS to recruit, build, and retain high-performing, outcome-driven teams through industry-leading training solutions that bolster cyber resilience.
Equip your team with cutting-edge cybersecurity skills, designed to address your organization’s most critical security needs.
Empower your leaders with strategies that drive better decision-making, stronger risk management, and improved cyber resilience.
Mitigate human risk and ensure compliance with advanced training that addresses evolving threats and security regulations.
Adapt to new SEC mandates with a 10-module training course designed to expand cyber literacy and help leaders facilitate an engaged, united cybersecurity culture.

Join the SANS Cyber Leaders Network, exclusively for senior security executives. Connect with experts and thought leaders, share ideas and lessons learned and help drive industry breakthroughs.

Gain exclusive access to free resources, tools, and expert content—news, training, podcasts, whitepapers, and more. Explore unique member benefits designed for cybersecurity professionals that you won’t find anywhere else.

When you join the SANS community, you gain access to free cybersecurity resources, including free training, 150+ instructor-developed tools, the latest industry updates, and more.
In this session, SANS instructors Matt Edmondson and Ngô Minh Hiếu (Hiếu PC), CEO of ChongLuaDao, will demonstrate how modern OSINT techniques and AI-powered workflows are transforming cyber investigations.

Protocol-SIFT has been getting a lot of attention lately, but the first release was 100% focused on Windows investigations. In this talk, we'll look at what it takes to extend this to cover Linux investigations.

Get deeper with WinDbg in this advanced session for offensive researchers. Explore dx, variables, custom functions, memory editing, extensions, and live user- and kernel-mode debugging to build confidence for SEC665-level red team work.

In this session, Kurtis Minder examines how threat actors weaponize openly available personal data to make social engineering faster, cheaper, and more convincing, and why traditional security controls rarely account for it.

In this webcast, report authors Lance Spitzner and Rachael Saffer walk through the complete findings of the 2026 report. In it, they cover where the industry currently stands, how the risk landscape is shifting, and what this year's practitioner responses reveal about the state of the field today.

Most security teams I’ve worked with and helped have a handful of people defending thousands. Yet we expect them to cover everything, watch everything, and control everything, like they have an army’s headcount to do it.

AI is a major topic of discussion today—and rightfully so. But for those of us in cybersecurity, it's crucial not only to understand how to use AI for security, but also to recognize the threats targeting AI models, their ecosystems, and how to defend and secure them effectively.

Attendees will walk away with a clear mental model of where AI accelerates AppSec, where AI must be defended, and how to adopt vendor AI responsibly, all supported by open-source frameworks and ready to use resources.

Not every AI harness fits every cloud security task. This webinar compares tools like Claude Code, Codex, and Cursor with leading models, evaluating accuracy, speed, cost, and reliability so teams can choose the right fit.

This session argues that modern cyber incidents are not the result of novel or sophisticated threats, but of the industry’s repeated failure to fix problems we have understood since the 1990s.

Initial access is only the beginning. This session shows how attackers escape endpoint restrictions and pivot from constrained environments, with a new lab focused on breaking out of a Dockerized network appliance.

In this session, Ismael Valenzuela, author of SANS SEC530: Defensible Security Architecture and Engineering, applies his Think Red, Act Blue approach to both sides of the agentic SOC.

In this webcast, SANS Certified Instructor Matt Bromiley will explore the operational realities of managing AI-driven environments and examine the three foundational disciplines organizations must develop to close the maturity gap: governance, visibility, and control.

Join Josh and Phill as they discuss the latest trends, practical use cases, and the challenges of integrating AI into modern DFIR workflows.

Data protection strategies haven't kept pace with where data actually lives today. This SANS Security Lab will tackle the real-world gaps in modern DLP, from cloud sprawl and tool fragmentation to the emerging risks inside AI pipelines.

Discover how to effectively incorporate artificial intelligence and machine learning into SOC detection engineering workflows.

AI is changing how sensitive data flows across the enterprise. Learn how to identify AI-driven data exposure, reduce shadow AI risk, improve visibility into AI activity, and implement practical controls that enable secure AI adoption without slowing innovation.

AI is moving fast and your security program may not be keeping up. Join SANS for an exclusive look at the AI Security Maturity Model, a practical framework for benchmarking and advancing your AI security capabilities, followed by a candid expert panel on the real-world challenges of securing agentic AI.

The session closes on the practical part: the actions worth starting now to prepare for a post-quantum future, and the ones that can safely wait.

The session will demonstrate how AI can be applied as both a SAST and DAST capability for discovering and exploiting zero-day vulnerabilities in web applications, as well as its growing role in binary exploitation.
