SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsConfront emerging threats, secure your environment, and strengthen cyber resilience with SANS
Equip yourself or your team with comprehensive hands-on cybersecurity training. Explore 85+ courses covering technical skills, leadership, and real-world defense against evolving cyber threats.







Close critical team skill-gaps across all cyber disciplines in one building at Cyber Defense Initiative 2026 (Dec 14-19, Washington D.C. and online)
Can't Miss Keynote: Our CEO, James Lyne sits down with Brett Leatherman, Assistant Director, FBI Cyber Division, to discuss the FBI’s evolving cyber mission.
Included with any CDI course: 120 days of OnDemand access plus a GIAC exam attempt. Worth up to $2,000. Register by Nov 15.

GDPR taught compliance teams what a single-market regulation costs to implement, and what it doesn't. The EU AI Act runs on a different model: four risk tiers instead of one compliance build, and a rollout now stretching to August 2028 after regulators pushed the high-risk rules back once. A SANS discussion paper maps four real similarities and four real differences between the two regulations, paired with a survey on how organizations are preparing.

SANS AI Cybersecurity Summit Fall 2026
Nov. 2-3 | Arlington, VA & Live Online
The SANS AI Cybersecurity Summit Fall 2026 brings together practitioners building, securing, evaluating, and governing AI to share what they're learning now.
Explore what's working, where the hard problems remain, and how teams are tackling AI governance, agentic systems, security controls, and emerging threats through technical talks, real-world case studies, and hands-on workshops.

Heather Barnhart has spent more than 20 years investigating what happened after a digital incident. As a SANS digital forensics expert, she knows how much can hinge on a conversation at home before anything goes wrong. This October, she’s helping families prepare for AI scams with the Secure the Family Protocol: four practical steps, one to take each week.

Whether you're getting started or advancing your skills, choose from world-class training, industry-recognized certifications, or explore with free course demos. Start building your path with SANS.
Learn your way, whether in person, live instruction delivered in an online format, or self-paced, on your own schedule, with cybersecurity courses from top industry experts.
Master the skills to earn GIAC certifications, the industry's most rigorous credentials, with expert exam preparation from SANS.
Preview 70+ SANS courses, assess course difficulty, watch expert instructors, and experience the SANS OnDemand training platform firsthand.
The real value of this training lies at the intersection of quality content and delivery by a subject-matter expert actively working in the field, making it incredibly relevant and immediately applicable to my job.
You cannot beat the quality of SANS classes and instructors. I came back to work and was able to implement my skills learned in class on day one. Invaluable.
SANS is the best information security training you’ll find anywhere. World-class instructors, hands-on instruction, actionable information you can really use, and NetWars.
Effective cybersecurity operations rely on layers of offensive testing, defensive architecture and monitoring, forensics and incident response, cloud security, and leadership. Advancing your capabilities in these focus areas is our mission because it furthers your ability to protect us all.
Artificial Intelligence (AI) Cyber Security Training and Resources Ensure professionals at every level are prepared to navigate the complexities of an AI-driven future, equipping them with critical understanding of AI-powered threats and the skills to leverage AI to enhance security operations.
Learn moreTraining in penetration testing, red teaming, purple teaming, and exploit development, provides the skills needed to simulate real-world attacks, evade defenses, and enhance security through adversary emulation and improving defense strategies.
Learn moreEffective Cyber Defense enables organizations to anticipate, withstand, and recover from cyber-attacks through proactive monitoring, threat detection, and incident response. It combines security operations, automation, and resilient architecture to reduce risk and minimize attack impact.
Learn moreHow the internet holds together, how botnets work, and what an AI-driven attack would actually require




Governments around the world rely on SANS for best-in-class training, equipping local and international cybersecurity teams with the skills necessary to protect critical infrastructure and stay ahead of adversaries

Cybersecurity professionals of all skill levels train with SANS to learn from industry experts and gain hands-on, practical knowledge that can be applied immediately, effectively preparing them for real-world threats.

SANS Institute is GIAC’s preferred partner for exam preparation, offering focused curriculums that help individuals pass with confidence and validate their expertise in various cybersecurity domains.

Fortune 500 companies partner with SANS to recruit, build, and retain high-performing, outcome-driven teams through industry-leading training solutions that bolster cyber resilience.
Equip your team with cutting-edge cybersecurity skills, designed to address your organization’s most critical security needs.
Empower your leaders with strategies that drive better decision-making, stronger risk management, and improved cyber resilience.
Mitigate human risk and ensure compliance with advanced training that addresses evolving threats and security regulations.
Adapt to new SEC mandates with a 10-module training course designed to expand cyber literacy and help leaders facilitate an engaged, united cybersecurity culture.

Join the SANS Cyber Leaders Network, exclusively for senior security executives. Connect with experts and thought leaders, share ideas and lessons learned and help drive industry breakthroughs.

Gain exclusive access to free resources, tools, and expert content—news, training, podcasts, whitepapers, and more. Explore unique member benefits designed for cybersecurity professionals that you won’t find anywhere else.

When you join the SANS community, you gain access to free cybersecurity resources, including free training, 150+ instructor-developed tools, the latest industry updates, and more.
This talk will explore the latest news and developments at the intersection of AI and cybersecurity, including emerging AI-powered threats, evolving attack techniques, and new capabilities for threat detection, prevention, and incident response.

Descubre los resultados de la Encuesta SANS SOC 2026 con Ismael Valenzuela y un panel de líderes de España y América Latina. IA, talento, fatiga de alertas e inversión: claves para entender la evolución de los SOC.

Cloud sprawl, misconfigurations, shadow IT, third-party risk, and identity-driven threats—exposure management is now a defining challenge in cybersecurity. As digital environments expand, so does the complexity of defending them.

Cyber42 puts CISOs and security leaders in AI-era scenarios where they must act on limited data, weigh competing views, and leave with takeaways they can use immediately.

Linux isn't just the majority of web servers in the world, it also lives inside infrastructure devices you might not think about, like routers, switches, firewalls, and most IOT devices.

This session walks through the findings: where AI and automation are genuinely changing analyst workflows and where they are not, which CTI practices are gaining ground, the challenges analysts report most often, and how teams are measuring the value and effectiveness they deliver back to the business.

Scammers are smarter than ever — and they're coming for you and your family. Learn the latest social engineering tricks and how to spot and stop them before they strike.

SANS 2026 DFIR Summit Solutions Track delivers a deep technical exploration of the tools, methodologies, and operational models driving next-generation digital forensics and incident response.

The Ransomware Solutions Track brings together practitioners, researchers, and technology innovators to showcase actionable strategies that strengthen resilience against the world’s most disruptive cyber threat.

In this session, we investigate all the different kinds of malware that are actively infecting devices, explain how they achieve the needed permissions, and discover why Android is much more susceptible to malware than iOS.

The 2027 SANS Exposure Management Survey examines how organizations turn visibility into action. It explores how teams combine vulnerability data, asset context, threat intelligence, identity risk, cloud posture, business criticality, and attack-path analysis to decide what matters most and drive remediation.

See how SEC556 and SEC617 have evolved with AI-assisted workflows, updated labs, revised hardware kits, and broader platform support—and learn which course fits your IoT or wireless testing goals.

Breaking into cyber can feel overwhelming. Hear how recent SANS grads landed their first roles, stood out, and the advice they wish they'd had, in an honest conversation with NICE's Karen Wetzel.

In this webinar, we’ll explore how AI is changing phishing and social engineering, from convincing emails and messages to cloned voices, synthetic identities and deepfakes.

The 2026 SANS Cloud Security Research Survey brings together insights from security leaders and practitioners worldwide. This year’s study examines the current state of cloud security, highlighting key challenges, top threats, and the tools organizations are using—or wish they had—to secure cloud environments at scale. Join us for this exclusive webcast to explore the survey findings, gain practical insights, and benchmark your organization’s approach to cloud security.

In this webcast, SEC565 co-author David Mayer will explore how organisations can use publicly available threat intelligence to identify relevant adversary behaviours, map tactics, techniques and procedures to MITRE ATT&CK, and develop an adversary-emulation plan that reflects the threats they are most likely to face.

Get ready for Cyber Quest CTF, Powered by RBC. Join the orientation webinar to learn how to access the platform, prepare your setup, navigate the competition, and get answers before the 72-hour challenge begins.

AI is changing what cybersecurity teams need from every role. This session shows leaders, HR teams, and practitioners how to adapt hiring, training, and workforce strategy to build resilient, AI-ready security teams.

This session reframes agent adoption as a hiring decision. It covers what to document before an agent touches production, how to audit and red team what it actually does, how to evaluate performance against something more useful than vibes, and why an offboarding plan matters as much as the onboarding one.

For years, critical infrastructure organizations have built their cybersecurity strategies around a familiar set of assumptions: cyber incidents are isolated events, communications remain available, response resources can scale, mutual aid will arrive, and recovery will be measured in days. Today’s nation-state threat landscape is exposing the limits of those assumptions.
