SEC536: Adversarial AI - Penetration Testing AI Systems

In-Person & Virtual
Speaker: Morgan Adamski, PWC
In-Person & Virtual
Speaker announcement coming soon!
In-Person & Virtual
Speaker announcement coming soon!
In-Person & Virtual
In-Person & Virtual
Speaker announcement coming soon!
In-Person & Virtual
Moderator announcement coming soon!
In-Person & Virtual
In-Person & Virtual
Speaker announcement coming soon!
In-Person & Virtual
In-Person
As organizations adopt generative AI on AWS, security teams need to extend their investigation capabilities into the AI layer. In this hands-on workshop, participants work through a realistic multi-phase incident.
Participants will trace a compromised credential from initial exposure through privilege escalation into Amazon Bedrock knowledge bases and AI agents. Using Amazon GuardDuty, AWS Security Hub, Amazon CloudTrail, and Amazon Athena, attendees reconstruct the full attack chain and walk away with the skills to detect, investigate, and respond when threat actors pivot from traditional cloud resources into generative AI workloads.
In-Person
Speaker announcement coming soon!
In-Person
In-Person
In-Person & Virtual
Speaker: Michael Collins, Mastercard
In-Person & Virtual
Speaker: Daniel Miessler, Unsupervised Learning
In-Person & Virtual
Speaker announcement coming soon!
In-Person & Virtual
In-Person & Virtual
Speaker announcement coming soon!
In-Person & Virtual
New speaker announcement coming soon!
In-Person & Virtual
The SANS Find Evil! Hackathon challenged participants to build open-source, autonomous DFIR agents capable of analyzing real forensic evidence, tracing conclusions back to verified artifacts, and correcting their own mistakes.
Join first-place winner Caleb Evans and second-place winner Trinity Harrison as they share how they approached the challenge and built two distinct investigative agents. Caleb will introduce Mulder, which conducts a five-phase investigation across disk, memory, network, mobile, and log evidence, then challenges its own conclusions before producing a report. Trinity will discuss TRUDI, a hypothesis-driven agent that uses independent reasoning and adversarial review to identify unsupported claims and reconsider its findings when the evidence disagrees. Caleb and Trinity will walk through how they built their agents, what broke along the way, and where autonomous AI helps and where it still needs a human investigator. Both winning tools are open source, and both are expected to be included in a future release of the SANS SIFT Workstation.
In-Person & Virtual
In-Person
Security teams are starting to hand their AI agents real work, such as triaging alerts, isolating endpoints, and disabling accounts. Each team must decide how much of that work its agents may do without a person approving each action. In this workshop, you’ll learn to choose which tasks an agent may handle on its own, and where a person must approve, override, or roll back its actions.
I’ll walk you through how one security operations team made those choices for its AI agents. In small groups, you’ll then debate the decisions you’d change, such as letting an agent isolate endpoints without approval. You’ll leave ready to run the same debate with your own team.
In-Person
Presented by: Caleb Evans
What does an autonomous digital forensic investigation look like in practice? In this hands-on workshop, Find Evil! Hackathon winner Caleb Evans will introduce participants to Mulder, his open-source, agentic DFIR platform built for the SANS SIFT Workstation. Participants will explore how Mulder moves through a five-phase investigation, cataloging forensic evidence, extracting and correlating artifacts across systems, developing findings, challenging its own conclusions, and producing a structured incident report.
Caleb will demonstrate how Mulder uses established forensic tools while maintaining an auditable trail that connects every finding to the underlying evidence.
Along the way, participants will learn how Mulder addresses some of the greatest challenges associated with autonomous AI, including hallucinations, unsupported conclusions, incomplete analysis, and the need for human-verifiable results. Attendees will leave with a practical understanding of how AI agents can accelerate DFIR investigations while preserving evidence integrity, transparency, and analyst oversight.