SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsConfront emerging threats, secure your environment, and strengthen cyber resilience with SANS
Equip yourself or your team with comprehensive hands-on cybersecurity training. Explore 85+ courses covering technical skills, leadership, and real-world defense against evolving cyber threats.








AI adoption in DFIR is already happening, with or without formal policies. Most teams lack governance models, validation standards, and defensible practices for integrating AI into critical investigative workflows.
Two new practitioner-developed frameworks from Heather Barnhart, DFIR Curriculum Lead and Head of Faculty at SANS Institute, provide phase-by-phase guidance for Digital Forensics and Incident Response – covering where AI can responsibly accelerate the work, where human oversight is required, and where AI should never be relied upon.

Explore SANS training in Asia Pacific either in person or online. Learn from industry experts and build mission-critical skills.

New research from 536 security professionals shows AI adoption jumped from 50% to 78% in a year, the largest single-year increase the survey has recorded. Governance, detection reliability, and workforce readiness are all struggling to keep pace. Senior SANS Instructor Dave Shackleford breaks down the findings in an on-demand webcast.

From hot topics to hands-on tips, SANS Community Nights bring learning and connection to cyber pros across Asia Pacific. Find the latest events and join us for a great night of learning.

Go beyond the numbers with report authors Lance Spitzner and Rachael Saffer as they walk through the complete 2026 findings, where programs stand, the impact of AI, and what the most effective teams are doing differently.

Whether you're getting started or advancing your skills, choose from world-class training, industry-recognized certifications, or explore with free course demos. Start building your path with SANS.
Learn your way, whether in person, live instruction delivered in an online format, or self-paced, on your own schedule, with cybersecurity courses from top industry experts.
Master the skills to earn GIAC certifications, the industry's most rigorous credentials, with expert exam preparation from SANS.
Preview 70+ SANS courses, assess course difficulty, watch expert instructors, and experience the SANS OnDemand training platform firsthand.
The real value of this training lies at the intersection of quality content and delivery by a subject-matter expert actively working in the field, making it incredibly relevant and immediately applicable to my job.
You cannot beat the quality of SANS classes and instructors. I came back to work and was able to implement my skills learned in class on day one. Invaluable.
SANS is the best information security training you’ll find anywhere. World-class instructors, hands-on instruction, actionable information you can really use, and NetWars.
Effective cybersecurity operations rely on layers of offensive testing, defensive architecture and monitoring, forensics and incident response, cloud security, and leadership. Advancing your capabilities in these focus areas is our mission because it furthers your ability to protect us all.
Training in penetration testing, red teaming, purple teaming, and exploit development, provides the skills needed to simulate real-world attacks, evade defenses, and enhance security through adversary emulation and improving defense strategies.
Learn moreEffective Cyber Defense enables organizations to anticipate, withstand, and recover from cyber-attacks through proactive monitoring, threat detection, and incident response. It combines security operations, automation, and resilient architecture to reduce risk and minimize attack impact.
Learn moreCloud security encompasses technologies, policies, and controls that protect data, applications, and infrastructure in cloud environments. SANS provides hands-on cloud security training, courses, and certifications that will give you the knowledge to safeguard sensitive information in cloud environments that is crucial for preventing cyber threats, ensuring compliance, and maintaining business continuity.
Learn moreLearn why AI workflows, not AI models, are becoming the real cybersecurity battleground. Sean O'Connor explores AI agents, model risk, observability, shadow AI, and practical steps defenders can take to build more resilient security programs.





Governments around the world rely on SANS for best-in-class training, equipping local and international cybersecurity teams with the skills necessary to protect critical infrastructure and stay ahead of adversaries

Cybersecurity professionals of all skill levels train with SANS to learn from industry experts and gain hands-on, practical knowledge that can be applied immediately, effectively preparing them for real-world threats.

SANS Institute is GIAC’s preferred partner for exam preparation, offering focused curriculums that help individuals pass with confidence and validate their expertise in various cybersecurity domains.

Fortune 500 companies partner with SANS to recruit, build, and retain high-performing, outcome-driven teams through industry-leading training solutions that bolster cyber resilience.
Equip your team with cutting-edge cybersecurity skills, designed to address your organization’s most critical security needs.
Empower your leaders with strategies that drive better decision-making, stronger risk management, and improved cyber resilience.
Mitigate human risk and ensure compliance with advanced training that addresses evolving threats and security regulations.
Adapt to new SEC mandates with a 10-module training course designed to expand cyber literacy and help leaders facilitate an engaged, united cybersecurity culture.

Join the SANS Cyber Leaders Network, exclusively for senior security executives. Connect with experts and thought leaders, share ideas and lessons learned and help drive industry breakthroughs.

Gain exclusive access to free resources, tools, and expert content—news, training, podcasts, whitepapers, and more. Explore unique member benefits designed for cybersecurity professionals that you won’t find anywhere else.

When you join the SANS community, you gain access to free cybersecurity resources, including free training, 150+ instructor-developed tools, the latest industry updates, and more.
In this session, SANS instructors Matt Edmondson and Ngô Minh Hiếu (Hiếu PC), CEO of ChongLuaDao, will demonstrate how modern OSINT techniques and AI-powered workflows are transforming cyber investigations.

Protocol-SIFT has been getting a lot of attention lately, but the first release was 100% focused on Windows investigations. In this talk, we'll look at what it takes to extend this to cover Linux investigations.

Get deeper with WinDbg in this advanced session for offensive researchers. Explore dx, variables, custom functions, memory editing, extensions, and live user- and kernel-mode debugging to build confidence for SEC665-level red team work.

In this session, Kurtis Minder examines how threat actors weaponize openly available personal data to make social engineering faster, cheaper, and more convincing, and why traditional security controls rarely account for it.

In this webcast, report authors Lance Spitzner and Rachael Saffer walk through the complete findings of the 2026 report. In it, they cover where the industry currently stands, how the risk landscape is shifting, and what this year's practitioner responses reveal about the state of the field today.

Most security teams I’ve worked with and helped have a handful of people defending thousands. Yet we expect them to cover everything, watch everything, and control everything, like they have an army’s headcount to do it.

AI is a major topic of discussion today—and rightfully so. But for those of us in cybersecurity, it's crucial not only to understand how to use AI for security, but also to recognize the threats targeting AI models, their ecosystems, and how to defend and secure them effectively.

Attendees will walk away with a clear mental model of where AI accelerates AppSec, where AI must be defended, and how to adopt vendor AI responsibly, all supported by open-source frameworks and ready to use resources.

Not every AI harness fits every cloud security task. This webinar compares tools like Claude Code, Codex, and Cursor with leading models, evaluating accuracy, speed, cost, and reliability so teams can choose the right fit.

This session argues that modern cyber incidents are not the result of novel or sophisticated threats, but of the industry’s repeated failure to fix problems we have understood since the 1990s.

Initial access is only the beginning. This session shows how attackers escape endpoint restrictions and pivot from constrained environments, with a new lab focused on breaking out of a Dockerized network appliance.

In this session, Ismael Valenzuela, author of SANS SEC530: Defensible Security Architecture and Engineering, applies his Think Red, Act Blue approach to both sides of the agentic SOC.

In this webcast, SANS Certified Instructor Matt Bromiley will explore the operational realities of managing AI-driven environments and examine the three foundational disciplines organizations must develop to close the maturity gap: governance, visibility, and control.

Join Josh and Phill as they discuss the latest trends, practical use cases, and the challenges of integrating AI into modern DFIR workflows.

Data protection strategies haven't kept pace with where data actually lives today. This SANS Security Lab will tackle the real-world gaps in modern DLP, from cloud sprawl and tool fragmentation to the emerging risks inside AI pipelines.

Discover how to effectively incorporate artificial intelligence and machine learning into SOC detection engineering workflows.

AI is changing how sensitive data flows across the enterprise. Learn how to identify AI-driven data exposure, reduce shadow AI risk, improve visibility into AI activity, and implement practical controls that enable secure AI adoption without slowing innovation.

AI is moving fast and your security program may not be keeping up. Join SANS for an exclusive look at the AI Security Maturity Model, a practical framework for benchmarking and advancing your AI security capabilities, followed by a candid expert panel on the real-world challenges of securing agentic AI.

The session closes on the practical part: the actions worth starting now to prepare for a post-quantum future, and the ones that can safely wait.

The session will demonstrate how AI can be applied as both a SAST and DAST capability for discovering and exploiting zero-day vulnerabilities in web applications, as well as its growing role in binary exploitation.
