SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Apply your credits to renew your certifications
Course material is geared for cyber security professionals with hands-on experience
Apply what you learn with hands-on exercises and labs
Learn to secure autonomous AI agents with the controls, guardrails, and defenses needed for real-world deployment.
Want to be the first to know when SEC546 beta registration opens? Complete the interest form to receive updates on beta registration, full release date, training events, OnDemand availability, and more. Be among the first to experience the only SANS course built end-to-end for securing agentic AI.
SEC546 equips defenders to secure modern AI agents across their full autonomy lifecycle, from input to inter-agent communication, against risks that traditional controls were never built to stop. Students enforce strong boundaries, resist prompt injection, apply secure design patterns, protect memory, and govern runtime behavior. They defend MCP and tool execution, secure desktop, browser, and multi-agent environments, and contain unsafe agent actions through hands-on, live-fire defense.


Vis Chirravuri brings more than 20 years of cybersecurity experience to SANS SEC545 and SEC546, with deep work in AI security, AppSec, DevSecOps, product security governance, and software supply chain security.
Read more about Viswanath (Vis) ChirravuriExplore the course syllabus below to view the full range of topics covered in SEC546: Securing Agentic AI.
Section 1 builds the foundation for defending agentic AI by helping students understand the risk landscape, establish trusted boundaries, resist prompt injection, apply secure design patterns, and enforce strong identity and least-privilege controls. It equips defenders to secure agents before they act.
Section 2 moves from foundational controls to hardening production agentic AI systems at enterprise scale. Participants will secure persistent agent memory against poisoning, detect and safely terminate rogue agents, enforce runtime governance policies on live agent actions, and deploy defensive gateways that govern how agents reach external tools, data, and services.
Section 3 hardens the building blocks agents depend on at runtime, including MCP data flows and desktop agent environments. Participants will detect context poisoning and tool response tampering, sandbox tool execution paths, secure desktop agents such as OpenCode, and validate the provenance of dependencies, skills, and prompts.
Section 4 defends the runtime ecosystem where agents communicate with peers, drive browsers and operating systems, and delegate authority. Participants build verifiable trust chains between agents, sandbox browser and computer-use actions with Cua, scope delegated authorization across agent-to-agent handoffs, and prevent task data from crossing tenant boundaries.
Section 5 establishes strict fail-safe mechanisms for agents that act on the physical world or hardware devices, then present the current frontier of agentic security defenses with confidential computing. The day closes with a comprehensive live-fire defense exercise that requires participants to apply every defensive technique from the week against a multi-stage compromise of a production-grade autonomous system.
We're updating our course schedule - please check back later.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources