SEC536: Adversarial AI - Penetration Testing AI Systems


Morgan Adamski
Principal, Cyber, Data, and Tech Risk Leader
PWC

Michael Collins
Senior Principal Security Engineer
Mastercard

Sergej Epp
CISO
Sysdig

Gadi Evron
Founder and CEO
Knostic

Jeremiah Grossman
Chief Executive Officer
Root Evidence

Katie Moussouris
Founder and CEO
Luta Security
Check in at the registration desk to pick up your Summit credentials, then enjoy a hot breakfast, freshly brewed coffee, and a selection of hot teas before the day’s sessions begin.
In-Person
In-Person & Virtual
In-Person & Virtual
In-Person & Virtual
In-Person & Virtual
Step away from the morning sessions to recharge and connect with fellow attendees. Enjoy coffee, tea, assorted soft drinks and juices, fresh fruit, and a featured snack. Be sure to visit the Solutions Expo to meet our Summit sponsors and explore the tools, services, and resources they offer.
In-Person & Virtual
Speaker announcement coming soon!
In-Person & Virtual
In-Person & Virtual
Join your fellow Summit attendees for a delicious lunch and an opportunity to connect. After lunch, visit the Solutions Expo to meet our Summit sponsors and explore the tools, services, and resources they offer.
In-Person & Virtual
Speaker: John Hultquist, Chief Analyst, Google Threat Intelligence Group
In-Person & Virtual
No-holds-barred Q&A. Ask your toughest questions.
Everyone's got an opinion on AI. Almost nobody says the quiet part out loud on stage. This session flips that. No slides, no talking points, no PR-approved answers, just Chris Cochran in the hot seat, taking your hardest, most uncomfortable questions live and unrehearsed.
Call for questions: We're opening a call for questions ahead of the Summit, submit the ones you've always wanted answered but never had the venue for. And we’ll be taking questions live from the room at the event, so come ready to put Chris on the spot.
Bring the questions people whisper about in hallway tracks but never dare put on a mic. The ones about the vendors overselling, the strategies quietly failing, and the uncomfortable truths the industry would rather leave in the parking lot. If it's a question worth asking, it's fair game here.
Questions like:
In-Person & Virtual
As you transition to workshops, enjoy an afternoon pick-me-up featuring coffee, tea, assorted sodas and juices, fruit, and a featured snack.
AI agent swarms continuously regenerate identities, accounts, and infrastructure, turning incident scoping and investigation into a moving target. Conventional incident response models are not designed to handle this new reality.
In this hands-on workshop, analysts will learn the Dynamic Approach to Incident Response (DAIR), a model that meets the needs of modern investigations, as they investigate a swarm intrusion. Bring your system to practice the dynamic response cycle: detect, verify, triage, scope, analyze, and rescope as the evidence changes. No AI account or prior forensics experience is required for the workshop.
In-Person
As organizations adopt generative AI on AWS, security teams need to extend their investigation capabilities into the AI layer. In this hands-on workshop, participants work through a realistic multi-phase incident.
Participants will trace a compromised credential from initial exposure through privilege escalation into Amazon Bedrock knowledge bases and AI agents. Using Amazon GuardDuty, AWS Security Hub, Amazon CloudTrail, and Amazon Athena, attendees reconstruct the full attack chain and walk away with the skills to detect, investigate, and respond when threat actors pivot from traditional cloud resources into generative AI workloads.
In-Person
Join us for a hands on lab experience focusing on the implementation side of AI based pentesting. Attendees will learn how to actively run open source AI backed pentest tools, and exploit open-source applications.
In-Person
After a full day of AI insights, take the Summit experience to new heights at the SANS Evening Summit Social. Enjoy drinks and food while connecting with fellow attendees, speakers, and SANS experts.
In-Person
Join us for networking and a hot breakfast, freshly brewed coffee, and a selection of hot teas before the day’s sessions begin.
In-Person
In-Person & Virtual
In-Person & Virtual
In-Person & Virtual
In-Person & Virtual
Step away from the morning sessions to recharge and connect with fellow attendees. Enjoy coffee, tea, assorted soft drinks and juices, fresh fruit, and a featured snack. Be sure to visit the Solutions Expo to meet our Summit sponsors and explore the tools, services, and resources they offer.
In-Person
Speaker announcement coming soon!
In-Person & Virtual
In-Person & Virtual
Join your fellow Summit attendees for a delicious lunch and an opportunity to connect. After lunch, visit the Solutions Expo to meet our Summit sponsors and explore the tools, services, and resources they offer.
New speaker announcement coming soon!
In-Person & Virtual
The SANS Find Evil! Hackathon challenged participants to build open-source, autonomous DFIR agents capable of analyzing real forensic evidence, tracing conclusions back to verified artifacts, and correcting their own mistakes.
Join first-place winner Caleb Evans and second-place winner Trinity Harrison as they share how they approached the challenge and built two distinct investigative agents. Caleb will introduce Mulder, which conducts a five-phase investigation across disk, memory, network, mobile, and log evidence, then challenges its own conclusions before producing a report. Trinity will discuss TRUDI, a hypothesis-driven agent that uses independent reasoning and adversarial review to identify unsupported claims and reconsider its findings when the evidence disagrees. Caleb and Trinity will walk through how they built their agents, what broke along the way, and where autonomous AI helps and where it still needs a human investigator. Both winning tools are open source, and both are expected to be included in a future release of the SANS SIFT Workstation.
In-Person & Virtual
As you transition to workshops enjoy an afternoon pick-me-up featuring coffee, tea, assorted sodas and juices, fruit, and a featured snack.
In-Person
Security teams are starting to hand their AI agents real work, such as triaging alerts, isolating endpoints, and disabling accounts. Each team must decide how much of that work its agents may do without a person approving each action. In this workshop, you’ll learn to choose which tasks an agent may handle on its own, and where a person must approve, override, or roll back its actions.
I’ll walk you through how one security operations team made those choices for its AI agents. In small groups, you’ll then debate the decisions you’d change, such as letting an agent isolate endpoints without approval. You’ll leave ready to run the same debate with your own team.
In-Person
What does an autonomous digital forensic investigation look like in practice? In this hands-on workshop, Find Evil! Hackathon winner Caleb Evans will introduce participants to Mulder, his open-source, agentic DFIR platform built for the SANS SIFT Workstation. Participants will explore how Mulder moves through a five-phase investigation, cataloging forensic evidence, extracting and correlating artifacts across systems, developing findings, challenging its own conclusions, and producing a structured incident report.
Caleb will demonstrate how Mulder uses established forensic tools while maintaining an auditable trail that connects every finding to the underlying evidence.
Along the way, participants will learn how Mulder addresses some of the greatest challenges associated with autonomous AI, including hallucinations, unsupported conclusions, incomplete analysis, and the need for human-verifiable results. Attendees will leave with a practical understanding of how AI agents can accelerate DFIR investigations while preserving evidence integrity, transparency, and analyst oversight.
In-Person
Most AI security sessions show you a tool. This one puts attendees behind the keyboard driving one.
Attendees work in an isolated firing range, using an agent to run a real assessment workflow end to end: reconnaissance against a live target subnet, web application testing, and code analysis. A short demonstration opens each segment and the rest is hands-on. Attendees extend the agent with their own skills and tool definitions, then check its output and learn where it is trustworthy and where it is confidently wrong.
The material is drawn from SEC590, the five-day AI-driven penetration testing course we are building for the Offensive Operations curriculum, with an alpha run planned for early 2027. This is the first public look at it.
Key takeaways:
- How to scope and prompt a coding agent for recon and web application testing, rather than treating it as a chat window
- How to extend an agent with custom skills and tool definitions that persist across engagements
- How to verify agent findings and recognize the failure modes: invented vulnerabilities, false confidence, unsafe actions
- An honest read on what AI can and cannot do in an offensive engagement today
- Working agent configurations attendees keep and reuse after the Summit
Target audience: Intermediate. Penetration testers, red teamers, and security engineers who are comfortable on a command line and have done some offensive testing. No AI or machine learning background needed. We start from the practitioner's view, not the researcher's.
In-Person
In-Person