SEC536: Adversarial AI - Penetration Testing AI Systems

This talk begins with a brief examination of recent breach data and the growing ecosystem of attacker tooling available through Dark Web marketplaces and Telegram channels, highlighting where OSINT and cyber threat intelligence teams should focus their monitoring efforts.
In-Person & Virtual
On December 29, 2025, the threat group ELECTRUM launched an attack against Distributed Energy Resource (DER) sites in Poland. This represents a new level of ICS attacks in Europe beyond the current theater of war in Ukraine. The talk will cover details of the attack and what electric operators in Europe should do no to detect and respond to this type of attack.
In-Person & Virtual
For years, kernel exploitation was synonymous with executing shellcode in Ring 0. You hijacked the control flow, ran your payload, and walked away with a SYSTEM or root shell.
Today, the landscape is violently different. With the widespread enforcement of SMEP, SMAP, kCFI, and virtualization-based security (VBS/HVCI), traditional control-flow hijacking has become fragile, computationally expensive, or entirely obsolete. If we can no longer safely execute our own code in the kernel, how do we win?
In-Person & Virtual
Registration: All students who register for a 4–6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About DFIR NetWars: Focused on digital forensics, incident response, threat hunting, and malware analysis, this tool-agnostic approach covers everything from low-level artifacts to high-level behavioral observations.
In-Person & Virtual
Registration: All students who register for a 4–6 day course will be eligible to play NetWars for free. Registration for this event will be through your SANS Account Dashboard the week of the event.
About DFIR NetWars: Focused on digital forensics, incident response, threat hunting, and malware analysis, this tool-agnostic approach covers everything from low-level artifacts to high-level behavioral observations.
In-Person & Virtual