SEC536: Adversarial AI - Penetration Testing AI Systems

Your Incident Response plan is lying to you. Not deliberately—it just hasn't met the incident yet.
Steve unpicks the gap between the plan your board signed off and the ransomware incident your team is actually fighting at three in the morning.
The spice must flow, the business must keep running, and somewhere between those two truths sits an Incident Commander trying very hard not to pull their hand out of the pain box.
This is a Dune themed working session on the habits, instincts and small acts of discipline that separate Incident Commanders who hold the line from those who panic-pay the ransom by lunchtime. Bring your runbooks. Leave the blue pill at the door. The worm is already coming.
This bonus session is only available to in-person and virtual attendees of this event. Links to the virtual presentations will be shared on the event slack channels in advance of the presentations.
In-Person & Virtual
This talk is about throwing everything but the kitchen sink at the problem of C2 detection and obsessing over the nitty-gritty details of spotting beaconing traffic.
We are going to look at various data science approaches like statistical methods, signal processing, probability theory, machine learning, and... what? AI? Sure, maybe that one too! I mean, why not?
However, these solutions are not fast, nor perfect out of the box, so we are going to leave behind all those JupyterLab notebooks to address code optimization, multi-threading, and using accelerated computing as well.
We will show you our results when we pit our implementations and novel solutions against other tools and projects, such as Flare or RITA, to compare and further improve the current state of the art. Sounds awesome, right? Yeah... if you have the data to begin with! But where can we find it? And how can we massage it into a format that is useful for us?
We will also consider the often-overlooked issue of finding data for testing and training models, and then generating and collecting the data for detection.
This bonus session is only available to in-person and virtual attendees of this event. Links to the virtual presentations will be shared on the event slack channels in advance of the presentations.
In-Person & Virtual
Registration:
About Core NetWars: The most comprehensive and AI-forward cyber range in the NetWars portfolio. Designed for practitioners across multiple disciplines, Core NetWars combines emerging AI security challenges with real-world cyber scenarios to strengthen the technical skills most needed for today's threats. It is the only range that qualifies for the annual Core NetWars Tournament of Champions!
Computer Requirements: Internet-based
Recommended For: All infosec practitioners of any level. It is recommended, but not required, that students have a basic or foundational knowledge of information technology and technical topics.
Disciplines: Cybersecurity 101, Cyber Defense, Penetration Testing, Digital Forensics, Incident Response, Cloud Computing, and AI.
Example Topics:
Interactive Scenario: SANS students are deployed to BLOCCORP, a global media giant built on toys, streaming, gaming, and AI. As strange activity spreads across its infrastructure, they uncover compromised systems, vulnerable AI models, rogue IoT devices, and reckless automation. Can they expose BLOCCORP’s hidden agenda and stop its AI-driven ambitions before the damage is done?
In-Person & Virtual
Registration:
About Core NetWars: The most comprehensive and AI-forward cyber range in the NetWars portfolio. Designed for practitioners across multiple disciplines, Core NetWars combines emerging AI security challenges with real-world cyber scenarios to strengthen the technical skills most needed for today's threats. It is the only range that qualifies for the annual Core NetWars Tournament of Champions!
Computer Requirements: Internet-based
Recommended For: All infosec practitioners of any level. It is recommended, but not required, that students have a basic or foundational knowledge of information technology and technical topics.
Disciplines: Cybersecurity 101, Cyber Defense, Penetration Testing, Digital Forensics, Incident Response, Cloud Computing, and AI.
Example Topics:
Interactive Scenario: SANS students are deployed to BLOCCORP, a global media giant built on toys, streaming, gaming, and AI. As strange activity spreads across its infrastructure, they uncover compromised systems, vulnerable AI models, rogue IoT devices, and reckless automation. Can they expose BLOCCORP’s hidden agenda and stop its AI-driven ambitions before the damage is done?
In-Person & Virtual