SEC536: Adversarial AI - Penetration Testing AI Systems


Crowley will review findings from the 2026 survey: AI use, technology satisfaction, staffing, metrics, funding, and security operations capabilities. He'll delve into extensive details of results, multi-year trend analysis, correlation details, and share the code and methodology he uses for reviewing survey responses. Every company has security operations of some form. Come to this talk to understand what you can do better when you return to work.
In-Person & Virtual
The Washington, DC metro region is home to one of the nation's most influential cybersecurity communities, where government, industry, and security leaders come together to tackle today's biggest challenges. Join us for an evening of networking, conversation, and lasting connections.
Connect with the Washington, DC Cybersecurity Community Home to federal agencies, defense organizations, leading enterprises, and cybersecurity innovators, the Washington, DC metro area brings together one of the nation's most active security communities. SANS DC Metro 2026 Community Night is your opportunity to connect with the professionals, practitioners, and leaders advancing cybersecurity every day.
Note: SANS DC Metro course students do not need to register to attend.
In-Person
Join us for an exciting, hands-on exploration where we transform a humble chat completion script into a sophisticated, fully agentic AI system, all through a series of live, iterative demonstrations. We will demystify how they work by building an agentic system from the ground up.
We'll kick off with a memory-less agent that does well with single questions but stumbles on conversational follow-ups. Watch as we add persistent message history, enabling coherent multi-turn dialogues.
Next, we'll hit the wall of context limits when tackling file operations and large data, revealing why raw tool access isn't enough. Through additions of tool-calling capabilities, we'll differentiate between built-in tools and configurable MCP services. Our agent will gain "hands" to act on the world, "eyes" to inspect complex data structures (databases, logs, packets, registries), and advanced memory architectures to manage its cognitive load.
Culminating in a blueprint for agentic memory management, including adaptive system prompts, modular skill loading, planning modes, and compressible context, we'll demonstrate how these elements combine to create truly autonomous, efficient AI agents.
Note: This is a hands-on exercise and attendees are encouraged to bring their laptops.
In-Person & Virtual