SEC536: Adversarial AI - Penetration Testing AI Systems



Security culture is one of the most widely used terms in cybersecurity, yet it is often poorly defined and poorly understood. This session challenges a common assumption: that security culture exists as something separate from organisational culture. Instead, we will explore how existing cultural norms, leadership behaviours, incentives and stories influence security decisions across the workforce. Drawing on practical examples and established organisational culture models, the session offers a different perspective on culture change. If we want to improve security outcomes, we must stop trying to build a separate security culture and start understanding the culture we already have.
In-Person & Virtual
This hands-on session will take you through a detailed FOR589 lab focusing on the complexities of cybercrime infrastructure. You will dive into the critical types of infrastructure indicators—Atomic, Behavioral, and Computed—and their roles in detecting and understanding cybercrime activities. Learn about the pivotal role that domains, IP addresses, and email accounts play as Atomic Indicators, and understand how Infrastructure-as-a-Service (IaaS) helps in identifying the ownership of these indicators. The workshop includes practical exercises where you will use advanced fingerprinting techniques not only to identify but also to predict cybercrime behaviors. This approach will enhance your skills in analyzing and countering cyber threats.
Learning Objectives: Learn to profile the technical infrastructure of cybercriminal sites, including malware Command & Control (C2) domains, phishing pages, and forums. Understand how to profile and disrupt the technical attack infrastructure of a cybercrime campaign. Develop skills to pivot and uncover additional elements of cybercriminal infrastructure.
Understand how to profile and disrupt the technical attack infrastructure of a cybercrime campaign. Develop skills to pivot and uncover additional elements of cybercriminal infrastructure.
Prerequisites: This workshop consists of a series of practical exercises designed for cybercrime investigators or researchers looking to enhance their skills in analyzing criminal infrastructure. Participants should have a problem-solving mindset and be open to learning new methods for investigating cybercrime. The technical prerequisites for this workshop are minimal, making it accessible for those with a basic understanding of cybersecurity concepts.
The content from this event supports concepts from the following SANS course - FOR589: Cybercrime Investigations
How to Prepare for the Workshop: This workshop is designed for cybercrime investigators or researchers. Bring your problem-solving skills and eagerness to learn new investigative techniques:
Check the system requirements on the FOR589 course page: www.sans.org/FOR589Download the SANS FOR589 Cybercrime Intelligence CROM VM using the following link and password to participate in the exercises: Download link: www.for589.com/workshop Password: SANSFOR589workshop
In-Person & Virtual
Registration:
About Core NetWars: The most comprehensive and AI-forward cyber range in the NetWars portfolio. Designed for practitioners across multiple disciplines, Core NetWars combines emerging AI security challenges with real-world cyber scenarios to strengthen the technical skills most needed for today's threats. It is the only range that qualifies for the annual Core NetWars Tournament of Champions!
Computer Requirements: Internet-based
Recommended For: All infosec practitioners of any level. It is recommended, but not required, that students have a basic or foundational knowledge of information technology and technical topics.
Disciplines: Cybersecurity 101, Cyber Defense, Penetration Testing, Digital Forensics, Incident Response, Cloud Computing, and AI.
Example Topics:
Interactive Scenario: SANS students are deployed to BLOCCORP, a global media giant built on toys, streaming, gaming, and AI. As strange activity spreads across its infrastructure, they uncover compromised systems, vulnerable AI models, rogue IoT devices, and reckless automation. Can they expose BLOCCORP’s hidden agenda and stop its AI-driven ambitions before the damage is done?
In-Person & Virtual
Registration:
About Core NetWars: The most comprehensive and AI-forward cyber range in the NetWars portfolio. Designed for practitioners across multiple disciplines, Core NetWars combines emerging AI security challenges with real-world cyber scenarios to strengthen the technical skills most needed for today's threats. It is the only range that qualifies for the annual Core NetWars Tournament of Champions!
Computer Requirements: Internet-based
Recommended For: All infosec practitioners of any level. It is recommended, but not required, that students have a basic or foundational knowledge of information technology and technical topics.
Disciplines: Cybersecurity 101, Cyber Defense, Penetration Testing, Digital Forensics, Incident Response, Cloud Computing, and AI.
Example Topics:
Interactive Scenario: SANS students are deployed to BLOCCORP, a global media giant built on toys, streaming, gaming, and AI. As strange activity spreads across its infrastructure, they uncover compromised systems, vulnerable AI models, rogue IoT devices, and reckless automation. Can they expose BLOCCORP’s hidden agenda and stop its AI-driven ambitions before the damage is done?
In-Person & Virtual