SEC536: Adversarial AI - Penetration Testing AI Systems

Artificial Intelligence has transformed social engineering from crude phishing emails into highly personalized, scalable, and disturbingly convincing manipulation campaigns.
In this session, we explore how attackers are leveraging generative AI, voice cloning, deepfakes, and conversational bots to exploit human trust with unprecedented precision. From AI-written spear-phishing emails that perfectly mimic corporate tone, to deepfake audio impersonating executives in real-time fraud attempts, the barriers to launching sophisticated attacks have dramatically lowered.
This talk examines how AI enables hyper-personalization at scale, adapts dynamically during live interactions, and exploits psychological triggers such as urgency, authority, and familiarity. Participants will gain insight into emerging threat patterns including AI-enhanced Business Email Compromise (BEC), automated scam call centers, synthetic identities, and misinformation campaigns.
Through real-world examples and case studies, we will unpack why traditional awareness training is no longer enough—and what new verification strategies are required in an era where seeing and hearing are no longer believing.
In-Person
Registration:
About Core NetWars: The most comprehensive and AI-forward cyber range in the NetWars portfolio. Designed for practitioners across multiple disciplines, Core NetWars combines emerging AI security challenges with real-world cyber scenarios to strengthen the technical skills most needed for today's threats. It is the only range that qualifies for the annual Core NetWars Tournament of Champions!
Computer Requirements: Internet-based
Recommended For: All infosec practitioners of any level. It is recommended, but not required, that students have a basic or foundational knowledge of information technology and technical topics.
Disciplines: Cybersecurity 101, Cyber Defense, Penetration Testing, Digital Forensics, Incident Response, Cloud Computing, and AI.
Example Topics:
Interactive Scenario: SANS students are deployed to BLOCCORP, a global media giant built on toys, streaming, gaming, and AI. As strange activity spreads across its infrastructure, they uncover compromised systems, vulnerable AI models, rogue IoT devices, and reckless automation. Can they expose BLOCCORP’s hidden agenda and stop its AI-driven ambitions before the damage is done?
In-Person & Virtual
Registration:
About Core NetWars: The most comprehensive and AI-forward cyber range in the NetWars portfolio. Designed for practitioners across multiple disciplines, Core NetWars combines emerging AI security challenges with real-world cyber scenarios to strengthen the technical skills most needed for today's threats. It is the only range that qualifies for the annual Core NetWars Tournament of Champions!
Computer Requirements: Internet-based
Recommended For: All infosec practitioners of any level. It is recommended, but not required, that students have a basic or foundational knowledge of information technology and technical topics.
Disciplines: Cybersecurity 101, Cyber Defense, Penetration Testing, Digital Forensics, Incident Response, Cloud Computing, and AI.
Example Topics:
Interactive Scenario: SANS students are deployed to BLOCCORP, a global media giant built on toys, streaming, gaming, and AI. As strange activity spreads across its infrastructure, they uncover compromised systems, vulnerable AI models, rogue IoT devices, and reckless automation. Can they expose BLOCCORP’s hidden agenda and stop its AI-driven ambitions before the damage is done?
In-Person & Virtual