SEC536: Adversarial AI - Penetration Testing AI Systems





Kick off your Network Security 2026 experience at the Welcome Reception designed to bring the community together before the week begins. Connect with fellow cybersecurity professionals, SANS faculty, and industry peers as you ease into the event. Share insights, spark conversations around today’s evolving threat landscape, and start building the relationships that will carry through the week. Enjoy refreshing beverages (adult and otherwise) and appetizers as we head into the fantastic week ahead.
In-Person
Kick off the evening by connecting with fellow attendees over drinks and light fare before heading into the exciting keynote presentation. This informal reception is the perfect opportunity to network, share ideas, and build new connections.
In-Person
This talk begins with a brief examination of recent breach data and the growing ecosystem of attacker tooling available through Dark Web marketplaces and Telegram channels, highlighting where OSINT and cyber threat intelligence teams should focus their monitoring efforts.
We will then explore why multi-factor authentication (MFA) bypass attacks continue to succeed despite widespread adoption, examining both the technical and operational factors that make these attacks so effective. The majority of the presentation will focus on Artificial Intelligence (AI) and its rapidly expanding role in modern offensive security. We will analyze how attackers are leveraging AI to dramatically increase the speed, scale, and sophistication of attacks, while also examining AI systems themselves as an emerging attack surface.
The session will demonstrate how AI can be applied as both a SAST and DAST capability for discovering and exploiting zero-day vulnerabilities in web applications, as well as its growing role in binary exploitation. Offensive innovation has historically outpaced defensive adaptation, and the adoption of AI is accelerating this imbalance.
This talk provides practical insight into how the threat landscape is evolving and what security professionals must understand to keep pace.
In-Person & Virtual
Do you understand Active Directory? Your enterprise, just like the entire Fortune 500, depends on it. Come to this talk to learn the most common, over-powered attacks that hackers are using now, learn how to lock these attacks down, and perhaps most important -- learn to detect when attackers are trying. Attackers don't get points for new attacks. Learn what they use, lock it down, and detect it.
In-Person & Virtual
I spent 25 years doing things the hard way. JTAG probes, logic analyzers, hex editors, late nights staring at Ghidra. When AI started creeping into security tooling, I did what any seasoned pentester would do: I crossed my arms and waited for it to prove itself. Then I let go of the wheel.
This talk is the story of how I went from skeptic to believer by building Plan R, an IoT-focused MCP server that gives AI agents direct access to real pentesting tools. We will walk through the architecture, the playbook-driven methodology that lets you teach an AI agent to hack new protocols and attack surfaces, and how iterating on playbooks turned a firmware-only tool into a multi-domain IoT pentesting framework spanning WiFi, BLE, network protocols, and beyond.
More importantly, we will walk through a real engagement where this approach uncovered vulnerabilities in a named vendor's IoT product, the messy reality of disclosing AI-discovered findings to a white box vendor, and what it taught us about the gap between what AI finds and what you can actually defend in a disclosure conversation. Part confessional, part technical demo, part cautionary tale.
Attendees will leave with a practical blueprint for building their own AI pentesting agents and a clear-eyed understanding of when to let go of the wheel and when to grab it back.
In-Person & Virtual
Your Incident Response plan is lying to you. Not deliberately—it just hasn't met the incident yet. Steve unpicks the gap between the plan your board signed off and the ransomware incident your team is actually fighting at three in the morning.
The spice must flow, the business must keep running, and somewhere between those two truths sits an Incident Commander trying very hard not to pull their hand out of the pain box.
This is a Dune themed working session on the habits, instincts and small acts of discipline that separate Incident Commanders who hold the line from those who panic-pay the ransom by lunchtime. Bring your runbooks. Leave the blue pill at the door. The worm is already coming.
In-Person & Virtual
You came here to talk about security. Good news, this talk isn't about that. Here's the thing. It doesn't matter whether you're offense, defense, management, forensics, or something in between. We've all got two things in common. First, we know AI is powerful. Second, we all have investments, and every one of us would like them to do a little better.
For a while now I've been leaning hard on AI to analyze my own investments. Stocks, real estate, and a handful of alternative plays. And honestly, the results have been good enough that I figured they were worth sharing.
In this talk I'll show you the actual techniques I'm using, walk through some real results, and hand you things you can go try the minute you get back to your hotel room. I'm not a financial advisor and I'm not here to sell you anything. I'm a security guy who got curious, pointed AI at his portfolio, and liked what happened. No theory, no vendor pitch, just real-world stuff for pointing AI at something that affects every single one of us, which is our money.
Take a break from security for an hour and let's talk about something fun.
In-Person & Virtual
Balancing the scales between safeguarding information assets and enabling business growth demands not just technical acumen but a strategic mindset.
"Cybersecurity Without the Chaos: A Step-by-Step Roadmap" is a presentation tailored to demystify the complexities of cybersecurity risk management, offering actionable insights and practical strategies for CISOs and cybersecurity leaders.
In this presentation, James Tarala, Senior Faculty at the SANS Institute and Managing Partner at Cyverity, will delve into the core principles of effective cyber risk management, emphasizing the necessity of making informed decisions when allocating limited resources among good, better, and best safeguards.
Attendees will gain a deeper understanding of how to assess their organization's current cybersecurity posture, identify gaps against their target state, and develop targeted plans to advance their cybersecurity maturity.
Drawing upon the structured pathway provided by the Cybersecurity Risk Foundation (CRF) Governance and Risk Model (GRM), this webcast provides a roadmap for navigating the challenges of cybersecurity enhancement. It emphasizes a systematic approach to improving defenses, ensuring resilience against evolving threats, and embedding cybersecurity as a cornerstone of operational and strategic planning.
Join us to learn how to turn the theoretical aspects of cybersecurity into a repeatable, annual cycle that aligns with your organization's strategic goals and operational needs.
Whether you're looking to refine your organization's cybersecurity strategy or seeking practical tips on managing cyber risks more effectively, this webcast is designed to equip you with the knowledge and tools necessary to elevate your organization's cybersecurity posture. Perfect for CISOs, cybersecurity leaders, and anyone involved in managing cybersecurity practices, "Cybersecurity Without the Chaos: A Step-by-Step Roadmap" is your guide to understanding and implementing a robust cyber risk management program.
In-Person & Virtual
Registration:
About Core NetWars: The most comprehensive and AI-forward cyber range in the NetWars portfolio. Designed for practitioners across multiple disciplines, Core NetWars combines emerging AI security challenges with real-world cyber scenarios to strengthen the technical skills most needed for today's threats. It is the only range that qualifies for the annual Core NetWars Tournament of Champions!
Computer Requirements: Internet-based
Recommended For: All infosec practitioners of any level. It is recommended, but not required, that students have a basic or foundational knowledge of information technology and technical topics.
Disciplines: Cybersecurity 101, Cyber Defense, Penetration Testing, Digital Forensics, Incident Response, Cloud Computing, and AI.
Example Topics:
Interactive Scenario: SANS students are deployed to BLOCCORP, a global media giant built on toys, streaming, gaming, and AI. As strange activity spreads across its infrastructure, they uncover compromised systems, vulnerable AI models, rogue IoT devices, and reckless automation. Can they expose BLOCCORP’s hidden agenda and stop its AI-driven ambitions before the damage is done?
In-Person & Virtual
Registration:
About DFIR NetWars: Focused on digital forensics, incident response, threat hunting, and malware analysis, this tool-agnostic approach covers everything from low-level artifacts to high-level behavioral observations.
Computer Requirements: Laptop/desktop-based
Recommended For: Experienced Digital Forensic Analysts, Forensic Examiners, Media Exploitation Examiners, Malware Analysts, Incident Responders, Threat Hunters, Security Operations Center (SOC) Analysts, Law Enforcement Officers, Federal Agents, Detectives, and Cyber Crime Investigators.
Disciplines: Digital Forensics, Incident Response.
Example Topics:
Interactive Scenario: As a DFIR specialist, you are provided with evidence files from a series of mysterious compromised systems and conventional computing environments. Your mission? Use your DFIR skills to shed light on attack vectors, indicators of compromise, and other evidence needed to resolve the incident.
In-Person & Virtual
Registration:
About Core NetWars: The most comprehensive and AI-forward cyber range in the NetWars portfolio. Designed for practitioners across multiple disciplines, Core NetWars combines emerging AI security challenges with real-world cyber scenarios to strengthen the technical skills most needed for today's threats. It is the only range that qualifies for the annual Core NetWars Tournament of Champions!
Computer Requirements: Internet-based
Recommended For: All infosec practitioners of any level. It is recommended, but not required, that students have a basic or foundational knowledge of information technology and technical topics.
Disciplines: Cybersecurity 101, Cyber Defense, Penetration Testing, Digital Forensics, Incident Response, Cloud Computing, and AI.
Example Topics:
Interactive Scenario: SANS students are deployed to BLOCCORP, a global media giant built on toys, streaming, gaming, and AI. As strange activity spreads across its infrastructure, they uncover compromised systems, vulnerable AI models, rogue IoT devices, and reckless automation. Can they expose BLOCCORP’s hidden agenda and stop its AI-driven ambitions before the damage is done?
In-Person & Virtual
Registration:
About DFIR NetWars: Focused on digital forensics, incident response, threat hunting, and malware analysis, this tool-agnostic approach covers everything from low-level artifacts to high-level behavioral observations.
Computer Requirements: Laptop/desktop-based
Recommended For: Experienced Digital Forensic Analysts, Forensic Examiners, Media Exploitation Examiners, Malware Analysts, Incident Responders, Threat Hunters, Security Operations Center (SOC) Analysts, Law Enforcement Officers, Federal Agents, Detectives, and Cyber Crime Investigators.
Disciplines: Digital Forensics, Incident Response.
Example Topics:
Interactive Scenario: As a DFIR specialist, you are provided with evidence files from a series of mysterious compromised systems and conventional computing environments. Your mission? Use your DFIR skills to shed light on attack vectors, indicators of compromise, and other evidence needed to resolve the incident.
In-Person & Virtual