SEC536: Adversarial AI - Penetration Testing AI Systems

Not sure what to take next? Stop by and talk it through with Wes Barnes, SANS Global Director of Customer Success. Bring your current cert path, your team's skill gaps, or just a general "what's next" question.
Wes will help map a training pathway that fits where you're headed. He'll also be showing a few new tools SANS is building to make course selection and skill development easier. Drop-ins welcome, no pitch, just planning!
In-Person
New York doesn't do anything halfway—and neither does this community. Join us for an evening that brings the world's top cybersecurity practitioners together in the city where ambition, talent, and opportunity collide. Whether you're protecting critical infrastructure, leading a SOC, or deep in the weeds of offensive research, this is your room. Networking Reception: 5:30pm - 6:30pm followed by a SANS@Night Talk. More details below.
In-Person
From the vulnerability scanners of the 1990s to today's exposure management frameworks, and beyond.
Join SANS Principal Instructor Jorge Orchilles on a trip through the past, present, and future of offensive security and vulnerability management. Understand where the discipline has been, where it stands today, and where every practitioner should be steering their program next.
Practical. Provocative. Precisely what a SANS@Night talk should be.
In-Person
USB Keyboard Emulation Device (KED) attacks remain a persistent threat due to their ability to bypass standard security controls by impersonating trusted peripherals. While commercial tools like the USB Rubber Ducky have made these attacks widely known, the barrier to entry has dropped dramatically with the availability of $4 microcontrollers.
This talk covers how these devices work and their attack mechanisms. Attendees will learn how to construct these devices for security testing while understanding the defensive challenges they present.
***This is an interactive workshop! Be sure to bring your laptop (with a USB-A port or USB-C to USB-A adapter) to get free hardware to program and keep.
Scope
In-Person
In the 1990s, government agencies, industry groups, and cybersecurity researchers began developing cybersecurity standards, which led to regulations and laws that require organizations to protect their data. Today, there are now dozens of standards dictating thousands of cybersecurity controls that organizations can consider when building their cybersecurity plans.
Every year, more standards are released, and the confusion grows. To make the problem even more challenging, no two standards are the same, nor do they even cover the same scope of defenses. This reality has led to confusion and frustration for organizations seeking to build comprehensive cybersecurity programs.
What should we do, what can we do, or must we do to protect our own information systems?
Until recently, there has been no Cyber Rosetta Stone for security and privacy professionals to compare these standards. Most organizations have limited resources and must choose which controls to implement and which to ignore. We haven’t had risk or threat models to demonstrate why certain cybersecurity controls are important and what should be prioritized.
In this presentation, Russell Eubanks, Principal Instructor at the SANS Institute and Managing Partner at Cyverity, will explain the state of cybersecurity standards with a scorecard comparison of popular standards based on specific, measurable research.
This presentation is an annual report that will focus primarily on the changes to the cybersecurity standards space over the past year. He will also introduce a Cyber Rosetta Stone that simplifies the process of building a cybersecurity control library across all standards.
Attendees will leave this webcast with a clear understanding of the differences and gaps among cybersecurity standards, enabling informed decisions about which standards to use when building their own cybersecurity programs.
In-Person