SEC536: Adversarial AI - Penetration Testing AI Systems


The Agentic SOC: Human-Led, Agent-Operated Security AI is pushing both attackers and defenders to machine speed. From autonomous vulnerability discovery to agent-driven attack chains, the threat landscape is evolving faster than traditional SOCs can keep up.
At the same time, the industry is obsessed with model power: GPT-5.5, Mythos, and beyond. Bigger models, better benchmarks, more hype. But raw model power is not what will define the future SOC. The idea of a fully autonomous “AI SOC” is misleading: Security is not a problem you can hand over to a model, no matter how advanced. The presenter sees a different future: human-led, agent-operated.
The Agentic SOC is built on architecture, not just AI:
In this session, Erik will demonstrate this through a live end-to-end demo: AI agents handling a SOC queue and responding to an active attack on a simulated ship control system, while humans steer every step. If you’re focusing only on the model, you’re missing the point.
In-Person
Registration:
About Core NetWars: The most comprehensive and AI-forward cyber range in the NetWars portfolio. Designed for practitioners across multiple disciplines, Core NetWars combines emerging AI security challenges with real-world cyber scenarios to strengthen the technical skills most needed for today's threats. It is the only range that qualifies for the annual Core NetWars Tournament of Champions!
Computer Requirements: Internet-based
Recommended For: All infosec practitioners of any level. It is recommended, but not required, that students have a basic or foundational knowledge of information technology and technical topics.
Disciplines: Cybersecurity 101, Cyber Defense, Penetration Testing, Digital Forensics, Incident Response, Cloud Computing, and AI.
Example Topics:
Interactive Scenario: SANS students are deployed to BLOCCORP, a global media giant built on toys, streaming, gaming, and AI. As strange activity spreads across its infrastructure, they uncover compromised systems, vulnerable AI models, rogue IoT devices, and reckless automation. Can they expose BLOCCORP’s hidden agenda and stop its AI-driven ambitions before the damage is done?
In-Person & Virtual
Registration:
About Core NetWars: The most comprehensive and AI-forward cyber range in the NetWars portfolio. Designed for practitioners across multiple disciplines, Core NetWars combines emerging AI security challenges with real-world cyber scenarios to strengthen the technical skills most needed for today's threats. It is the only range that qualifies for the annual Core NetWars Tournament of Champions!
Computer Requirements: Internet-based
Recommended For: All infosec practitioners of any level. It is recommended, but not required, that students have a basic or foundational knowledge of information technology and technical topics.
Disciplines: Cybersecurity 101, Cyber Defense, Penetration Testing, Digital Forensics, Incident Response, Cloud Computing, and AI.
Example Topics:
Interactive Scenario: SANS students are deployed to BLOCCORP, a global media giant built on toys, streaming, gaming, and AI. As strange activity spreads across its infrastructure, they uncover compromised systems, vulnerable AI models, rogue IoT devices, and reckless automation. Can they expose BLOCCORP’s hidden agenda and stop its AI-driven ambitions before the damage is done?
In-Person & Virtual
Modern security teams face a growing challenge: how to develop high-fidelity detection content that’s both actionable and resilient to evasive threats.
This talk explores the design and deployment of a robust detection engineering lab—built both on-prem and in the cloud—that enables engineers to simulate real-world attacks, validate hypotheses, and rapidly iterate on detection logic.
Whether working with Sigma rules, custom YARA signatures, or proprietary analytics, having a controlled yet realistic testing ground is essential for bridging the gap between theory and operational detection. We’ll dive into the architecture and automation behind building this lab—from infrastructure-as-code for rapid, repeatable environments, to the integration of honeypots and deception tools that mimic attacker behaviors. You'll learn how to orchestrate data pipelines into SIEMs, leverage attack simulation frameworks like Atomic Red Team, and run continuous detection validations.
The goal: empower detection engineers to write, test, and deploy high-quality detections with confidence, speed, and measurable impact.
In-Person
Can AI autonomously test a web application? We’ll put that claim to the test. Starting with classic web vulnerabilities and the manual methodology behind finding them, we’ll progressively automate the process using different agentic workflows. We’ll compare the results of different methods, discuss where they succeed and fail, and share practical lessons learned while designing an effective security-focused agent.
In-Person
Registration:
About Core NetWars: The most comprehensive and AI-forward cyber range in the NetWars portfolio. Designed for practitioners across multiple disciplines, Core NetWars combines emerging AI security challenges with real-world cyber scenarios to strengthen the technical skills most needed for today's threats. It is the only range that qualifies for the annual Core NetWars Tournament of Champions!
Computer Requirements: Internet-based
Recommended For: All infosec practitioners of any level. It is recommended, but not required, that students have a basic or foundational knowledge of information technology and technical topics.
Disciplines: Cybersecurity 101, Cyber Defense, Penetration Testing, Digital Forensics, Incident Response, Cloud Computing, and AI.
Example Topics:
Interactive Scenario: SANS students are deployed to BLOCCORP, a global media giant built on toys, streaming, gaming, and AI. As strange activity spreads across its infrastructure, they uncover compromised systems, vulnerable AI models, rogue IoT devices, and reckless automation. Can they expose BLOCCORP’s hidden agenda and stop its AI-driven ambitions before the damage is done?
In-Person & Virtual
Registration:
About Core NetWars: The most comprehensive and AI-forward cyber range in the NetWars portfolio. Designed for practitioners across multiple disciplines, Core NetWars combines emerging AI security challenges with real-world cyber scenarios to strengthen the technical skills most needed for today's threats. It is the only range that qualifies for the annual Core NetWars Tournament of Champions!
Computer Requirements: Internet-based
Recommended For: All infosec practitioners of any level. It is recommended, but not required, that students have a basic or foundational knowledge of information technology and technical topics.
Disciplines: Cybersecurity 101, Cyber Defense, Penetration Testing, Digital Forensics, Incident Response, Cloud Computing, and AI.
Example Topics:
Interactive Scenario: SANS students are deployed to BLOCCORP, a global media giant built on toys, streaming, gaming, and AI. As strange activity spreads across its infrastructure, they uncover compromised systems, vulnerable AI models, rogue IoT devices, and reckless automation. Can they expose BLOCCORP’s hidden agenda and stop its AI-driven ambitions before the damage is done?
In-Person & Virtual