SEC536: Adversarial AI - Penetration Testing AI Systems

Join us for an In-Person Networking Breakfast to kick off your SANS San Antonio experience. Connect with fellow attendees, exchange insights, and discover tips for making the most of your week in San Antonio, TX. Enjoy complimentary coffee and a light breakfast while building valuable connections to start your day.
In-Person
It’s no secret that artificial intelligence now plays a critical role in most modern enterprises. It does everything from screening resumes to triaging security alerts to even generating code, often without human oversight. We have, in essence, handed these models the keys to our kingdom, getting so consumed by the question of "can we" that we forgot to ask "should we."
Unfortunately, that question is quickly being answered for us by our adversaries. Every capability and advancement we’ve celebrated also hides a vulnerability we overlooked. The same model that screens a resume can be coerced into following an attacker’s hidden instructions. The same assistant that writes our code can be convinced to implement a hidden back door. The worst part is that organizations have no idea how prominent these attacks have become, or that they are exposing an attack surface that traditional penetration testing was never built to address. Prompt injection, jailbreaks, training-data poisoning, model extraction, and agentic exploitation are happening every day, and most security teams still lack any methodology to test for them.
This session, based on the new SEC536: AI Penetration Testing course, shifts focus from AI's capabilities to its role as a new attack vector, encouraging critical evaluation of its use. Live demonstrations will show how production-grade AI assistants can be manipulated to bypass safeguards, leak confidential data, and perform prohibited actions. Attendees will learn how these attacks operate, why standard defenses are ineffective, and how to incorporate AI systems into security assessments.
In-Person & Virtual
A relaxed evening reception designed to bring together OnDemand students, SANS instructors, course authors, and staff — for real conversation, shared stories, and new professional connections. It's where solo study becomes shared community.
Enjoy light bites, drinks, and open access to:
We can't wait to welcome you to SANS Unplugged.
In-Person
Registration:
About Core NetWars: The most comprehensive and AI-forward cyber range in the NetWars portfolio. Designed for practitioners across multiple disciplines, Core NetWars combines emerging AI security challenges with real-world cyber scenarios to strengthen the technical skills most needed for today's threats. It is the only range that qualifies for the annual Core NetWars Tournament of Champions!
Computer Requirements: Internet-based
Recommended For: All infosec practitioners of any level. It is recommended, but not required, that students have a basic or foundational knowledge of information technology and technical topics.
Disciplines: Cybersecurity 101, Cyber Defense, Penetration Testing, Digital Forensics, Incident Response, Cloud Computing, and AI.
Example Topics:
Interactive Scenario: SANS students are deployed to BLOCCORP, a global media giant built on toys, streaming, gaming, and AI. As strange activity spreads across its infrastructure, they uncover compromised systems, vulnerable AI models, rogue IoT devices, and reckless automation. Can they expose BLOCCORP’s hidden agenda and stop its AI-driven ambitions before the damage is done?
In-Person & Virtual
Registration:
About Core NetWars: The most comprehensive and AI-forward cyber range in the NetWars portfolio. Designed for practitioners across multiple disciplines, Core NetWars combines emerging AI security challenges with real-world cyber scenarios to strengthen the technical skills most needed for today's threats. It is the only range that qualifies for the annual Core NetWars Tournament of Champions!
Computer Requirements: Internet-based
Recommended For: All infosec practitioners of any level. It is recommended, but not required, that students have a basic or foundational knowledge of information technology and technical topics.
Disciplines: Cybersecurity 101, Cyber Defense, Penetration Testing, Digital Forensics, Incident Response, Cloud Computing, and AI.
Example Topics:
Interactive Scenario: SANS students are deployed to BLOCCORP, a global media giant built on toys, streaming, gaming, and AI. As strange activity spreads across its infrastructure, they uncover compromised systems, vulnerable AI models, rogue IoT devices, and reckless automation. Can they expose BLOCCORP’s hidden agenda and stop its AI-driven ambitions before the damage is done?
In-Person & Virtual