SEC536: Adversarial AI - Penetration Testing AI Systems



Kick off your SANSFIRE 2026 experience at this pre-keynote reception designed to bring the community together before the week begins. Connect with fellow cybersecurity professionals, SANS faculty, and industry peers as you ease into the event. Share insights, spark conversations around today’s evolving threat landscape, and start building the relationships that will carry through the week.
In-Person
AI accelerates development, attacks and to some extent, just maybe, defense. Our new ISC "Skynet 1.0" sensor takes advantage of LLMs to better disguise itself, find answers to attacks faster and inform defenders about ongoing attacks.
In-Person & Virtual
Start your day with intention. This all-levels guided yoga session by Katlyn Hill with Balanced Brain Yoga is designed to help you reset both mind and body before a full day of learning.
In-Person
The Internet Storm Center is going LIVE at SANSFIRE 2026—and you’re invited into the war room. Join the dedicated ISC Handlers this week as they transform a corner of our event into a full-fledged, live Command Threat Center. This is where real-time cyber intelligence meets hands-on insight—and you can watch it unfold.
In-Person
Security teams cannot detect what they cannot observe. Organizations are rapidly deploying agentic AI systems capable of executing commands, invoking tools, accessing data, and performing multi-step tasks with limited user interaction. Yet most security programs have little visibility into how these systems actually operate. While AI systems generate vast amounts of telemetry, collecting, normalizing, and correlating that data remains a significant challenge. Most AI telemetry was designed for observability, not security.
In-Person
Join Filigran for a hands-on OpenCTI demo, the leading open-source threat intelligence platform. Discover how OpenCTI centralizes threat data, enabling analysts to unify intelligence sources, accelerate analysis, and streamline reporting.
In-Person
*Sponsored by Sumologic
In-Person
Mythos claimed the headlines with access exclusivity, but we can use any AI model to accelerate vulnerability discovery.
In this talk, you'll learn how to apply the same workflow attackers are using to find zero-day vulnerabilities in open-source projects. You'll learn the practical techniques you can use to get started with vulnerability discovery using AI and apply them against a real-world target to build zero-day exploits.
In-Person & Virtual
Start your day with intention. This all-levels guided yoga session by Katlyn Hill with Balanced Brain Yoga is designed to help you reset both mind and body before a full day of learning.
In-Person
Start your day at the Vendor Expo Breakfast, where attendees can enjoy a complimentary breakfast while connecting with leading cybersecurity vendors and solution providers. Explore innovative technologies, learn about emerging industry trends, and engage in meaningful conversations with experts dedicated to advancing cyber defense and resilience.
In-Person
The SANS Vendor Solutions Exhibitor Hall brings together leading cybersecurity organizations and technology providers with a community of practitioners, defenders, and decision-makers dedicated to strengthening cyber resilience.
In-Person
Join us for lunch and take advantage of the opportunity to connect with fellow cybersecurity professionals, industry experts, and sponsors. Whether you're discussing insights from the morning sessions or exploring solutions in the Exhibitor Hall, lunch provides a valuable time to network, collaborate, and recharge for the afternoon ahead.
In-Person
In a field increasingly shaped by automation, AI, and digital tools, the relationships we build remain our greatest professional asset.
Join us for Community Night at SANSFIRE 2026—a dedicated evening for the people behind the keyboards.
In-Person
What if you could learn five times as much, every week? How would that compound over a career?
This practical talk introduces an AI-driven workflow designed to spot valuable topics in seconds (and skip the noise), capture and transcribe online media via Dev Tools and speech-to-text and effectively summarize the essentials.
In-Person & Virtual
Become part of the largest, oldest, and most open sensor network on the internet. Learn how to build, configure, and operate your very own honeypot. You are welcome to bring your own Raspberry Pi, n100, or similar system (or cloud account). This is a hands-on session and requires some familiarity with Linux.
Speakers: Internet Storm Center Handlers, Guy Bruneau and Jesse La Grew
In-Person
Start your morning with an energizing run or walk through the heart of the nation’s capital. Join fellow SANSFIRE attendees for a guided 5K route featuring some of Washington, D.C.’s most iconic landmarks, including the National Mall, Washington Monument, and White House corridor.
In-Person
The Internet Storm Center is going LIVE at SANSFIRE 2026—and you’re invited into the war room. Join the dedicated ISC Handlers this week as they transform a corner of our event into a full-fledged, live Command Threat Center. This is where real-time cyber intelligence meets hands-on insight—and you can watch it unfold.
In-Person
Information security is not getting easier. Our critical networks are complex, contain legacy systems, and may be isolated across remote sites. Poor network visibility jeopardizes your ability to safeguard critical assets, detect disruptions, proactively mitigate vulnerabilities, or respond to threats. Imagine having a comprehensive, real-time view of all assets and their detailed activity across all of your networks, all in one place.
In-Person
AI is a major topic of discussion today—and rightfully so. But for those of us in cybersecurity, it's crucial not only to understand how to use AI for security, but also to recognize the threats targeting AI models, their ecosystems, and how to defend and secure them effectively.
In-Person & Virtual
As part of your enrollment in a 4-6 day course at SANSFIRE 2026, you are eligible to participate in the Core NetWars Tournament (in-person & virtual) and Coin-A-Palooza (in-person).
For the in-person students, this is your chance to earn up to FIVE Offensive Operations challenge coins while participating in NetWars.
You read that right: if you've previously taken a SANS Offensive Operations course, this is your chance to earn challenge coins you may have missed out on! Only in-person students are eligible for Coin-A-Palooza.
Registration:
In-Person & Virtual
As part of your enrollment in a 4-6 day course at SANSFIRE 2026, you are eligible to participate in the Cyber Defense NetWars Tournament (in-person & virtual) and Coin-A-Palooza (in-person). For the in-person students, this is your chance to earn up to FIVE Cyber Defense challenge coins while participating in NetWars.
You read that right: if you've previously taken a SANS Cyber Defense course, this is your chance to earn challenge coins you may have missed out on! Only in-person students are eligible for Coin-A-Palooza.
Registration:
In-Person & Virtual
Join us at SANSFIRE as we honor the memory of Mark Jeanmougin, a beloved instructor and mentor who dedicated years to shaping the next generation of cyber defenders teaching SEC450 and SEC511.
In-Person
Join us at SANSFIRE 2026 for an evening of connection, conversation, and community at the Women’s Connect Reception.
This networking reception is designed to bring together women in cybersecurity, allies, mentors, practitioners, instructors, and industry peers for meaningful conversations in a welcoming environment.
In-Person
As part of your enrollment in a 4-6 day course at SANSFIRE 2026, you are eligible to participate in the Core NetWars Tournament (in-person & virtual) and Coin-A-Palooza (in-person).
For the in-person students, this is your chance to earn up to FIVE Offensive Operations challenge coins while participating in NetWars.
You read that right: if you've previously taken a SANS Offensive Operations course, this is your chance to earn challenge coins you may have missed out on! Only in-person students are eligible for Coin-A-Palooza.
Registration:
In-Person & Virtual
As part of your enrollment in a 4-6 day course at SANSFIRE 2026, you are eligible to participate in the Cyber Defense NetWars Tournament (in-person & virtual) and Coin-A-Palooza (in-person). For the in-person students, this is your chance to earn up to FIVE Cyber Defense challenge coins while participating in NetWars.
You read that right: if you've previously taken a SANS Cyber Defense course, this is your chance to earn challenge coins you may have missed out on! Only in-person students are eligible for Coin-A-Palooza.
Registration:
In-Person & Virtual