SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsPractical frameworks for governing the responsible use of AI in Digital Forensics and Incident Response.

Organizations are already using AI within investigative workflows. The challenge is no longer whether AI should be used. It's ensuring it's used responsibly.
Digital Forensics and Incident Response teams are already applying AI to accelerate investigations, correlate indicators, and reduce manual workload. That progress raises real questions: Who is accountable for AI-assisted findings? How is evidentiary integrity preserved? When can AI be trusted and where should AI never be relied upon?
The SANS Digital Forensics and Incident Response AI Frameworks answer those questions with practical, practitioner-developed guidance, not generic AI policy. These two frameworks are purpose-built for Digital Forensics and Incident Response and are grounded in real-world investigative experience, community collaboration, and recognized investigative methodologies.
Aligned with SWGDE Best Practices for Digital & Multimedia Evidence, this framework provides practical guidance for governing the responsible use of AI throughout the digital forensic lifecycle while preserving human accountability, validation, and evidentiary integrity.

This framework applies NIST Cybersecurity Framework (CSF) 2.0 to incident response, giving teams clear guardrails for using AI responsibly while maintaining operational trust, validation, and human decision making.

Developed by Heather Barnhart, DFIR Curriculum Lead and Head of Faculty at SANS Institute, and grounded in operational investigative experience, recognized methodologies, and community collaboration through the SANS DFIR Summit.
