SEC536: Adversarial AI - Penetration Testing AI Systems



Megan is a Senior Security Engineer at Datadog, SANS DFIR faculty, and co-author of FOR509. She holds two master’s degrees, serves as CFO of Mental Health Hackers, and is a strong advocate for hands-on cloud forensics training and mental wellness.
Virtual
Legacy DFIR stacks are slowing teams down with unreliable off-network collections, brittle or bloated agents, and too many disconnected point products and scripts. This creates operational drag that translates into increased risk, higher costs, and longer investigation timelines.
In this session, we'll demonstrate how Magnet Forensics solutions provide a faster, more resilient approach by replacing outdated remote collection methods while simplifying deployment and day-to-day operations. You'll see how investigators can leverage Magnet Nexus to remotely preview and collect evidence from live online endpoints, allowing teams to quickly target and acquire the data that matters most without waiting for devices to be physically accessed.
We’ll also explore how API-driven integrations with EDR and XDR platforms can automatically trigger collections the moment an alert fires, ensuring critical evidence is preserved before users shut down devices, systems go offline, or artifacts are overwritten. This session connects the dots across an integrated workflow spanning alerting, targeted collection, automated evidence acquisition, forensic analysis, and investigator collaboration.
*Sponsored by Magnet Forensics
Virtual
VMRay Labs identified a previously unattributed cybercriminal campaign, tracked as Operation STANDOFF, assessed with high confidence to be run by a Russian-speaking threat group and to remain actively maintained. It started with one behavioral detection. Execution-level analysis and infrastructure pivoting grew it into an operation combining commodity malware distribution, a proxy botnet, hands-on-keyboard intrusion and an AI-assisted influence capability.
In this session we will walk through that investigation end to end: how unrelated-looking findings connect, and how execution data drives infrastructure pivoting. One part of the infrastructure hid behind 301 redirects to GitHub. That behavior, together with certificate, TLS and hosting patterns, helped surface 48 related hosts, 44 of them published as indicators. GitHub was never compromised. The redirect was camouflage.
We will also cover STANDOFF COORD, the operators' own intrusion console, whose internal workflow could largely be reconstructed because its client-side code was exposed, and a Telegram account farm using AI-generated personas and automated engagement. Attendees will leave with the pivots and detection opportunities that turned one detection into campaign-level intelligence.
*Sponsored by VMRay
Virtual
Everyone claims an "AI SOC." This session shows the working machinery - and the evidence discipline that keeps it honest. You'll see how a triage agent defensibly auto-closes 80% of alert volume with evidence attached, how an orchestrator supervises specialist agents for packet forensics, identity, and threat intel, and why one wall is load-bearing: RAG advises, records prove.
Takeaways include bounding agents like service accounts (tool allowlists, query caps, read-only lanes), writing prompts as contracts rather than personas, containing false-negative risk with a sampled QA loop, and defending your retrieval pipeline against poisoned knowledge that rewrites agent behavior.
*Sponsored by Extrahop
Virtual
Virtual
When a critical vulnerability is disclosed, defenders often have only public research and limited detection content to assess exposure. Using FalconFlank, a local privilege escalation vulnerability in CrowdStrike Falcon Sensor, as a case study, this session demonstrates how to rapidly translate advisories and proof of concept research into actionable threat hunting content.
Attendees will learn how to identify exploitation artifacts across process, file system, and memory telemetry, then apply a repeatable detection engineering framework to future vulnerabilities, helping close visibility gaps before patches and detection coverage become available.
*Sponsored by Leap
Virtual
Virtual
Virtual