SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsOrganizations are deploying autonomous AI agents into production at scale: agents that authenticate, execute multi-step workflows, and make decisions across cloud infrastructure. These agents operate at machine speed, which means security operations must too. When agents behave unexpectedly, the pattern closely resembles an insider threat, but traditional detection and response cycles were designed for human-speed investigation. In this session, we'll share what we're seeing across enterprise environments as agentic workloads go into production: where the detection gaps are, why observability and security telemetry must converge at the application layer, and how organizations are building response capabilities that contain and remediate autonomously in seconds, not hours. We'll walk through practical patterns for calibrating automated response: when to contain, when to escalate, and when to let the system close the loop. The goal is to make security as fast and autonomous as the workloads it protects.


Dr. Rittenhouse is a security industry veteran with deep technical expertise and is regularly consulted on a wide range of security topics such as Zero Trust, data protection, and cloud security.
Read more about Gee Rittenhouse

Eric Johnson is a Fellow at the SANS Institute and Principal Security Engineer at Puma Security. He leads hands-on training in SEC540: Cloud Native Security and DevSecOps Automation, co-authors SEC549 and SEC510, and develops open-source tools to help practitioners secure cloud pipelines.
Read more about Eric Johnson








