SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsNinety practicing incident responders ran 1,775 tests against 123 finalists before choosing the winners, whose harnesses are open source
North Bethesda, MD, August 27, 2026 -- SANS Institute named the winners of Find Evil!, the largest practitioner evaluation of autonomous AI incident response agents to date. Ninety practicing incident responders ran 1,775 evaluations against 123 hackathon submissions, attacking each entry's safeguards before winners were named. All five winning harnesses are open source and available on GitHub.
“AI systems are like cars; the model is the engine and the harness is the chassis.” That is how Rob T. Lee, Chief AI Officer and Chief of Research at SANS Institute, separates a trustworthy AI incident response tool from a dangerous one. The model does the thinking; the harness is the code built around it that constrains what it can touch, checks its work, and keeps it from acting on a bad idea. Find Evil! was built to test that code under attack.
Find Evil! drew 4,413 registered entrants. By the time submissions closed, 291 teams had working code, and 123 qualified to advance to judging.
Lee built the first version of a digital forensics harness himself, over a weekend, then pointed that early prototype at a compromised system live on stage at RSA Conference 2026. Fourteen minutes and twenty-seven seconds later, it returned a complete forensic analysis of the system's C drive, work Lee said typically takes incident responders a week or longer by hand.
“Most of the harnesses out there right now are not going through a significant amount of testing,” Lee said in an interview ahead of this release. “These harnesses are like cars built in a garage.They need to be sent through crash tests to make sure we've thought of every single thing that could happen to this vehicle and that the driver is safe inside the car."
The Find Evil! Hackathon was designed to test every submission with practicing incident responders, skeptical that autonomous AI tools could be used in real investigations.
Lee singled out an important detail about the top submissions as a clear lesson of the challenge: the first- and second-place builders came from opposite fields, one from AI/ML, and one from security. Each had to learn the other's discipline to compete.
Almost every one of the 123 submissions blocked attempts to alter the systems under investigation. Protections in the code itself forced the model to behave, rather than trusting instructings to enforce behavior.
With fabrication effectively ruled out, judges were able to compare entries on how thorough an investigation each harness could complete.
Harnesses that documented their own failures scored better than ones that claimed perfect accuracy. FindEvil, a top five finalist, found and fixed two flaws in its own guardrails during development and published the fixes.
Find Evil! cost no fee to enter. Total prizes exceeded $22,000, with $10,000 for first place, $7,500 for second, and $4,500 for third. The SANS SIFT Workstation, the open source platform underpinning the challenge, is downloaded roughly 60,000 times a year, and is available globally to defenders. The top five harnesses are already installed in SIFT; using one requires nothing more than adding an API key for the model of an organization's choice.
“The tools that take on AI-speed attacks should belong to the community that defends against them, not to a vendor's price list,” Lee said.
Full results, all 123 submissions, demo videos, and source repositories are available at findevil.devpost.com.
For the full story behind the results, including how the winning harnesses work, what the judges attacked, and which two are shipping on the SIFT Workstation, see Find Evil! Winners: Five Open Source DFIR Agents.
About SANS Institute: The SANS Institute is the global leader in cybersecurity training and certifications, trusted by governments, enterprises, and security professionals worldwide. For over three decades, SANS has set the industry standard for technical excellence, equipping practitioners with the real-world skills needed to defend today’s most complex digital environments. As cybersecurity evolves, SANS continues to lead the way, defining best practices and establishing the global benchmark for AI security and emerging technologies.
Media Contact:
Jenn Elston
SANS Institute