SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Luke wants everyone to get better at the thing he loves most: running down an intruder in someone else's network. He is drawn to incident response because, unlike most of security, there is a live human on the other side of the keyboard. "Most of what we do in security is building walls and setting traps for things that might never come," he says. "Response is the one place you're up against an actual person who is trying to beat you, right now, in the moment. That's where the real fun is." His goal in the classroom is to turn skilled responders into people who can lead that fight — calm, methodical, and a step ahead of the adversary.
Luke's teaching focus is the discipline of the investigation itself: how to form a hypothesis, test it against the evidence, and keep a complex response coordinated when the pressure is on and the facts are still moving. He wants students to think clearly about what they are actually seeing before they act on it, to resist the pull of the obvious answer, and to understand that leading an intrusion response is as much about running the team and the timeline as it is about reading the artifacts. That same curiosity drives his research: Luke actively studies how to improve the practice of intrusion investigation and response, and feeds what he learns straight back into how he teaches it. At SANS he is the lead author of the upcoming FOR538, a course on taking ownership of the technical investigation and leading sophisticated intrusions from first detection through full eradication.
That focus comes from more than a decade of doing the work across government, consulting, and global enterprise. Luke led cyber security operations for Queensland's emergency services agencies, built a Security Operations Centre from the ground up in Australia, and spent nearly three years as a Senior Consultant with Mandiant, where he ran the most complex incident response engagements for APAC clients and became the person colleagues turned to for any problem that didn't fit an existing process. He is now Director of Cyber Security for the Computer Security Incident Response Team (CSIRT) at a major global SaaS provider, leading APAC and global incident response for one of the world's largest enterprise platforms. There he rebuilt the CSIRT hiring pipeline, cutting time-to-autonomy for new hires from three months to three weeks, and designed a triage process that brought median time-to-contain in the highest-risk environments down from twelve days to under forty minutes.
Luke holds the GIAC Security Expert (GSE #358), one of the most demanding credentials in the field, along with more than twenty GIAC certifications spanning incident response, forensics, intrusion analysis, penetration testing, and security leadership, including the GEIR, GX-FA, GX-IH, GX-IA, GCFA, GNFA, GCFR, GCIL, and GSTRT. He holds a Master's in Cyber Security from Charles Sturt University and the CISSP, and serves on GIAC advisory boards. He is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition. Luke writes about incident response, foundational skills, and the place of AI in security work at his blog, This Insecure World, and has presented at Black Hat Asia, BSides Brisbane, ChCon, and AvengerCon, and in SANS webcasts.
Away from the keyboard, Luke reads widely (with a heavy emphasis on fantasy), plays video games, and spends his time with family.
Review relevant educational resources made with contribution from this instructor.