SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Raymond DePalma is President of DePalma Research LLC. Raymond brings 14 years of experience in digital forensics, SOC operations, SIEM engineering, incident response consulting, and solutions architecture. His work runs in both directions where AI and DFIR meet. The first is AI for DFIR: applying large language models and multi-agent systems to accelerate investigations. The second is DFIR of AI: investigating LLM applications, agentic pipelines, MCP servers, and RAG/vector stores when the AI system itself is the victim.
Raymond's career began at MIT Lincoln Laboratory. He completed three rotations there, moving from the Security Service Department to the Forensic Analysis Center to IT Security Threat Assessment while holding a Department of Defense Top Secret clearance. That work grounded him in digital forensic acquisition, open-source threat research, and compliance auditing against NISPOM and NIST standards.
After earning his B.S. from Northeastern University, he spent nearly four years at Liberty Mutual Insurance. He rose from IT Analyst to Lead Responder on the company's global LSERT, where he drove threat-hunting initiatives and built training and threat exercises for SOC analysts. He then served as Principal SIEM Security Engineer and tech lead of a five-person detection engineering team that scaled Splunk Enterprise Security across the organization. He later led Managed Security Services workstreams at IBM as a Security Delivery Project Executive. He then joined Rapid7 as a Senior Security Solutions Engineer, advising customers across SIEM, SOAR, and MDR.
Raymond then spent five years at Palo Alto Networks, advancing through four roles:
Raymond created "AI for the Win," an open-source training program of 50+ hands-on labs and Capture the Flag challenges. It helps practitioners bring AI and machine learning into their detection and response work. He also maintains open-source projects including ai-dfir-toolkit and the AI-Powered Ransomware Intelligence Agent. He is a featured guest on the SANS Stay Ahead of Ransomware livestream series hosted by FOR528 author Ryan Chapman, and he writes for the SANS blog on AI-driven ransomware defense.
"A lot of talented responders are sitting on the sidelines of AI because nobody showed them the on-ramp," he says. "If you can write a detection rule, you can learn to work with an LLM. The gap is smaller than people think."
Off the clock, Raymond lives in New Hampshire with his red golden retriever, Cooper. He splits his time between snowboarding, hiking, and a home lab that keeps him as busy as his day job.
Speaker / Contributor: This individual participates in SANS events, presentations, written content, or other community resources as an external contributor. They are not a SANS employee, instructor, or affiliate.
Review relevant educational resources made with contribution from this instructor.