SEC536: Adversarial AI - Penetration Testing AI Systems

Examining common beliefs vs realities of cyber-attacks with an introduction to specific responsibilities of cyber security practitioners.
Focusing on three core principles of cyber security. The Principle of Least Privilege, The CIA Triad, and the principle of Prevent, Detect, Respond.
Learn how threats, vulnerabilities, countermeasures, laws, and compliance requirements inform Risk Management Programs.
Covers security hygiene practices that include practicing change control and configuration management; integrating security into SDLC; patch management; active threat hunting; and more.
Learn how to strengthen security with passphrases, password managers, and 2FA. This module covers best practices like using spaces in passphrases, setting permissions based on the Principle of Least Privilege, and understanding the Zero Trust Model.
Covering the effective deployment of encryption methods such as the Advanced Encryption Standard algorithm, Transport Layer Security, Internet Protocol Security, Virtual Private Networks, key management fundamentals, and Zero-Knowledge implementations.
Explore key attacks such as Social Engineering, Spear Phishing, Malware, and Denial of Service. This module also delves into advanced threats like QR Code Attacks, Teams Phishing, and AI-driven tactics, highlighting the crucial role of humans as the final line of defense.
An attack scenario is followed from start to finish, the training focuses on the need for changing our methods of detection and response as attack methods change.
Discover how to respond when a cyber-attack occurs, including deploying technologies to restore operations and fix underlying issues. This module highlights the use of AI tools to enhance threat detection, malware analysis, incident response, and vulnerability management.
Explore cloud environments, their respective security concerns, and best practices for secure deployments while examining the security advantages to cloud environments.
Reviews each of the Open Web Application Security Project (OWASP) top vulnerabilities and how security practitioners can prevent and/or mitigate issues in each category.
Examine real-world supply chain attacks to understand their causes and how to prevent or mitigate them. This module emphasizes learning from past incidents to strengthen defenses against future threats.