SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsEvidenceForge is an open-source project for creating realistic synthetic digital forensics and incident response (DFIR) datasets for testing, training, and threat hunting practice. You describe the malicious activity you want to simulate, from a simple phishing intrusion to a full multi-stage attack chain, and AI-assisted scenario authoring helps turn that story into a structured, reproducible plan. EvidenceForge then renders the scenario from a single canonical event model, producing causally ordered evidence across 20+ Windows, Linux, network, and EDR log formats. The result is a coherent investigation package with realistic background noise, cross-source correlations, ground truth documentation, and an analyst briefing.
EvidenceForge is not trying to create synthetic data that is indistinguishable from production in every detail. Its goal is practical fidelity: datasets realistic enough to exercise tools, teach analysts, and support repeatable research without needing access to sensitive real-world telemetry.


David has 20+ years of experience in the information security field, primarily in incident detection and response, threat hunting, and Cyber Threat Intelligence. He is the creator the Pyramid of Pain and the Threat Hunting Maturity Model.
Read more about David Bianco














