SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Security operations are crossing a threshold. For a decade we automated the SOC with playbooks and SOAR. Now we are delegating to it: AI agents that triage alerts, enrich intelligence, hunt threats, and take response actions with growing autonomy. That shift breaks assumptions our security architectures were built on. Agents spawn sub-agents, hold credentials ephemerally, delegate trust across elongating chains, and can have their intent hijacked through prompt injection without a single credential being stolen. Zero Trust gave us the right principles; agentic AI is stress-testing how we implement them.
In this session, Ismael Valenzuela, author of SANS SEC530: Defensible Security Architecture and Engineering, applies his Think Red, Act Blue approach to both sides of the agentic SOC. Thinking red: how adversaries are weaponizing autonomous agents and hijacking the ones you deploy. Acting blue: how to build a defensible architecture for agentic AI, from identity for non-human principals and least privilege at the tool layer to policy enforcement at the AI gateway and blast radius containment.
Attendees will leave with a practical threat model for agentic workflows, Zero Trust design patterns mapped to the OWASP Agentic Top 10, and a realistic roadmap for introducing agent autonomy without losing governance, auditability, or human accountability.


Ismael is a Senior SANS Instructor and Arctic Wolf VP. Author of SEC530 and a prestigious GSE-certified expert, he blends decades of SOC, threat research, and community contributions to equip defenders with resilient, adversary-aware strategies.
Read more about Ismael Valenzuela