SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Give a new hire root access on day one, no training, no oversight, and call it efficiency. Nobody would sign off on that. But that's effectively what a growing number of cloud environments are doing with agentic AI — autonomous, tool-using systems that plan and execute multi-step actions, often with the same standing privilege as the humans they're assisting. Prompt-engineering skills won't catch this. The risk isn't in what the AI says anymore. It's in what it does.
A SANS survey this year found 74% of organizations already run AI agents that require their own credentials. 92% don't rotate those credentials on even a 90-day cycle. In September 2025, that gap turned real: a state-sponsored group got a coding agent to run 80-90% of a cyber-espionage campaign on its own — reconnaissance, exploitation, lateral movement, data theft — while a human just reviewed the output.
This talk teaches the practitioner path from where most of us started: prompting an assistant for a faster answer. Then it walks through what changes once that assistant can act — what an agent SDK hands a piece of software by default, how AWS, Azure, and Google Cloud are building guardrails and telemetry to contain it, and which attack techniques are already being used against exactly this kind of deployment in production: MCP tool poisoning, agent-to-agent trust abuse, memory poisoning. Every comparison here was checked against real cloud guardrail configurations, not vendor documentation alone. You'll leave with a plain way to size how much autonomy a given agent deployment should actually have, and a framework for explaining that tradeoff to whoever signs off on it. You'll also get the specific attack techniques worth testing first, mapped to the native guardrails in AWS, Azure, and Google Cloud that catch them — plus the telemetry signal that flags an agent going off-script before it becomes an incident.


Terrence Williams is a SANS Certified Instructor and Security Engineer, Investigations at Meta, with deep expertise in cloud security, digital forensics, and incident response.
Read more about Terrence Williams