SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
OWASP offers much more than a single Top 10 list, and this talk turns that ecosystem into a live pentest workflow. The session starts with the OWASP project map, Top 10 families, Cheat Sheets, and training applications like Juice Shop, FinBot, and PyGoat. From there, the demo moves through recon with Amass compared to dnsrecon and fierce, vulnerability scanning with OWTF and Nettacker, Burp Suite scanning driven through MCP and Codex, scan data import into DefectDojo, and AI-assisted report writing. The result is a compressed but recognizable pentest arc that showcases both OWASP resources and modern AI-enabled operator workflows.
This session supports concepts from SEC542: Web App Penetration Testing and Ethical Hacking. To learn more about this course and explore upcoming sessions, Click Here.


Timothy McKenzie is a SANS Principal Instructor, founder of 3L337 Consulting, SEC542 co-author, and SEC588 instructor. His courses draw on more than 30 years of experience in Red Team operations, web application security, cloud penetration testing, and adversary emulation.
Read more about Timothy McKenzie