SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Precision attacks on industrial processes used to require years of hands-on experience. That barrier protected many operators. It is now gone.
An attacker no longer needs to understand your process. They need your configuration files and a production AI tool. Logic exports, address maps, HMI project files, and vendor manuals are enough. The AI reads the logic, infers the physics, and maps dependencies between systems. It then produces ranked attack paths with protocol-level steps to execute them.
This talk demonstrates the technique on a real PLC. Don C. Weber will show what the AI produced, what it got right, and what it cost. The answer is about one analyst workday and a few dollars in API fees.
Attendees will learn why configuration files must be protected like safety documentation. They will see why engineering workstations and their remote access deserve the same scrutiny as production systems. They will leave with practical steps to adjust OT security priorities now, because this technique should be assumed to be in use today.


A visionary OT security leader, SANS Principal Instructor, and USMC veteran, Don co-authored ICS613 and teaches ICS410. He translates years of frontline experience into safer, practical methods to empower defenders protecting critical infrastructure.
Read more about Don C. Weber