SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Case Scenario Overview:
An international consulting firm detects suspicious outbound traffic from a financial analyst’s workstation. Initial alerting suggests unauthorized access to internal document repositories. As the investigation begins, incident response uncovers signs of a coordinated intrusion campaign affecting multiple hosts across the network.
Over the course of this instructor-guided simulation, attendees will step into the role of a response team working through a multi-phase intrusion. The case begins with initial access via a malicious backdoor, escalates to persistence and credential abuse, and culminates in lateral movement and data exfiltration.
Analysts will be given evidence files and access to all affected systems, and they’ll work to reconstruct the full attack chain, identify compromised accounts, and map the attacker’s path across the enterprise.
Learning Objectives:
By the end of this simulation, attendees will be able to:


Carlos Cajigas is a digital forensics and incident response (DFIR) professional with more than two decades of experience spanning both law enforcement and the private sector.
Read more about Carlos Cajigas