SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Join us for an exciting, hands-on exploration where we transform a humble chat completion script into a sophisticated, fully agentic AI system, all through a series of live, iterative demonstrations. We will demystify how they work by building an agentic system from the ground up. We'll kick off with a memory-less agent that does well with single questions but stumbles on conversational follow-ups. Watch as we add persistent message history, enabling coherent multi-turn dialogues. Next, we'll hit the wall of context limits when tackling file operations and large data, revealing why raw tool access isn't enough.
Through additions of tool-calling capabilities, we'll differentiate between built-in tools and configurable MCP services. Our agent will gain "hands" to act on the world, "eyes" to inspect complex data structures (databases, logs, packets, registries), and advanced memory architectures to manage its cognitive load. Culminating in a blueprint for agentic memory management, including adaptive system prompts, modular skill loading, planning modes, and compressible context, we'll demonstrate how these elements combine to create truly autonomous, efficient AI agents.
Note: This is a hands-on exercise and attendees are encouraged to bring their laptops.


SANS Faculty Fellow Mark Baggett authored SEC573 and SEC673, leads as CTO of the SANS Internet Storm Center, and empowers defenders to automate security through practical, real-world application.
Read more about Mark BaggettElevate your skills in the epicenter of U.S. policy and defense. This D.C. area event offers elite training, plus access to monuments, museums, and networking opportunities in a city that never stops.
