SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Threat hunting is becoming increasingly automated. But not every part of the process can — or should — be handed over to AI.
Using the PEAK framework and hypothesis-led hunting as the foundation, Jeroen breaks the hunting process down step by step, assessing where automation genuinely adds value and where it quietly introduces unreliable results. The session includes a live demonstration of an end-to-end hunting flow, showing the checkpoints you need to keep consistency and trust intact.
The final focus is the part that cannot be automated: defining the right hypothesis. As automation accelerates everything downstream, the real constraint shifts upstream — to human reasoning and decision-making.
Ideal for threat hunters, SOC analysts and team leads, detection engineers, and incident responders working out where AI belongs in their hunting programme.
Presented by Jeroen Hoof — Security Operations Specialist, Davinsi Labs | SANS Certified Instructor Candidate, SEC504


Train with Jeroen Hoof, SANS Certified Instructor Candidate and incident response specialist, to build hands-on skills in intrusion analysis, attacker mindset, detection engineering, and real-world incident handling.
Read more about Jeroen Hoof