SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Australian organisations face a changing threat landscape, with phishing, compromised accounts and identity information gathering among the most frequently observed techniques reported by the Australian Signals Directorate. State-sponsored actors are also using “living off the land” techniques to blend malicious activity with legitimate network behaviour, making attacks more difficult to detect.
Traditional penetration testing can identify technical vulnerabilities, but it does not always show how effectively an organisation’s people, processes and technology can detect and respond to a realistic attack.
In this webcast, SEC565 co-author David Mayer will explore how organisations can use publicly available threat intelligence to identify relevant adversary behaviours, map tactics, techniques and procedures to MITRE ATT&CK, and develop an adversary-emulation plan that reflects the threats they are most likely to face. He will also explain how this approach can help organisations assess their detection and response capabilities and turn the findings into practical defensive improvements.


David “Dave” Mayer is CIO and Managing Director of Advanced Assessments at Neuvik , and a SANS Certified Instructor. Co-author of SEC565, he brings deep red team, penetration testing, and adversary emulation.
Read more about David Mayer