SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsKey findings:
The paper argues that alert volume and attacker speed have outpaced what human-only SOC teams can realistically absorb, and that the gap is a math problem as much as a talent problem. Rather than treating AI as a replacement for analysts, the paper frames the highest-performing model as one where AI handles investigation at machine speed while analysts retain authority over decisions, validation, and context. It positions this hybrid approach, illustrated through the TandemTrace platform, as an emerging standard rather than a niche tool, while noting that fully human SOCs may still suit highly regulated environments or very small organizations. The paper's data draws on the SANS 2025 SOC Survey, CrowdStrike threat reporting, and published human-AI teaming research, alongside the author's own analysis of alert-volume economics and SOC workflow timing.
In this SANS webcast, Mathias Fuchs examines whether human-only security operations can realistically keep up in an era of AI-enabled attacks, shrinking budgets, and a widening cybersecurity workforce gap.

A mid-sized organization receiving 4,500 alerts daily would need nearly 94 full-time analysts working without breaks to give each alert just 10 minutes of attention, according to SANS.
Nearly half of all alerts go completely uninvestigated in many organizations, and two-thirds of SOC teams say they cannot keep pace with alert volume, per the SANS 2025 SOC Survey.
CrowdStrike puts average attacker breakout time at 48 minutes, while traditional SOC workflows measure response in hours or days, according to the SANS paper "AI-Human Collaboration in Modern SOCs."
Yes. Research on human-AI teaming cited in the paper found hybrid teams outperform both pure-human and pure-AI approaches by roughly 25%.
No. The paper argues AI shifts analysts from mechanical alert processing to judgment-based work — validating conclusions and providing contextual and ethical oversight that AI systems lack.


"Renaissance man" may be the most fitting description of SANS instructor Mathias Fuchs, who is the Head of Investigation & Intelligence at the Swiss firm InfoGuard AG as well as a volunteer paramedic and a pilot.
Read more about Mathias Fuchs




















