SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsKey takeaways:
The paper's central argument is that sustainable detection engineering depends on making change safe, quality measurable, and decay visible — not on writing more rules or chasing a perfect coverage score. As SIEM platforms absorb more of the testing, observability, and governance burden, detection teams can shift their effort from infrastructure plumbing toward threat-informed research and high-fidelity analytics, using shared patterns rather than shared, ready-made detections to compound learning across the industry. The analysis draws on the authors' hands-on experience in purple teaming, detection engineering, and SOC operations, and was published as part of SANS's Research Program with sponsorship from Splunk, a Cisco company.
Join SANS Senior Instructor Erik Van Buggenhout, Splunk’s Director of Product Management Tim Nary, and NVISO Detection Engineering SME Stamatis Chatzimangou as they explore effective detection engineering.

Failure is rarely about skill — it happens because detection content is treated as a static configuration rather than a living capability, so detections silently decay as environments, telemetry, and adversary behavior change over time.
DaC applies software engineering discipline — version control, peer review, and CI/CD — to detection content, but it adds engineering overhead, requires software and CI/CD skills many detection teams lack, and doesn't by itself solve whether telemetry is sufficient or alerts are actionable.
An alert can trigger exactly as designed and still lack the identity, business, or technical context — such as user privilege level or process history — needed to turn it into an actionable decision.
Not fully. Sigma provides a shared, structured way to express detection intent across teams, but it operates at a lowest-common-denominator level and still requires real engineering effort to translate into a production-grade detection in languages like SPL or KQL.
No. ATT&CK coverage scores are a useful directional signal for prioritization, but absolute coverage isn't measurable or achievable, and detection effectiveness is ultimately proven through testing, signal quality, and sustained performance rather than a coverage percentage.


Train with Erik Van Buggenhout, SANS instructor and NVISO co-founder, and develop hands-on skills in purple teaming, adversary emulation, and detection engineering to continuously improve detection, response, and real-world cyber defense.
Learn more

Stamatis is a detection engineering subject matter expert with over a decade of hands-on experience in cybersecurity operations. He has worked with multiple MSSPs, defending environments in the EMEA region in roles ranging from L1–L3 SOC Analyst to SOC Engineer and Detection Engineer.
Learn more















