SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsEnterprise Network Security Monitoring (NSM) solutions generate massive volumes of traffic. However, most organizations cannot sustain full packet capture (PCAP) due to insufficient storage capacity, processing power, and administrative resources.
This limitation is increasingly relevant as modern threats demand deeper historical visibility to investigate incidents effectively. Current tactics rely on either full PCAP collection, which is expensive and difficult to scale, or network flow-based and metadata monitoring, which lacks forensic depth. Existing research focuses on the challenges of full PCAP storage, high-speed capture performance, and comparative effectiveness of Intrusion Detection Systems (IDSs). A review of the current feasibility of any assessment related to whether alert-driven selective PCAP retention can serve as a viable substitute for comprehensive packet capture within large enterprise or government environments.
The goal is to determine whether conditional, alert-driven PCAP can significantly reduce storage consumption while still preserving enough forensic evidence to support meaningful analysis.


















