SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us

Key findings: • Only 51% of organizations formally measure the effectiveness of their threat hunting, down sharply from 64% in 2024 • Organizations fully outsourcing threat hunting dropped to 30%, down from 37% the prior year, while those managing it entirely in-house rose to 58% • 61% of respondents cite skilled staffing shortages as their primary barrier to threat hunting success • Cloud infrastructure is the single hardest environment to threat hunt in, cited by 39% of respondents, despite being a growing priority area • Ransomware detections through threat hunting fell from 63% to 46% year over year, while nation-state detections rose slightly to 41% • "Living off the land" (LOTL) techniques remain the most prevalent adversary tactic, appearing in 76% of nation-state attacks — unchanged from 2024 • The use of internally built threat-tracking tools rose to 48%, up from 33%, while reliance on commercial intelligence tools declined to 58% from 70% • EDR/XDR ranks as the most critical tool for threat hunting, followed by SIEM and network detection and response (NDR) • 76% of organizations now use vendor blogs and papers as a priority threat intelligence source, up from 59% the prior year • 48% of organizations are prioritizing AI and machine learning integration into their threat hunting tools to improve automation and detection accuracy The survey finds an industry in transition: organizations are pulling threat hunting capabilities in-house and investing in custom tooling, even as they struggle to formally measure whether their hunting programs are working. Cloud visibility remains the most persistent technical gap, and while AI adoption is a stated priority, its measurable impact on catching threat actors so far remains limited. The overall trend points to continued investment in threat hunting as a strategic priority despite budget and staffing constraints. Respondents were drawn primarily from the government, technology, cybersecurity, and banking and finance sectors, spanning organizations from under 1,000 employees to more than 50,000, with security administrators/analysts, SOC analysts, and security managers or directors making up the largest respondent roles.
Learn how to enhance your cloud security posture through actionable insights and use cases involving Microsoft Defender for Cloud.



Josh leads global MDR at Uptycs, defending major international brands, while also serving as an independent DFIR expert advising legal, government, and commercial clients in Australia.
Read more about Josh Lemon

















