SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsKey findings:
The guide's central framing is that AI accelerates the mapping and hypothesis-generation stages of source code review, but verification and exploitation confirmation remain squarely human responsibilities. Skipping steps in the five-step loop, or accepting AI findings without file:line-level reproduction, produces results that won't survive exploitation attempts or report review. Methodology: This is a course-affiliated field guide rather than a research survey; it distills workflow guidance developed for SANS SEC543 rather than empirical study findings.
The five steps are Map (inventory entry points, auth boundaries, and data flows), Slice (pull a dependency-complete code fragment), Interrogate (ask adversarial questions), Verify (reproduce findings by hand), and Exploit (chain validated findings into working attacks).
Because AI-claimed findings can be confidently stated but unreproducible, which damages both the assessment and the reviewer's credibility; the guide requires each finding to be manually reproduced before it's trusted.
Four things: written permission to send client source to a third-party model, internal data classification and acceptable use policy, the provider's data retention practices, and — if any of that is unclear — defaulting to a local model or zero-retention enterprise tenant.
Adversarial framing produces findings, while descriptive framing tends to produce rewrites of the existing code rather than new vulnerability discoveries.
Treat it as contaminating the entire session — the guide recommends resetting rather than continuing, since one fabricated finding can undermine confidence in everything else the model reported in that session.


Joshua Wright, Senior Technical Director at Counter Hack Challenges and author of SEC504, has spent over two decades teaching and building tools that help defenders identify and counter real-world cyber threats through practical, hands-on learning.
Read more about Joshua Wright




















