Enter knowing little about AI. Leave a practitioner who builds custom pentest agents, orchestrates autonomous assessments, and supervises AI-driven operations — because you built the harness yourself.
Most "AI pentest" training teaches you to watch a tool work. SEC590 teaches you to build one. Over five days you move from driving AI by hand, to assembling an autonomous pentest harness, to telling real findings from confident fiction, to supervising and governing agents an enterprise can actually trust. The lab environment is NorseStar Security — a full fictional company you'll assess end to end.
A deliberate arc: do it by hand, automate it, validate it, supervise it, deploy it.
The attack surfaces AI changes, the model/inference/agent stack, and coding agents as pentest operators — driven by hand so you understand every call before you automate it.
Autonomy vs automation, the anatomy of a harness, the open-source and open-weight-model ecosystems, the commercial landscape, and the cost/token economics that decide what is actually runnable.
Why AI pentesting fails, the classes of AI-generated false vulnerabilities, trust boundaries, why exploitability is not a statistical property, and black-box exploit chaining.
Why supervising output is the wrong model, detecting reward hacking, human-interrupt models, adversarial testing of AI pentest systems, and defending against AI pentest agents.
Building an internal AI pentest program, designing systems humans can trust, the emerging AI-security-supervisor role, where the field is heading — and a capstone against the full NorseStar range.
Two practitioners who build this for a living.
A curated, weekly-refreshed inventory of the open-source AI offensive-security landscape — platform comparison, attack-surface coverage, and a governance-readiness matrix.