This is the real course. NorseStar Security is the fictional cyber-range we built to teach it — SEC590 is a genuine SANS course by Pedram Amini & Adrian Wood.
SEC590SANS
SANS · Offensive Operations

SEC590
AI-Driven Penetration Testing

Enter knowing little about AI. Leave a practitioner who builds custom pentest agents, orchestrates autonomous assessments, and supervises AI-driven operations — because you built the harness yourself.

5 daysbuild → supervise
50 / 50lecture / hands-on labs
Build, don't observecourse philosophy

What this course is

Most "AI pentest" training teaches you to watch a tool work. SEC590 teaches you to build one. Over five days you move from driving AI by hand, to assembling an autonomous pentest harness, to telling real findings from confident fiction, to supervising and governing agents an enterprise can actually trust. The lab environment is NorseStar Security — a full fictional company you'll assess end to end.

Build, don't observeAutonomous harnessesAgent supervisionGovernance & auditabilityOpen-weight modelsCost & token economics

The five days

A deliberate arc: do it by hand, automate it, validate it, supervise it, deploy it.

  1. Day 1

    AI-Assisted Pentesting: The Manual Way

    The attack surfaces AI changes, the model/inference/agent stack, and coding agents as pentest operators — driven by hand so you understand every call before you automate it.

    Attack surfaces · the AI stack · coding agents · source & binary analysis · tool/function calling & skills
  2. Day 2

    AI Pentest Harnesses: What Exists and How They Work

    Autonomy vs automation, the anatomy of a harness, the open-source and open-weight-model ecosystems, the commercial landscape, and the cost/token economics that decide what is actually runnable.

    autonomy vs automation · harness anatomy · OSS ecosystem · open-weight models · design convergence · commercial landscape · token economics
  3. Day 3

    Getting It Right

    Why AI pentesting fails, the classes of AI-generated false vulnerabilities, trust boundaries, why exploitability is not a statistical property, and black-box exploit chaining.

    failure modes · false-vuln taxonomy · trust boundaries · exploitability ≠ probability · exploit chaining
  4. Day 4

    Supervision, Adversarial Testing & Governance

    Why supervising output is the wrong model, detecting reward hacking, human-interrupt models, adversarial testing of AI pentest systems, and defending against AI pentest agents.

    supervision models · reward hacking · human interrupts · adversarial testing · defending against agents
  5. Day 5

    Enterprise Deployment & Capstone

    Building an internal AI pentest program, designing systems humans can trust, the emerging AI-security-supervisor role, where the field is heading — and a capstone against the full NorseStar range.

    internal programs · trustworthy systems · the supervisor role · future trajectory · capstone

Your authors

Two practitioners who build this for a living.

PA

Pedram Amini

Author · Day 1

Security researcher and entrepreneur, co-founder of the Zero Day Initiative (ZDI) and co-author of Fuzzing: Brute Force Vulnerability Discovery. Founder of InQuest; creator of the PaiMei reverse-engineering framework and OpenRCE. His work spans vulnerability research, fuzzing, and reverse engineering — now focused on the security of AI systems and applying AI to offensive operations.

pedram@banaco.com
AW

Adrian Wood

Author · Day 2

Security engineer with 17+ years across red teaming, application security, exploit development, cloud security, and machine-learning security. Founder of the consultancy WHITEHACK, a frequent DEF CON and Black Hat speaker, a MITRE ATLAS contributor through his work on the offensive-ML wiki, and holder of multiple patents in malware detection and adversarial-AI defense.

“threlfall” · @threlfall.bsky.social
Resources · kept current

The AI Pentest Tool Index

A curated, weekly-refreshed inventory of the open-source AI offensive-security landscape — platform comparison, attack-surface coverage, and a governance-readiness matrix.

Open the index ▸