ᚠ ᚢ ᚦ ᚨ ᚱ ᚲ  ᚷ ᚹ ᚺ ᚾ ᛁ ᛃ  ᛈ ᛇ ᛉ ᛊ ᛏ ᛒ
The watchtower of the nine realms

Guard every realm.
Wield the machine.

NorseStar Security is where defenders learn to build and command autonomous offensive agents. A mythic threat-intel house — and the living home of SANS SEC590.

What we watch

Three bridges into the enterprise

The attack surface the course teaches you to assess — and the realms NorseStar's fictional telemetry pretends to defend.

ᚨ

Outside-in recon

Map the exposed edge the way an autonomous agent would — before it strikes.

ᚱ

AI as attack surface

Chatbots, gateways, model registries. The new soft underbelly of the stack.

ᛊ

Supply chain

From a prompt to a pull request to a poisoned build. The long game.

The Course

SEC590

Five days, fifty-fifty lecture and labs. Students enter knowing little about AI and leave building custom pentest agents and supervising autonomous operations.

PA
Pedram Amini
Author · Day 1
AW
Adrian Wood
Author · Day 2
Day 1Attack surfaces for AI pentesting
Day 2AI pentest harnesses
Day 3Getting it right — trust & false findings
Day 4Autonomous operations
Day 5Supervise & govern
Resources · kept current

The AI Pentest Tool Index

A curated inventory of the open-source AI offensive landscape, drawn from the SEC590 research pipeline.

Auto-synced weekly · last update Mon
ToolCategoryStarsΔ 7dType
HexStrike-AIMCP · 150+ tools8.9k+412Orchestrator
StrixAutonomous · web6.1k+288Agent
PentestGPTGuided assistant9.4k+77Assistant
CAIFramework · REPL3.7k+154Framework