Advanced · Security engineers, red teams, AppSec
AI Security & Red Teaming
The threat model for AI products is nothing like classic web security, and red teams trained on the OWASP Top 10 routinely miss the important holes. This course is a hands-on walkthrough of prompt injection, data exfiltration, tool abuse, and the defensive patterns that actually contain them.
2h 30m
Verifiable certificate
25 languages
4 modules · 29 lessons
€29
/ seat
Find the prompt-injection holes before your customers do.
Hands-on labs
OWASP LLM Top 10
Defensive patterns
Includes 12 months access, certificate, and evidence trail. Cancel any time before your learner starts.
What you'll learn
Three concrete things every learner walks out with.
01
Enumerate the threat model for an LLM, agent, or RAG product.
02
Execute prompt-injection, exfiltration, and tool-abuse attacks in a lab.
03
Design layered defenses and an eval-driven red-team loop.
Curriculum
A short course that respects your team's time.
4 modules · 29 lessons · 150 minutes. Designed to complete in a single working session or stretch across a week.
01
The LLM threat model
6 lessons · 30 min
+
01
The LLM threat model
6 lessons · 30 min
Why prompt injection is not XSS, and why tool-use expands the blast radius.
02
Prompt injection in the wild
8 lessons · 40 min
+
02
Prompt injection in the wild
8 lessons · 40 min
Direct, indirect, and multi-hop injection vectors, with case studies from shipped products.
03
Data exfiltration and tool abuse
7 lessons · 35 min
+
03
Data exfiltration and tool abuse
7 lessons · 35 min
How attackers turn benign integrations into exfil channels, and the scoping patterns that stop them.
04
Defensive architecture & red-team loops
8 lessons · 45 min
+
04
Defensive architecture & red-team loops
8 lessons · 45 min
Layered defenses, eval-driven regression, and the weekly cadence that keeps products honest.
Outcomes
What your team will be better at by next month.
A real AI threat model
Leave with a documented threat model tuned to your stack, not a generic checklist.
Findings you can actually fix
Prioritized, reproducible attack scenarios with suggested remediations per class.
A continuous red-team loop
A cadence that finds new holes as your product surface grows.
Verifiable certificate
Deterministic ID, third-party verifiable.
Evidence trail
Cited, timestamped, regulator-accepted.
25 languages
All 24 official EU languages plus English.
Private by default
Zero-retention mode, EU residency available.
More from the library
Pair it with something your team already asks for.
AI Security & Red Teaming
Ready to train your team on this one?
Start with a single seat and grow into a team bundle, same dashboard, same evidence trail, either way.