Course Information
Course Overview
Become professional in AI and LLM Penetration Testing and Vulnerability Discovery (Lite Version!)
THIS COURSE IS NO LONGER MAINTAINED. PLEASE CHOOSE MY ULTIMATE AI/LLM/ML Penetration Testing Training Course instead!!!
Ethical Hacking against and with AI/LLM/ML Training Course (Lite Version!)
Welcome to this course of Ethical Hacking and Penetration Testing Artificial Intelligence (AI) and Large Language Models (LLM) Training course.
Important note: This course is NOT teaching the actual usage of Burp Suite and its features.
Your instructor is Martin Voelk. He is a Cyber Security veteran with 25 years of experience. Martin holds some of the highest certification incl. CISSP, OSCP, OSWP, Portswigger BSCP, CCIE, PCI ISA and PCIP. He works as a consultant for a big tech company and engages in Bug Bounty programs where he found thousands of critical and high vulnerabilities.
This course has a both theory and practical lab sections with a focus on finding and exploiting vulnerabilities in AI and LLM systems and applications. The training is aligned with the OWASP Top 10 LLM vulnerability classes. Martin is solving all the LLM labs from Portswigger in addition to a lot of other labs and showcases. The videos are easy to follow along and replicate. There is also a dedicate section on how to use AI for Penetration Testing / Bug Bounty Hunting and Ethical Hacking.
The course features the following:
· AI/LLM Introduction
· AI/LLM Attacks
· AI/LLM Frameworks / writeups
· AI LLM01: Prompt Injection
· AI LLM02: Insecure Output Handling
· AI LLM03: Training Data Poisoning
· AI LLM04: Denial of Service
· AI LLM05: Supply Chain
· AI LLM06: Permission Issues
· AI LLM07: Data Leakage
· AI LLM08: Excessive Agency
· AI LLM09: Overreliance
· AI LLM10: Insecure Plugins
· Threat Model
· Putting it all together
· Using AI for Penetration Testing / Ethical Hacking
· The Yolo AI Tool
· Prompt Airlines CTF Walkthrough
· AI Prompt Attack and Defense Game Tensortrust
· Tooling
Notes & Disclaimer
Portswigger labs are a public and a free service from Portswigger for anyone to use to sharpen their skills. All you need is to sign up for a free account. I will update this course with new labs as they are published. I will to respond to questions in a reasonable time frame. Learning Pen Testing / Bug Bounty Hunting is a lengthy process, so please don’t feel frustrated if you don’t find a bug right away. Try to use Google, read Hacker One reports and research each feature in-depth. This course is for educational purposes only. This information is not to be used for malicious exploitation and must only be used on targets you have permission to attack.
Course Content
- 20 section(s)
- 39 lecture(s)
- Section 1 Agenda
- Section 2 Introduction to AI
- Section 3 AI/LLM Attacks
- Section 4 AI/LLM Frameworks / write ups
- Section 5 AI LLM01: Prompt Injection
- Section 6 AI LLM02: Insecure Output Handling
- Section 7 AI LLM03: Training Data Poisoning
- Section 8 AI LLM04: Denial of Service
- Section 9 AI LLM05: Supply Chain
- Section 10 AI LLM06: Permission Issues
- Section 11 AI LLM07: Data Leakage
- Section 12 AI LLM08: Excessive Agency
- Section 13 AI LLM09: Overreliance
- Section 14 AI LLM10: Insecure Plugins
- Section 15 Threat Model
- Section 16 Using AI for Penetration Testing / Ethical Hacking
- Section 17 The Yolo AI Tool
- Section 18 Prompt Airlines CTF Walkthrough
- Section 19 AI Prompt Attack and Defense Game Tensortrust
- Section 20 Tooling
What You’ll Learn
- AI/LLM vulnerabilities, get to a professional level in AI/LLM penetration testing, get to a professional level in AI/LLM bug bounty, Basics of AI/LLM, AI/LLM Attacks, AI/LLM Frameworks, AI/LLM Prompt Injection, AI/LLM Insecure Output Handling, AI/LLM Training Data Poisoning, AI/LLM Denial of Service, AI/LLM Supply Chain, AI/LLM Permission Issues, AI/LLM Data Leakage, AI/LLM Excessive Agency, AI/LLM Overreliance, AI/LLM Insecure Plugins, AI/LLM Threat Model, Using AI for Penetration Testing / Ethical Hacking, The Yolo AI Tool
Skills covered in this course
Reviews
-
MManju Shahu
It could be better more. There were more theory than practical. The examples were taken from embracethered site, but only theory.
-
JJohn Ilboudo
Well defined course and good explanation
-
MM Karupa Swamy
good
-
RRobin Shakya
excellent