gourses

← Volver a la búsqueda

The Ultimate AI/LLM/ML Penetration Testing Training Course

udemy · IT y software · ⭐ 4.54 (1.652 reseñas) · All Levels · en · ⏱ 40,5 h

Impartido por Martin Voelk · 20.678 alumnos

79.99 USD

Entra en tu cuenta para guardar este curso y volver a él cuando quieras.

Comparar este curso
Ver curso en udemy

Enlace de afiliado: podemos cobrar comisión, sin coste extra para ti. Más información

Descripción

The Ultimate AI/LLM/ML Penetration Testing Course Your instructor is Martin Voelk. He is a Cyber Security veteran with 26 years of experience. Martin holds some of the highest certification incl. AIRTP+, a dozen SecOps Certs incl. the AI Certifications, CISSP, OSCP, OSWP, Portswigger BSCP and Cisco CCIE. He works for a startup company and engages in Bug Bounty programs where he found thousands of critical and high vulnerabilities. This course has a both theory and practical lab sections with a focus on finding and exploiting vulnerabilities in AI and LLM systems and applications. The training is aligned with the OWASP Top 10 LLM as well as the OWASP Top 10 Agentic vulnerability classes. The videos are easy to follow along and replicate. The course features the following: · Prompt Injection · Prompt Injection (Indirect) · Prompt Injection (Agentic Actions) · Prompt Injection (Data Exfiltration) · Prompt Injection (Memory Manipulation) · Prompt Injection (Hidden and Obfuscated) · Sensitive Information Disclosure · Supply Chain · Data and Model Poisoning · Improper Output Handling · Excessive Agency · System Prompt Leakage · Vector and Embedding Weaknesses · Misinformation · Unbounded Consumption and DoS · OWASP PwnzzAI Shop (OWASP Top 10 LLM Labs) · OWASP Top 10 for Agentic Applications · OWASP Finbot (OWASP Top 10 for Agentic Applications Labs) · Portswigger - Agentic AI Labs · SecOps Group AI/ML Mock Exams 1 & 2 Walkthrough · SecOps Group Agentic AI Mock Exam Walkthrough · Jailbreaking · AI Browsers Attacks · AI Coding Agents Attacks · MCP Attacks · Multimodal Attacks (Images, Audio and Video) · Tooling · Prompt Airlines CTF Challenge Walkthrough · Selara Jailbreak Game CTF · Gandalf Agent Breaker CTF · Hack The Agent CTF · AI Prompt Attack and Defense Game Tensortrust CTF · Crowdstrike AI Unlocked Challenge CTF · Game Arena Challenges CTF · PromptTrace Prompt Injection Labs CTF · PromptInjects CTF · 8ksec CTF · AIPWN CTF · Bot Tricks CTF · Wraith CTF · Other CTFs · OWASP Finbot CTF (old) · Old legacy Gandalf lab Notes & Disclaimer I keep this course current, but it will not always reflect every new AI vulnerability or exploit as soon as it appears. Some students asked me to remove older CTFs. Others asked me to keep them because many of the techniques still apply to live AI systems and LLMs. I moved all CTF walkthroughs after the Tooling section. They are optional. Watch all of them, some of them, or none. I left them in so beginners can work through as many as they want. Most labs are free and available online. I do not control whether the owners take them down. Even if a lab disappears, the methods, techniques, and methodologies still apply, and you can use them on the labs that remain. LLM providers update their models often. Many of these techniques still work. Some may stop working later or may need extra tuning. Keep that in mind as you practice. Do not use this material for unauthorized or malicious attacks. Use it only on systems you own or have explicit permission to test.

Lo que aprenderás

  • AI/LLM/ML vulnerabilities
  • LLM01: Prompt Injection
  • LLM01: Prompt Injection (Indirect)
  • LLM01: Prompt Injection (Agentic Actions)
  • LLM01: Prompt Injection (Data Exfiltration)
  • LLM01: Prompt Injection (Memory Manipulation)
  • LLM01: Prompt Injection (Hidden and Obfuscated)
  • LLM02: Sensitive Information Disclosure
  • LLM03: Supply Chain
  • LLM04: Data and Model Poisoning
  • LLM05: Improper Output Handling
  • LLM06: Excessive Agency
  • LLM07: System Prompt Leakage
  • LLM08: Vector and Embedding Weaknesses
  • LLM09: Misinformation
  • LLM10: Unbounded Consumption
  • ASI01 - Agent Goal Hijack
  • ASI02 - Tool Misuse and Exploitation
  • ASI03 - Identity and Privilege Abuse
  • ASI04 - Agentic Supply Chain Vulnerabilities
  • ASI05 - Unexpected Code Execution / RCE
  • ASI06 - Memory and Context Poisoning
  • ASI07 - Insecure Inter-Agent Communication
  • ASI08 - Cascading Failures
  • ASI09 - Human-Agent Trust Exploitation
  • ASI10 - Rogue Agents
  • All Portswigger AI and Agentic AI Labs Walkthrough
  • SecOps Group AI/LLM Pentester and Agentic Pentester Mock Labs Walkthrough
  • Jailbreaking
  • AI Browsers Attacks
  • AI Coding Agents Attacks
  • MCP Attacks
  • Multimodal Attacks
  • Tooling
  • Hundreds of AI CTF Walkthroughs
  • Find and exploit AI/LLM/ML vulnerabilities
  • Penetration Testing
  • Bug Bounty Hunting

Requisitos

  • Basic IT Skills
  • Basic understanding of web technology
  • No Linux, programming or hacking knowledge required
  • Computer with a minimum of 4GB ram/memory
  • Operating System: Windows / Apple Mac OS / Linux
  • Reliable internet connection
  • Any Webbrowser