You'll exploit real vulnerabilities in LLM apps, RAG retrieval pipelines, MCP tool servers, and autonomous agents — then implement the mitigation and prove it holds.
Start free: 15 community labs, no card. After that, $39/mo for individuals or $59/seat/mo for teams, billed yearly.
Curriculum aligned and mapped to OWASP LLM Top 10 2026 · OWASP Agentic AI Top 10 2026 · OWASP MCP Top 10 2025 · NIST AI RMF · MITRE ATLAS · ISO/IEC 42001.Mapped to these frameworks, not endorsed by them.
For pentesters and security engineers picking up AI security hands-on. Work through live targets at your own pace, then prove your fix holds.
Give your security engineers and developers one shared, hands-on path. Assign labs, see who's ready, and export evidence for your auditors.
Every lab sits behind a full teaching module — not a README. Concept video, annotated diagrams, the principles that actually hold, and a knowledge check, so you understand the mechanism before you exploit it.
Two paths per topic: an offensive path for pentesters and a defensive path for developers shipping AI features.
Filmed for this module — not a recorded webinar.
The mechanism as a diagram — you see exactly where the trust boundary breaks.
The handful of rules that decide whether a control holds.
Make sure the mechanism landed before you touch a live target.
Reusable attack payloads and the secure patterns that defeat them.
A checklist to run against the AI features you ship.
Assign labs, inspect graded results by engineer, and export coverage you can hand to your CISO or an auditor.
Example data — not a real team.
Per-person OWASP coverage across the team
Push paths and track completion, no manual review
Every graded result is defensible and exportable
A credential per engineer, linked to the exploits they passed
Proctored assessments with a unique target and vulnerability per candidate, graded on the evidence they produce.
Send a role-calibrated, proctored assessment against live AI targets and get a verifiable competency report — not a résumé claim.
Every lab runs the same graded loop against a live target — not a flag to google.
Exploit a live target — override a support bot, poison a RAG index, hijack an agent loop — and capture proof.
Implement a real mitigation: sanitize input, anchor instructions, filter output, add retrieval guardrails.
Confirm the fix actually holds under the original attack and its variants — not just that it looks right.
The catalogue is mapped to OWASP’s three GenAI security lists — the LLM Top 10, the Agentic (ASI) Top 10, and the MCP Top 10. Many labs span more than one category.
15 community labs free, no card. Or book a walkthrough of the admin console and competency reporting.