genai
SECURITY LAB
About

Built by a practitioner, not a course company.

Every lab in GenAI Security Lab is written by Aditya Agrawal — creator of PentestBox and AppSecWiki, with 800+ client pentests behind him. Each one is built from the way these attacks run on real engagements, then calibrated against a live model until a genuine exploit works and a lucky guess doesn't.

He built this because the training and deep labs for each attack category didn't exist. Scope requests for LLM and agentic systems were arriving faster than anyone could train for them — so he built the proving ground he kept wishing for.

HackerOne bug-bounty Top-100·2014·2015·2016·2017Top Cobalt Core pentester · 2020
Aditya Agrawal, founder of GenAI Security Lab
Aditya Agrawal · Founder
The record

More than a decade in security.

In two acts — each line below links to where you can verify it.

2014–2017 · Research & open source

Independent bug-bounty research plus the open-source tools below — PentestBox, AppSecWiki, Appie and a mobile-security series. The four HackerOne global reputation Top-100 finishes in the chips above are from this period.

2018–present · Consulting & pentesting

Offensive-security consulting — eight years at NotSoSecure (part of the Claranet Group), principal consultant by 2021 — before leaving that full-time role in 2026 to build GenAI Security Lab, with freelance pentest work for Cobalt and as a HackerOne-approved pentester on the side.

The throughline

Same problem, new domain.

The same thing, over and over: a hole in security tooling that nobody was filling. GenAI Security Lab is the fifth time.

The gapWhat he built

Practical, hands-on Android app-security material was hard to find.

Android security toolkits all assumed Linux.

Appie2015

No complete Windows-native pentesting environment existed.

Web and mobile app-security knowledge was scattered across a hundred bookmarks.

AI security had no deep, hands-on labs.

GenAI Security Lab2026 Now
The labs

Graded on the exploit, not the essay.

Most AI security training stops at prompt injection. GenAI Security Lab runs the full OWASP Top 10 for LLMs and for Agentic AI — a hands-on lab for every class, scored on what actually happened in the session rather than on what you wrote afterwards. The Breach Replay track reconstructs documented AI security failures.

There's no content team — every lab is written, run end-to-end, and maintained by Aditya.

No XP. No streaks. No leaderboards. No badges dressed up as progress. You're here to learn a skill, not watch a number go up.

See what a real lab feels like.

The record above is history; the lab is the current work. Talk a support bot into approving a refund it was told to deny — a few minutes, the free tier covers it, and you'll know.

GenAI Security Lab is built and run by Aditya Agrawal.