genai
SECURITY LAB
DocsGetting startedLearning paths

Learning paths

Guided routes through the material — a concept video, the key principles, then hands-on labs, in one progression you can follow start to finish.

genaisecuritylab.com/learning-path
Learning paths: guided routes through each domain, filterable by track, level, and your own progress.
Learning paths: guided routes through each domain, filterable by track, level, and your own progress.

What a learning path is

A learning path is a guided route through one topic, start to finish. Instead of picking labs one at a time from the catalogue, you follow a path that weaves a concept video, the key principles in writing, and hands-on labs against a live target into a single progression — each step setting up the one after it.

There are 25 published paths today, with more added as new techniques and vulnerability classes emerge. You'll find them under Learning Paths in the sidebar once you're signed in.

Paths are made of labsEvery path is built from the same live, seeded targets you'd meet in the catalogue — a path just orders them and wraps each one in the context that explains why it matters.

Start here

If you're new, begin with Foundations of GenAI Security — the one path flagged “Start here.” In about an hour, across seven short modules, it builds the map of the territory: the trust-model shift that makes LLM security different, just enough of how models work, and where every OWASP LLM Top 10 risk actually lives. It's the shared entry to both the attack and defence tracks, so nothing later assumes something you skipped.

Already comfortable with the basics? Jump straight to a topic path like LLM01: Prompt Injection, and come back to Foundations only if a concept doesn't land. The list is ordered for learning by default — each topic sets up the next — but you can switch it to plain OWASP number order whenever you'd rather browse by the list you already know.

Inside a module

genaisecuritylab.com/learning-path/prompt-injection
Inside a path: an overview with a concept video and key principles, then numbered lessons full of live-target labs.
Inside a path: an overview with a concept video and key principles, then numbered lessons full of live-target labs.

Open a path and it breaks into an overview plus a handful of numbered lessons. The overview sets the scene — a short concept video, the key principles, a breach replay, and a quick knowledge check — and then each lesson drops you into real labs on the topic it just taught.

Take LLM01: Prompt Injection: eight lessons walk from direct overrides through jailbreaks, encoding, hidden-text smuggling, and indirect injection, all the way to the controls that actually hold — 29 labs in all. You watch, you read, then you attack a live target and prove you can do it yourself. Grading works exactly as it does anywhere else on the platform; see how grading works.

Tracks and domains

Every path sits on one of two tracks. Attack paths teach you to find and exploit a flaw; Defence paths teach you to design it out and prove the fix holds. Most topics have both, so you can attack LLM01, then take the LLM01 defence path to close it properly — the same attack, defend, verify loop, spread across a whole topic.

Paths are grouped by domain so you can go deep where it matters:

DomainWhat it covers
FoundationsThe shared groundwork for everything else.
OWASP LLM Top 10A path per risk, attack and defence, across the full list.
Agentic AI SecurityAttacks on systems where a model plans, remembers, and acts on its own.
MCP Server SecurityThe trust boundary an MCP server brokers, and how to hold it.

Each path also carries a difficulty — Foundational, Beginner, Intermediate, or Advanced — and the filter rail lets you narrow the list by domain, track, level, or your own status. For the full taxonomy, including the separate Agentic (ASI) and MCP top-ten lists, see the OWASP mapping.

Your progress

Progress saves automatically as you go — there's nothing to submit to “save” a path. Every path shows one of three states: not started, in progress, or completed, and the list tells you how many modules you've finished overall.

Pick up exactly where you left off from the Resume path button on your dashboard, or straight from the path list. Your dashboard also rolls path work up into OWASP coverage, so you can see which categories you've actually practised and which are still blank.

What's free

Three complete paths are open on the free tier: Foundations of GenAI Security, and both the attack and defence paths for LLM01 Prompt Injection — enough to feel the whole rhythm of a path before you commit.

Every other path is part of the paid catalogue. A path you can't open yet shows a padlock, and clicking it explains exactly what unlocks it. Both Individual and Team open every path.

Was this page helpful?
Previous
Your first lab