genai
SECURITY LAB
For pentesters

AI is in your scope now

The scoping call mentions a chatbot, an agent with tool access, a RAG (retrieval-augmented generation) pipeline. You can test the web and cloud layer around it already — this closes the part that is new, on live targets rather than slideware.

Live models, not simulationsGraded on captured evidenceBuy it yourself — no employer needed

Buying for a practice or a team?

The gap

Your instincts transfer. Your techniques don't.

There is no payload list

Injection here is a persuasion problem, not a syntax one. The same request phrased two ways gets refused once and obeyed once.

The boundary is not where you expect

A prompt is not a parser. Trust breaks between retrieval and context, or between an agent and its tools — often in a different file.

Impact is hard to argue

“The model said something rude” is not a finding. Turning behaviour into demonstrated business impact is the skill clients pay for.

The report is different

Non-determinism means a client will re-run your payload and get a different answer. Evidence has to be captured, not described.

Coverage

Add LLM features, agents, and MCP servers to the systems you can test

Work every category in the OWASP LLM Top 10, then MCP (Model Context Protocol) tool servers and agentic systems, against deliberately vulnerable applications running live. Use the web, API and cloud judgement you already have to test prompt injection, retrieval boundaries, tool access, and agent behaviour.

genaisecuritylab.com/learn
Your scope, this year
Web appYou already test this
APIYou already test this
CloudYou already test this
LLM featuresNew in scope
Agents & toolsNew in scope
MCP serversNew in scope
Method

Five steps. Same order. Every engagement.

Same five steps whether the client ships a chatbot or an agent, so your second AI engagement does not start from scratch.

genaisecuritylab.com/methodology
AI pentest methodology
1
Scope
Map the AI surface: models, tools, retrieval, agents
2
Map
Trace where untrusted text reaches context
3
Test
Work the OWASP LLM Top 10 against each entry point
4
Verify
Re-run the payload against the proposed fix
5
Report
Evidence, impact, remediation the client can action

Then prove it with GSCP

GSCP — the GenAI Security Certified Professional — is proctored, hands-on, and graded on the exploits you capture and the report you write. Weighted 75% GenAI, 20% web, 5% cloud — which is what a modern engagement actually looks like. One credential, no tiers.

Paying for it yourself

You don't need an employer to sign off

Individual
$49/mo · $468 charged yearly

Every lab and the full curriculum. The GSCP sitting is $499 on its own, whenever you are ready.

Certification bundle
$646$549one-timeSave 15%

The GSCP exam plus three months of lab access to prepare. One free retake, then $99 per attempt. There's no attendance version of this credential — you pass it or you don't.

Break a live model before your next scoping call

The free tier is 15 labs against a live model, no card required.