Learn to find and fix vulnerabilities in AI applications through guided, hands-on labs. Practice on deliberately vulnerable chatbots, retrieval (RAG) systems, and AI agents — then apply the mitigation and prove it holds.
Start learning free: 25 community labs, no card. After that, plans from $19/mo for individuals or $39/seat/mo for teams, both billed annually.
Limited time offer — 25% off everything · code LAUNCH25OFF · until 3rd October 2026
Curriculum aligned and mapped to OWASP LLM Top 10 2026 · OWASP Agentic AI Top 10 2026 · OWASP MCP Top 10 2025 · NIST AI RMF · MITRE ATLAS · ISO/IEC 42001.Mapped to these frameworks, not endorsed by them.
For pentesters adding AI to their scope and developers shipping AI features. Work through live targets at your own pace — find the vulnerability, apply the fix, and prove it holds.
Give your security engineers and developers one shared, hands-on path. Assign learning paths, track demonstrated skills, and export completion evidence for reviews and audits.
Every topic sits in a guided learning path — written lessons, concept videos, and the principles that actually hold — so you understand the mechanism before you exploit it.
Two paths per topic: an offensive path for pentesters and a defensive path for developers shipping AI features.
Filmed for this module — not a recorded webinar.
The mechanism as a diagram — you see exactly where the trust boundary breaks.
The handful of rules that decide whether a control holds.
Make sure the mechanism landed before you touch a live target.
Reusable attack payloads and the secure patterns that defeat them.
A checklist to run against the AI features you ship.
There was a clear need for AI-native sandboxed labs, and GenAI Security Lab meets that need well. The learning paths are structured and easy to follow, and the labs reflect realistic application scenarios we encounter in day-to-day work. Overall, this platform is an effective way to learn current LLM, agentic, and MCP vulnerabilities.
I really liked the learning experience and the clean, well-thought-out design. It made learning difficult concepts feel a lot easier and actually enjoyable.
GenAI Security Lab does a good job combining structured OWASP-based training with practical, scenario-driven labs and automated verification. What stands out is how it connects offensive techniques like MCP tool schema poisoning and cross-tool data exfiltration back to the actual vulnerable backend code, the root causes, and practical defenses — including code-level fixes and blast-radius containment. For pentesters, it helps you build more realistic test cases, trace the full attack chain, confirm the real security impact, and produce evidence-backed findings with clear, actionable remediation.
The portal is honestly impressive. What I liked most is that it actually covers the OWASP Top 10 for AI/LLM applications — something a lot of other platforms just skip. I also appreciated that the course looks at both the offensive and defensive sides of security. That makes it feel much more useful if you’re trying to build real, practical skills in AI/LLM security.
Assign labs, inspect graded results by engineer, and export coverage you can hand to your CISO or an auditor.
Example data — not a real team.
Per-person OWASP coverage across the team
Push paths and track completion, no manual review
Every graded result is defensible and exportable
A credential per engineer, linked to the exploits they passed
Every lab runs the same graded loop against a live target — not a flag to google.
Exploit a live target — override a support bot, poison a RAG index, hijack an agent loop — and capture proof.
Implement a real mitigation: sanitize input, anchor instructions, filter output, add retrieval guardrails.
Confirm the fix actually holds under the original attack and its variants — not just that it looks right.
The catalogue is mapped to OWASP’s three GenAI security lists — the LLM Top 10, the Agentic (ASI) Top 10, and the MCP Top 10. Many labs span more than one category.
More on plans, cancellation and refunds on the .
25 community labs free, no card. Or book a walkthrough of the admin console and competency reporting.