AI Security and Red Teaming (Hacking with AI)
Published by Pearson
Hacking AI Applications, Agentic Systems, and AI Models
- Learn about the latest AI security research and tools.
- Explore cutting-edge AI algorithmic red teaming techniques and related tools.
- Gain expert insights into vulnerabilities in AI applications and agentic systems.
AI applications and agentic systems are everywhere. This intensive training session is taught by Omar Santos, a best-selling security author, speaker, and cybersecurity and AI expert. The training includes focused live discussions, real-world demonstrations, and insights into hacking AI systems from someone who has been on the front lines of AI security research.
You will learn how to hack AI applications, large language models (LLMs), MCP servers, and multi-agent systems. You will also learn how to identify and exploit vulnerabilities in AI agentic applications using the latest frameworks and tools.
This course dives deep into AI algorithmic red teaming, the OWASP Top 10 for LLMs, the OWASP Top 10 for AI Agentic Applications, and the MAESTRO Framework. You will master the use of tools such as garak, PyRIT, Prompt Fuzzer, Purple Llama, MCP Scanner, A2A Scanner, and more for offensive security operations against AI systems. You will also use AI coding agents, including Claude Code, Cursor, Codex, Windsurf, Warp, Copilot, Cline, AMP, and others, for offensive security operations.
What you’ll learn and how you can apply it
- Identify and exploit vulnerabilities in AI applications, LLMs, MCP servers, and multi-agent systems using the OWASP Top 10 for LLMs and the MAESTRO Framework.
- Perform AI algorithmic red teaming and assess agentic AI applications for security weaknesses across the entire AI lifecycle.
- Use cutting-edge tools for hacking AI systems including MCP and A2A scanners, and perform attacks such as prompt injection, confused deputy, hallucinations, and more.
- Use AI coding agents to automate and enhance your exploitation workflow.
This live event is for you because...
- Cybersecurity Professional (Analysts, Engineers, Architects, and Consultants) looking to upgrade your skills for the AI-driven era.
- Ethical Hacker seeking to automate and enhance your offensive security capabilities.
- Software Developer or DevOps Engineer focused on building secure applications and infrastructure.
- AI/ML Engineer or Data Scientist who wants to learn the latest trends in the dynamic fields of AI and cybersecurity.
- Anyone that is interested in learning how real-world attackers compromise systems.
Prerequisites
- Course participants should have a basic understanding of cybersecurity and networking concepts.
Course Set-up
- Setup WebSploit Labs as documented at: https://websploit.org and review the information at http://hackertraining.org
Recommended Preparation
- Read: AI-Powered Digital Cyber Resilience by Omar Santos and Dr. Petar Radanliev
- Watch: Practical Cybersecurity Fundamentals by Omar Santos
- Attend: Modern Cybersecurity Fundamentals by Omar Santos
- Attend: AI-Enabled Programming, Networking, and Cybersecurity by Omar Santos
- Watch: Building the Ultimate Cybersecurity Lab and Cyber Range by Omar Santos
Recommended Follow-up
- Read: Redefining Hacking: A Comprehensive Guide to Red Teaming and Bug Bounty Hunting in an AI-driven World by Omar Santos, Savannah Lazzara, and Wesley Thurner
- Watch: Build Your Own AI Lab by Omar Santos
- Watch: Securing Generative AI by Omar Santos
- Watch: Defending and Deploying AI by Omar Santos
- Practice: Ethical Hacking Labs by Omar and Derek Santos
- Attend: AI and LLM Cyber Risks and Mitigations by Omar Santos
Schedule
The time frames are only estimates and may vary according to how the class is progressing.
Segment 1: Introduction to Hacking of AI Applications and Agentic Systems (50 minutes)
- Overview of Hacking Techniques for AI Applications, LLMs, and Agentic Systems
- Exploiting Vulnerabilities in MCP Servers and Understanding Real-World Attack Scenarios
- Fundamentals of AI Algorithmic Red Teaming and Adversarial Testing Across the AI Lifecycle
- Deep Dive into the OWASP Top 10 for LLMs: Identifying and Exploiting Core Vulnerabilities
- Applying the MAESTRO Framework for Comprehensive Agentic AI Security Assessments
- Analyzing Security Weaknesses in Multi-agent Systems and Agentic Workflows
Break (10 minutes)
Segment 2: Using Offensive Security Tools and Hands-On Exploitation (50 minutes)
- Exploring the OWASP Top 10 for AI Agentic Applications and Key Exploitable Flaws
- Utilizing Cutting-Edge Tools for AI System Hacking: garak, PyRIT, Prompt Fuzzer, Purple Llama, MCP Scanner, A2A Scanner, and More
- Leveraging AI Coding Agents (Claude Code, Cursor, Codex, Windsurf, Warp, Co-pilot, Cline, AMP) for Automated and Scalable Exploitation
- Practical Hands-On Demonstrations: Prompt Injection, Confused Deputy, Hallucinations, and Additional Attack Techniques
Break (10 minutes)
Segment 3: Using AI Coding Agents for Automation and Reporting (50 minutes)
- Hacking Model Context Protocol (MCP) implementations
- Harnessing AI coding agents to streamline and automate offensive security tasks, from vulnerability exploitation to evidence collection and workflow management
- Generating comprehensive penetration testing and red teaming reports using AI agents to assist with documentation, data aggregation, and actionable recommendations
- Demonstrating how AI coding agents can accelerate repetitive tasks, improve reporting accuracy, and help synthesize findings for clear communication with stakeholders
Course Wrap-up and Q&A (10 minutes)
Your Instructor
Omar Santos
Omar Santos is a Distinguished Engineer at Cisco focusing on advanced AI security research, cybersecurity, incident response, and vulnerability disclosure. He is the co-chair of the Coalition for Secure AI (CoSAI) alongside leading AI companies such as OpenAI, Google, Anthropic, and NVIDIA. Omar has served in the board of the OASIS Open standards organization and is also the chair of the OpenEoX and the Common Security Advisory Framework (CSAF) technical committee. His work led the creation of the CSAF ISO standard. Omar's collaborative efforts extend to numerous organizations, including OWASP, FIRST, and he was the lead of the DEF CON Red Team Village for several years. Omar is the author of over 25 books, 21 video courses, and over 50 academic research papers. Omar is a renowned expert in ethical hacking, vulnerability research, incident response, and AI security. Omar's work in cybersecurity is also recognized through multiple granted patents. Prior to Cisco, Omar served in the United States Marines focusing on the deployment, testing, and maintenance of Command, Control, Communications, Computer, and Intelligence (C4I) systems.
Skills covered
- AI Security
- Penetration Testing / Ethical Hacking