
Learn to think like an attacker to test AI security through direct and indirect prompt injection, multi-turn attacks, and red-teaming labs, including uncensored local models.
Install VMware Workstation Pro on your PC to run multiple operating systems in a secure, isolated environment for testing and development, with personal-use licensing from Broadcom.
Download a pre-built Kali Linux image from the official site, open it in VMware, adjust RAM and CPU, enable NAT, boot the VM, and use whoami and ifconfig to explore.
Set up a fully operational AI red-teaming lab on Kali Linux using Microsoft's AI Red Teaming Playground Labs, Docker, and Azure OpenAI deployments to tackle 12 red-teaming challenges.
Explore how generative AI creates content and how a red team examines its four training phases, tokens, embeddings, and the prompt injection attack surface.
Explore direct prompt injection attacks that override a model's system prompt by crafting one-shot prompts, illustrating how social engineering, role framing, and obfuscation bypass guardrails.
Explore direct prompt injection and social engineering techniques to test ai red-teaming safeguards, show how bots resist exfiltration attempts, and how resets and framing affect responses.
Engage in lab 2 direct prompt injection to uncover a secret word hidden in the system prompt, testing meta prompt extraction and defenses.
Explore multi-turn attacks, including skeleton key and crescendo, and how prompts can bypass model guardrails. Learn how these techniques steer a model toward harmful outputs in a safe educational context.
Examine multi-turn attacks and the crescendo method to coax a model into revealing unsafe instructions for a molotov cocktail, and analyze how gradual escalation enables prompt injection.
Explore multiturn attacks and prompt injection in ai red teaming, testing model alignment and safety filters, demonstrating a crescendo approach from benign prompts to risky ones.
Learn how multiturn attacks, including the crescendo prompt-injection technique, escalate from neutral prompts to profanity about inflation to test and bypass model safety policies.
Explore indirect prompt injection, where external data such as emails contain hidden commands that hijack a language model.
Examine indirect prompt injection by poisoning a web page and embedding a hidden instruction in an HTML comment, diverting the model from summarizing pages and prompting a jailbreak narrative.
Learn practical defenses against prompt injection by applying spotlighting techniques to distinguish trusted prompts from untrusted content, using delimiting, data marking, and encoding.
Install uncensored llms locally to protect privacy and run ai offline, using two methods: a GUI-based llm studio and a command-line powered olama setup.
Learn to use Gemini CLI on Kali Linux to orchestrate nmap, nikto, sqlmap, and go-buster for recon, SQL injection testing, and automated JSON reports, with safety rails.
“This course contains the use of artificial intelligence.”
AI Red Teaming is no longer a niche skill—it is one of the most in-demand specialties in all of cybersecurity. As companies race to integrate Generative AI into their products, they are exposing themselves to a new class of vulnerabilities. The #1 risk, according to OWASP, is Prompt Injection —and the only way to defend against it is to learn how to do it yourself.
This is the most practical, hands-on, and comprehensive guide to AI hacking available. We will be using the official Microsoft AI Red Teaming Playground —the same set of labs taught by Microsoft's own AI Red Team at Black Hat USA.
This is 100% hands-on. I will guide you, step-by-step, through practical challenges. You will not just see the solution—you will see the process. I will show you the prompts that fail and explain why they fail. Then, I will show you the prompts that succeed and break down the psychology and technical tricks that make them work.
This course is built on the official "AI Red Teaming 101" Microsoft Learn series , but goes even further. We'll start by building our lab from scratch, then add bonus modules on installing your own uncensored local AI models so you can practice these attacks without any filters.
What We Will Master:
Lab Setup : A complete, manual walkthrough of setting up the Microsoft AI Red Teaming Labs with Docker and a free Microsoft Azure account.
Direct Prompt Injection: Learn single-turn jailbreaks to exfiltrate credentials. We'll cover everything from simple instruction overrides to advanced social engineering and emotional manipulation prompts.
Metaprompt Extraction : Trick the AI into leaking its own "secret sauce." You'll learn to use creative, deceptive prompts to steal the system prompt.
The Crescendo Attack: Master the sophisticated multi-turn attack. We'll start innocent conversations and gradually "steer" the AI into bypassing its safety alignment to generate instructions for weapons, toxins, and profanity.
Bypassing Guardrails: We'll level up our attack to defeat an AI with active defenses, learning how to "backtrack" and rephrase our prompts when the model resists.
Indirect Prompt Injection: Execute the most dangerous attack. You'll learn to "poison" an external webpage with hidden instructions (in HTML comments and CSS) that hijack the AI when a normal user asks it to summarize the page.
Install Uncensored LLM ( AI model): Want more from your LLM. Learn to install uncensored LLM on your local PC.
By the end of this course, you won't just know what AI red teaming is. You will have a practical, repeatable skill set.