Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
The Ultimate AI/LLM/ML Penetration Testing Training Course
Bestseller
Rating: 4.5 out of 5(1,794 ratings)
22,703 students

The Ultimate AI/LLM/ML Penetration Testing Training Course

Become professional in finding and exploiting AI/LLM vulnerabilities. For Ethical Hackers, Bug Hunters and Pentesters.
Created byMartin Voelk
Last updated 9/2026
English

What you'll learn

  • Find and exploit prompt injection: direct, indirect, hidden/obfuscated, memory abuse, and data exfiltration
  • Attack AI agents and tool use: unwanted actions, delayed tools, excessive agency, and agent kill chains
  • Test MCP servers and plugins: tool poisoning, path issues, auth bypass, and malicious MCP setups
  • Break AI browsers and coding agents (Claude, Copilot, Cursor-style tools, Antigravity, and similar)
  • Jailbreak modern models and leak system prompts across ChatGPT, Claude, Gemini, Grok, and others
  • Cover OWASP Top 10 for LLMs and OWASP Top 10 for Agentic Applications with theory plus hands-on labs
  • Practice on real labs and CTFs (PortSwigger, Finbot, Gandalf, Wraith, AIPWN, and many more)
  • Use AI red-team tooling such as Garak, Promptmap, MCP scanners, Leakhub, and related utilities
  • Abuse multimodal and supply-chain paths: image/audio/video injection, embeddings, and model/data risks
  • Build offensive skills for AI/LLM penetration testing, red teaming, and bug bounty work

Course content

46 sections • 521 lectures • 43h 31m total length
  • Updates from 2025 OWASP Top 10 LLM to OWASP Top 10 LLM 202610:01

    Explore the 2025 OWASP top ten for LLM security, mapping new and moved categories like prompt injection, sensitive information disclosure, supply chain, data and model poisoning, and prompt leakage.

  • Course Structure (Core Content vs. CTFs) - Please watch8:00
  • AI/LLM Introduction18:54

    Learn how ai, llm systems, and large language models raise security challenges and how to identify and remediate vulnerabilities for penetration testers using the owasp top ten.

  • AI/LLM Attack Overview18:49

    Explore an overview of AI attack categories, including misalignment, jailbreaks, and prompt injections, and understand how injections, data exfiltration, and plugins create security risks in LLMs.

  • AI/LLM Frameworks / writeups4:49

    Review attack frameworks and write-ups for AI/LLM pentesting, including the current OWASP top ten, llm-attacks.org, and the prompt injection primer for engineers.

  • KONTRA - OWASP Top 10 LLM Free guided walkthroughs5:19

    Explore KONTRA's free guided walkthroughs on the OWASP Top 10 for LLM, with interactive hands-on labs for web apps and APIs, including prompt injection and vulnerable code analysis.

Requirements

  • Basic computer and internet skills (browse the web, install apps, follow on-screen steps)
  • Basic understanding of how websites and web apps work (helpful, not advanced)
  • No prior hacking, Linux, or programming experience required — everything is shown step by step
  • A computer with at least 4GB RAM (Windows, macOS, or Linux)
  • A reliable internet connection and any modern web browser
  • Willingness to practice only on systems you own or have permission to test

Description

The Ultimate AI/LLM Penetration Testing Course

Your instructor is Martin Voelk, a cybersecurity veteran with 27 years of experience. Martin holds AIRTP+, multiple SecOps certifications including the AI certifications, CISSP, OSCP, OSWP, PortSwigger BSCP, and Cisco CCIE. He works at a startup and hunts bugs in bug bounty programs, where he has found thousands of critical and high-severity vulnerabilities.

This course mixes short theory with hands-on labs so you can find and exploit vulnerabilities in AI and LLM apps. It follows the OWASP Top 10 for LLMs and the OWASP Top 10 for Agentic Applications. Videos are practical and easy to follow along.

What you'll cover (core content)

· Prompt injection — direct, indirect, agentic actions, data exfiltration, memory abuse, and hidden/obfuscated payloads

· Sensitive Information Disclosure

· Excessive Agency

· Supply Chain

· Data and Model Poisoning

· Unbounded Consumption and DoS

· Misinformation

· System Prompt Leakage (Hidden Context Exposure)

· Vector and Embedding Weaknesses

· Improper Output Handling

· OWASP PwnzzAI Shop labs

· OWASP Top 10 for Agentic Applications + OWASP Finbot labs

· PortSwigger - Agentic AI Labs

· SecOps Group AI/ML and Agentic mock exam walkthroughs

· Jailbreaking modern models

· AI Browsers Attacks

· AI Coding Agents Attacks

· MCP Attacks

· Multimodal Attacks (Images, Audio and Video)

· Red-team Tooling

CTF walkthroughs (optional)

Practice as many as you want after the core content:

· Deniskim CTF

· Prompt Airlines CTF Challenge Walkthrough

· Selara Jailbreak Game CTF

· Gandalf Agent Breaker CTF

· Hack The Agent CTF

· AI Prompt Attack and Defense Game Tensortrust CTF

· Crowdstrike AI Unlocked Challenge CTF

· Game Arena Challenges CTF

· PromptTrace Prompt Injection Labs CTF

· PromptInjects CTF

· 8ksec CTF

· AIPWN CTF

· Bot Tricks CTF

· Wraith CTF

· Other CTFs

Archive (legacy labs)

Kept for practice; techniques may still apply:

· Legacy OWASP Finbot CTF

· Legacy Gandalf lab

Notes & Disclaimer

I keep this course updated, but it will not always include every new AI bug the day it appears.

Some students want older CTFs removed; others want them kept. All CTF walkthroughs sit after Tooling and are optional — watch all, some, or none.

Most labs are free online. I don't control if owners take them down. If a lab disappears, the methods still apply to other labs and real targets you are allowed to test.

LLM providers change models often. Many techniques still work; some may need tuning later.

Use this only on systems you own or have clear permission to test. No unauthorized or malicious use.

Who this course is for:

  • Beginners who want a practical path into AI/LLM penetration testing and AI red teaming
  • Ethical hackers, pentesters, and bug bounty hunters expanding into AI and LLM targets
  • Security engineers and SOC/AppSec folks who need to understand how AI apps get attacked
  • Developers and AI builders who want to see real attack patterns against agents, tools, and prompts
  • Anyone preparing for AI/LLM security certifications or hands-on AI security labs and CTFs
  • Not for people looking for a pure theory/policy course with no demos — this is heavily practical