AI Free course · Certificate included
AI Security: Prompt Injection, Data Leakage and Red Teaming
Threat-model, attack and harden LLM apps and agents using OWASP, MITRE ATLAS and NIST guidance, garak, PyRIT and promptfoo
- Advanced
- 7 h 18 min
- 17 lessons in 7 modules
- 2 h 23 min of video lectures
- Updated Sep 2026
About this course
LLM applications and agents read untrusted text, hold sensitive data and increasingly take real actions, which makes them a new and fast-moving attack surface. This advanced course teaches you to think like an attacker and build like a defender. You will threat-model LLM apps, map risks to the OWASP Top 10 for LLM Applications (2025 and the August 2026 update) and the OWASP Top 10 for Agentic Applications, and use MITRE ATLAS and NIST guidance. You will dissect direct and indirect prompt injection, jailbreaks, data exfiltration through tools, links and images, excessive agency, supply-chain risks in models, datasets and MCP servers, RAG poisoning, improper output handling and secret or PII leakage. Then you will design defense in depth, run structured red-team exercises with garak, PyRIT and promptfoo, and prepare incident response. The capstone: red-team and harden a tool-using agent.
Tools you’ll use
- OWASP Top 10 for LLM Applications
- OWASP Agentic Top 10
- MITRE ATLAS
- NIST AI RMF
- garak
- PyRIT
- promptfoo
- Inspect
- Microsoft Presidio
- Model Context Protocol
- OpenTelemetry
- Docker
Skills
- AI security
- Prompt injection defense
- Threat modeling
- AI red teaming
- Agent security
- LLM supply chain security
- Incident response
What you’ll be able to do
- Threat-model an LLM application or agent, identifying trust boundaries, assets and abuse cases
- Map risks to the OWASP LLM and Agentic Top 10 lists, MITRE ATLAS and NIST guidance
- Explain and demonstrate direct and indirect prompt injection, jailbreaks and exfiltration channels
- Secure tools, agents, RAG pipelines and supply chains including models, datasets and MCP servers
- Design defense-in-depth controls: privilege separation, allowlists, approvals, provenance and monitoring
- Plan and run red-team exercises using garak, PyRIT and promptfoo, and report findings
- Prepare and run incident response for AI-specific security events
Curriculum
Syllabus
- Modules
- 7
- Lessons
- 17
- Reading time
- 4 h
- Assessment questions
- 30
Understand why LLMs break the code/data boundary, identify assets, trust boundaries and the lethal trifecta, and run a practical threat model with abuse cases.
- The LLM threat landscape and the lethal trifectaVideo lecture, 9′13 min
- A practical threat-modeling process for LLM systemsVideo lecture, 8′14 min
Use the OWASP Top 10 for LLM Applications (2025 and 2026 editions) and Agentic Applications, MITRE ATLAS and NIST AI guidance as a shared language for coverage, attacks and risk management.
- OWASP Top 10 for LLM and Agentic ApplicationsVideo lecture, 8′14 min
- MITRE ATLAS and NIST AI guidanceVideo lecture, 8′13 min
Recognize direct injection and jailbreak families, defend against indirect injection by separating reading from acting, and close exfiltration channels such as images, links and tools.
- Direct prompt injection and jailbreaksVideo lecture, 8′14 min
- Indirect prompt injection and separation patternsVideo lecture, 8′15 min
- Data exfiltration: images, links, tools and EchoLeakVideo lecture, 8′14 min
Contain excessive agency with narrow, authorized tools and approvals; secure models, datasets, packages and MCP servers; and defend RAG indexes, vector stores and memory.
- Excessive agency and secure tool designVideo lecture, 8′15 min
- AI supply chain: models, datasets, packages and MCP serversVideo lecture, 8′14 min
- RAG poisoning, vector store security and memoryVideo lecture, 8′14 min
Treat model output as untrusted input to every downstream sink, and prevent sensitive information disclosure, hidden context exposure and unbounded consumption.
- Improper output handling: XSS, SQL, code execution and SSRFVideo lecture, 9′14 min
- Secrets, PII, hidden context and unbounded consumptionVideo lecture, 9′14 min
Design layered defenses with deterministic cores and kill switches, plan and run structured AI red-team engagements, and automate testing with garak, PyRIT, promptfoo and Inspect.
- Defense-in-depth architecture for LLM apps and agentsVideo lecture, 9′15 min
- Planning and running AI red-team engagementsVideo lecture, 9′14 min
- Red-team tooling: garak, PyRIT, promptfoo and InspectVideo lecture, 9′14 min
Prepare for and respond to AI security incidents, then red-team and harden a deliberately insecure tool-using agent end to end.
- Incident response for AI systemsVideo lecture, 8′14 min
- Capstone: red-team and harden a tool-using agentVideo lecture, 9′25 min
- Final assessment
Your certificate
Finish with a credential anyone can check
Earn the Certified AI Security Practitioner badge: The holder can secure LLM applications and agents: threat modeling, mapping risks to OWASP, MITRE ATLAS and NIST guidance, defending against direct and indirect prompt injection, exfiltration, excessive agency, supply-chain and RAG poisoning attacks, designing defense in depth, running structured red-team exercises with open-source tools, and responding to AI security incidents.
Completed all lessons and scored at least 80% on the final assessment.
- A public verification page
- A PDF certificate to download
- An Open Badge you can share
- One click to your LinkedIn profile
Final assessment
- 30questions drawn from a larger pool
- 45 mintime limit
- 80%pass mark
- 3attempts per 24 hours
Start learning today. It’s free.
Every lesson is free to read. A free account saves your progress, unlocks the final assessment and issues your certificate.