AI Free course · Certificate included

AI Security: Prompt Injection, Data Leakage and Red Teaming

Threat-model, attack and harden LLM apps and agents using OWASP, MITRE ATLAS and NIST guidance, garak, PyRIT and promptfoo

  • Advanced
  • 7 h 18 min
  • 17 lessons in 7 modules
  • 2 h 23 min of video lectures
  • Updated Sep 2026
Preview lesson 1
Earn the badgeCertified AI Security Practitioner

About this course

LLM applications and agents read untrusted text, hold sensitive data and increasingly take real actions, which makes them a new and fast-moving attack surface. This advanced course teaches you to think like an attacker and build like a defender. You will threat-model LLM apps, map risks to the OWASP Top 10 for LLM Applications (2025 and the August 2026 update) and the OWASP Top 10 for Agentic Applications, and use MITRE ATLAS and NIST guidance. You will dissect direct and indirect prompt injection, jailbreaks, data exfiltration through tools, links and images, excessive agency, supply-chain risks in models, datasets and MCP servers, RAG poisoning, improper output handling and secret or PII leakage. Then you will design defense in depth, run structured red-team exercises with garak, PyRIT and promptfoo, and prepare incident response. The capstone: red-team and harden a tool-using agent.

Tools you’ll use

  • OWASP Top 10 for LLM Applications
  • OWASP Agentic Top 10
  • MITRE ATLAS
  • NIST AI RMF
  • garak
  • PyRIT
  • promptfoo
  • Inspect
  • Microsoft Presidio
  • Model Context Protocol
  • OpenTelemetry
  • Docker

Skills

  • AI security
  • Prompt injection defense
  • Threat modeling
  • AI red teaming
  • Agent security
  • LLM supply chain security
  • Incident response

What you’ll be able to do

  1. Threat-model an LLM application or agent, identifying trust boundaries, assets and abuse cases
  2. Map risks to the OWASP LLM and Agentic Top 10 lists, MITRE ATLAS and NIST guidance
  3. Explain and demonstrate direct and indirect prompt injection, jailbreaks and exfiltration channels
  4. Secure tools, agents, RAG pipelines and supply chains including models, datasets and MCP servers
  5. Design defense-in-depth controls: privilege separation, allowlists, approvals, provenance and monitoring
  6. Plan and run red-team exercises using garak, PyRIT and promptfoo, and report findings
  7. Prepare and run incident response for AI-specific security events

Curriculum

Syllabus

Modules
7
Lessons
17
Reading time
4 h
Assessment questions
30
  1. Understand why LLMs break the code/data boundary, identify assets, trust boundaries and the lethal trifecta, and run a practical threat model with abuse cases.

    1. The LLM threat landscape and the lethal trifectaVideo lecture, 9′13 min
    2. A practical threat-modeling process for LLM systemsVideo lecture, 8′14 min
  2. Final assessment30 questions · 45 minutes · pass mark 80%

Your certificate

Finish with a credential anyone can check

Earn the Certified AI Security Practitioner badge: The holder can secure LLM applications and agents: threat modeling, mapping risks to OWASP, MITRE ATLAS and NIST guidance, defending against direct and indirect prompt injection, exfiltration, excessive agency, supply-chain and RAG poisoning attacks, designing defense in depth, running structured red-team exercises with open-source tools, and responding to AI security incidents.

Completed all lessons and scored at least 80% on the final assessment.

  • A public verification page
  • A PDF certificate to download
  • An Open Badge you can share
  • One click to your LinkedIn profile

Final assessment

  • 30questions drawn from a larger pool
  • 45 mintime limit
  • 80%pass mark
  • 3attempts per 24 hours

Start learning today. It’s free.

Every lesson is free to read. A free account saves your progress, unlocks the final assessment and issues your certificate.