Skip to content
Hacked By HimelHacked By Himel
  • Category
    • AI Security
    • Blue Team
    • Bug Bounty
    • cloud security
    • Ethical Hacking
    • Fundamentals
    • Network Pentesting
    • OSINT
    • Pentesting
    • Pentesting AI
  • Home
  • Courses
  • Blog
  • Contact Us
    • About US
    • Contact Us
    • Dashboard
0

Currently Empty: ৳ 0.00

Continue shopping

Join for Free
Hacked By HimelHacked By Himel
  • Home
  • Courses
  • Blog
  • Contact Us
    • About US
    • Contact Us
    • Dashboard
  • Home
  • Course
  • Professional AI Red Teaming

Professional AI Red Teaming

  • By mdhimelatikh
  • AI Security
Breadcrumb Abstract Shape
Breadcrumb Abstract Shape
Breadcrumb Abstract Shape
  • Course Info
  • Instructor
  • More
    • Professional AI Red Teaming is a 6-month, fully practical cybersecurity program designed to transform you into a real-world AI Security Pentester. Delivered in Bangla and built for professionals, this course goes beyond theory—focusing on hands-on exploitation, defense strategies, and enterprise-level AI risk assessment. As organizations rapidly adopt generative AI and machine learning, they introduce complex new attack surfaces that traditional penetration testing simply cannot address

      Offered by HBHsec Academy, this program prepares you to secure modern AI systems used across SaaS platforms, automation pipelines, fintech, healthcare, and enterprise applications.


      Why AI/LLM Pentesting Matters Now

      AI adoption is exploding across industries—yet most organizations deploy LLMs without understanding their security risks.

      Today’s AI systems power:

      • Content & Code Generation Automation

      • AI Chatbots & Customer Support Platforms

      • Financial & Medical Analysis Engines

      • DevOps & Software Review Automation

      • Cyber Threat Detection & Intelligence Systems

      With this rapid integration comes a new attack surface that traditional pentesting does NOT cover.


      Real-World AI Threats You Will Learn to Exploit & Defend

      This course trains you to identify and mitigate the exact vulnerabilities companies are struggling with today:

      • Prompt Injection Attacks

      • LLM Data Leakage & Sensitive Information Exposure

      • Model Hallucination Exploitation

      • Malicious Code Generation Abuse

      • Adversarial Input Manipulation

      • AI Supply-Chain & Agentic Workflow Attacks

      You will work with frameworks aligned to OWASP Top 10 for LLM (2025) and MITRE ATLAS to simulate enterprise-grade attack scenarios.


      What Makes This Course Different?

      This is NOT another theory-heavy AI course.
      It is built like a real red-team training pipeline.

      ✔ 90% Practical Training — Labs, exploitation workflows, and real-world simulations
      ✔ 110+ Recorded Classes — Structured module-based learning over 6 months
      ✔ Weekly Live Problem-Solving Sessions with AI Security Experts
      ✔ CTF + Capstone Project — Perform a full AI/LLM penetration test
      ✔ Industry Tools Mastery — Garak, Promptmap, MCP Scan, Agentic Radar, TensorTrust
      ✔ Enterprise Attack Methodology — How real attackers break AI systems
      ✔ Mock Exams + Certification Path — Validate your professional readiness


      Learn by Doing — Not Watching

      Each week includes:

      • Guided exploitation labs

      • Scenario-based attack simulations

      • Practice day dedicated entirely to hands-on testing

      • Instructor & community support inside a private learning channel

      Students are expected to invest minimum 2 hours per day, mirroring real security research workflows.


      Certification & Assessment

      • 10 Full Mock Exams

      • ≥70% Score Required for Certification

      • SecOps AI/ML Exam Walkthrough Included

      • Designed to validate real operational skills—not memorization.


      Device Requirements

      • PC/Laptop with 4–8 GB RAM

      • 125–250 GB Storage (SSD recommended)


      Built by Pentesters, Not Influencers

      The course is developed by Hacked by Himel, an ISO/IEC 27001:2022 certified cybersecurity organization committed to ethical security research and aligned with Bangladesh Cyber Security Act 2023.

      We train defenders — not attackers without ethics.


      📅 Program Timeline

      • Registration Deadline: 2nd February 2027

      • Classes Start: 5th February 2027

      • New Modules Released Weekly

      • Classes Uploaded Daily (6 Days/Week)


      Who Should Enroll?

      • Pentesters wanting to enter AI Security

      • SOC Analysts & Threat Hunters

      • Developers integrating LLM into products

      • Cybersecurity students preparing for next-gen threats

      • Professionals looking to future-proof their career

      Show More

      Course Content

      Module 1: Introduction to AI

      • AI/LLM Introduction
      • AI/LLM Attack Overview
      • The AI gold rush & why security matters
      • Traditional app vulns vs. LLM-specific risks
      • Attack surface of AI-powered systems

      Module 2: AI/LLM Ecosystem & Architectures

      • AI model lifecycle: training, fine-tuning, deployment
      • LLMs, RAG (Retrieval-Augmented Generation), and AI agents
      • AI supply chain security & dataset integrity
      • Cloud AI services: AWS, Azure, GCP security concerns

      Module 3: AI Security Frameworks & Standards

      • OWASP AI/LLM Top 10 (2023 → 2025 updates)
      • MITRE ATLAS for adversarial ML
      • HBHSEC AI/LLM Assessment methodology

      Module 4: Fundamentals of Prompt Injection

      • Prompt injection theory & taxonomy
      • Direct vs. indirect injection
      • Gradient fuzzing vs. logical injections
      • Case studies of prompt injection in the wild

      Module 5: Advanced Prompt Injection Techniques

      • Prompt Injection – Gandalf Lab
      • Prompt Injection – Indirect Prompt Injection Lab
      • Prompt Injection via image – demo
      • Indirect prompt injection with data exfiltration – demo
      • Updating ChatGPT memories via prompt injection – demo
      • Deleting ChatGPT memories via prompt injection – demo
      • Conditional Prompt Injection
      • Prompt Injection into terminal / IDE via ANSI Characters
      • Indirect Prompt Injection in Grok

      Module 5: Advanced Prompt Injection Techniques

      • Use AI Models to jailbreak AI Models
      • Indirect Prompt injection in GitHub Copilot / Cursor via rules files
      • Image Prompt Injection leaking to tool invocation via MCP server

      Module 6: Sensitive Information Disclosure

      • OWASP Top 10 – Sensitive Information Disclosure
      • Sensitive Information Disclosure – Theory
      • Sensitive Information Disclosure – demo
      • Sensitive Information Disclosure with AI agents – demo

      Module 7: Supply Chain Vulnerabilities

      • OWASP Top 10 – Supply Chain
      • Supply chain vulns (malicious plugins, poisoned datasets)

      Module 8: Model & Training Data Poisoning

      • OWASP Top 10 – Data and Model Poisoning
      • Model and Training Data Poisoning – Theory
      • Model and Training Data Poisoning – Fake documents – Practical
      • RAG poisoning GlobalBank AI Scenario

      Module 9: Improper Output Handling

      • OWASP Top 10 – Improper Output Handling
      • Improper Output Handling – Theory
      • Improper Output Handling – Lab Insecure output handling
      • Improper Output Handling – HTML injection Practical

      Module 10: Excessive Agency

      • OWASP Top 10 – Excessive Agency
      • Excessive Agency – Theory
      • Insecure Plugin Design – Theory
      • Exploiting LLM APIs with excessive agency Lab
      • Exploiting vulnerabilities in LLM APIs Lab

      Module 11: System Prompt Leakage

      • OWASP Top 10 – System Prompt Leakage
      • Prompt Leakage – Demo
      • ChatGPT Prompt Leak
      • Ultra short prompt to leak prompt
      • Universal Prompt Leak Payload
      • Claude Memory and Prompt Enumeration
      • Claude Code Prompt Leakage
      • Cluely – system prompt leakage

      Module 12: Vector and Embedding Weaknesses

      • OWASP Top 10 – Vector and Embedding Weaknesses

      Module 13: Misinformation & Over-reliance

      • OWASP Top 10 – Misinformation
      • Misinformation and Overreliance – Theory
      • Misinformation and Overreliance – Demo – Hallucination
      • Misinformation and Overreliance – Demo – Health Care Agent
      • Misinformation and Overreliance – Demo – False Information
      • Misinformation and Overreliance – Image Misclassification Demo
      • DeepSeek bias leads to insecure code
      • Jailbreaking Grok to generate harmful social media images

      Module 14: Unbounded Consumption and DoS

      • OWASP Top 10 – Unbounded Consumption and DoS
      • Model Denial of Service – Theory
      • Model Theft – Theory
      • Agent Denial of Service (Demo)
      • Claude Magic String DoS Scenario

      Module 15: Prompt Airlines AI/ML CTF Challenge

      • Prompt Airlines AI/ML CTF Challenge – Flag 1 and 2 Walkthrough
      • Prompt Airlines AI/ML CTF Challenge – Flag 3 Walkthrough
      • Prompt Airlines AI/ML CTF Challenge – Flag 4 Walkthrough
      • Prompt Airlines AI/ML CTF Challenge – Flag 5 Walkthrough

      Module 16: SecOps Group AI/ML Mock Exam Walkthrough

      • SecOps Group AI/ML Mock Exam 1 Walkthrough
      • SecOps Group AI/ML Mock Exam 2 Walkthrough

      Module 17: AL Prompt Attack & Defense game Tensortrust AI

      • Tensortrust AI Practical

      Module 18: Selara JailBreak Assessment

      • Basic Prompt Injection & Direct Key Extraction
      • Encoding Evasion – Base64 & Data Format Manipulation
      • Multilingual Jailbreaking & Language Switching Attacks
      • Encoding + Obfuscation Attacks (Morse Code & Partial Spelling)
      • Acrostic Poem Technique & Progressive Key Extraction
      • Advanced Persona + Role-Play Jailbreaking (Final Boss Level)

      Module 19: Gandalf Agent Breaker CTF

      • Thingularity Level 1 Walkthrough
      • Mindfulchat Level 1 Walkthrough
      • Solaceai Level 1 Walkthrough
      • PortfolioIQ Advisor Level 1 Walkthrough
      • Onmichat Desktop Level 1 Walkthrough
      • Cycling Coach Level 1 Walkthrough
      • Trippy Planner Level 1 Walkthrough

      Module 20: Hack the Agent CTF

      • Hack the Agent Challenge 1
      • Hack the Agent Challenge 2
      • Hack the Agent Challenge 3

      Module 21: Other AI Security Testing Labs

      • New 0din CTF (AI Extraction Challenge)
      • HeliosBank LLM CTF
      • Multi-Agents CTF Tendry
      • Broken LLM Integration App
      • LMQL Demo Environment (Prompt Injection Challenge)
      • LLM Security Labs Playground
      • Prompt Defense CTF
      • Blore Bank AI Level 1
      • Blore Bank AI Level 2
      • Hackapromptle Daily Challenge – Day 1
      • Hackapromptle Daily Challenge – Day 2

      Module 22: AI/LLM Jailbreaking

      • Quick Deepseek R1 Jailbreak
      • Gemini 3.1 Jailbreak
      • Grok 4.2 Jailbreak
      • Latest Grok Jailbreak
      • Google Translate Jailbreak
      • Bypass Guardrails and Jailbreak with your own language
      • Grok jailbreak makes it output offensive information
      • Novel Jailbreaks for Grok and Deepseek
      • Jailbreak for GPT5.2, Grok 4.1 and Deepseek 3.2
      • Gemini Jailbreak with country flags
      • Jailbreaking Frontier Models with national flags
      • Grok 4.1 optimizes malware script
      • Gemini 3 Flash Jailbreak
      • Deepseek providing details instructions to generate an undesired item
      • Jailbreak to retrieve activation codes
      • Jailbreaking Grok with a chemical formula
      • Academic Jailbreak
      • Complete Bypass of most LLM guardrails
      • Jailbreaking Deepseek v3.2

      Module 23: AI Browser Attacks

      • Claude in Chrome Vulnerability
      • Claude in Chrome – System Prompt Leakage Haiku
      • Claude in Chrome – XSS Javascript Execution
      • Peplexity Comet Browser Data Exfiltration via Markdown Hyperlink
      • Perplexity Comet Image Based Prompt Injection
      • Data Exfil via Browser Agent in Comet Perplexity
      • Perplexity Comet – potential Browser Tab DoS
      • Perplexity-Comet Browser-Prompt- Injection-via-file closes-all-tabs
      • Perplexity Comet Browser Data Exfil of Google Calendar
      • Perplexity Comet Browser – VM enumeration
      • Perplexity Comet Browser Memory Manipulation via indirect prompt injection
      • Perplexity Comet Browser Prompt Leakage
      • Indirect Prompt Injection in Brave Browser with Leo AI
      • Prompt Leak and Profanity in Brave Browser with Leo AI
      • Brave Browser (Leo AI) Indirect Prompt Injection

      Module 24: AI Coding Agents Attacks

      • Google Antigravity – Browser Cookie Stealing
      • Google Antigravity System Prompt Leak
      • Google Antigravity File operation vulnerabilities
      • Google Antigravity Indirect Prompt Injection via instruction files or code
      • Claude skills data exfil
      • Cursor Browser Tool Data Exfiltration
      • Claude Code Secret exfiltration via image markdown link rendering
      • Claude Code System File Access
      • Claude Code System Prompt Leak
      • Claude Code RCE via reverse shell
      • OpenAI Codex Remote Code Execution (RCE)
      • KILL based prompt injection leads to RCE in Claude Code

      Module 25: MCP Attacks Testing

      • Challenge 01 Asana-multi-tenant-authorization-bypass
      • Challenge 02 Filesystem Prefix Bypass (CVE-2025-53110)
      • Challenge 03 Hidden Instructions in Tool Responses
      • Challenge 04 Xata Read-Only Bypass
      • Challenge 05 News Preview Prompt Exfiltration
      • Challenge 06 Log Poisoning Incident Response
      • Challenge 07 SQL Injection to Stored Prompt Injection
      • Challenge 08 Command Injection in MCP CLI Wrappers
      • Challenge 09 GitHub Public Issue Injection
      • Prompt injection to leak data to malicious MCP Server
      • No Path Validation on MCP Server Vulnerability
      • MCP Server Path Traversal Vulnerability
      • MCP Server No file type validation Vulnerability
      • MCP Server Summarization of Secrets vulnerability

      Module 26: Multimodal Attacks (Images, Audio and Video)

      • Prompt Injection and Jailbreaking via Image Steganography
      • Image Scaling Attack Prompt Injection in Claude
      • Image Prompt Injection to trigger MCP call
      • Adversarial Audio Attack
      • Prompt Injection via QR code
      • Image Prompt Injection in Grok

      Module 27: Automated Vulnerability Assessment

      • Garak Tool Demo
      • Promptmap Tool Demo
      • Agentic Radar Tool Demo
      • MCP Scan Tool

      Module 28: Report Writing and Post Testing Actions

      Pentesting Career & Guideline

      Tags

      • ai hacking
      • pentesting

      A course by

      M
      mdhimelatikh

      Course Includes:

      • Price:
        ৳ 45,000.00 Original price was: ৳ 45,000.00.৳ 15,000.00Current price is: ৳ 15,000.00.
      • Instructor:mdhimelatikh
      • Lessons:173
      • Level:Expert
      ৳ 15,000.00 ৳ 45,000.00
      Wishlist
      Hi, Welcome back!
      Continue with Google
      Forgot Password?
      Don't have an account?  Register Now

      Share On:

      cropped-hacked-by-himel-logo.png

      Hacked by Himel is a cybersecurity learning platform sharing ethical hacking, write-ups, and courses to help you master offensive and defensive security in Bangladesh.

      Add: Jashore, Bangladesh
      Call: +8801951045900
      Email: services@hbhsec.com

      Online Platform

      • Home
      • Blog
      • About US
      • Contact Us
      • Privacy Policy

      Links

      • Home
      • Courses
      • Blog
      • Contact Us

      Contacts

      Enter your email address to register to our newsletter subscription

      Icon-facebook Icon-youtube Icon-linkedin2 Icon-instagram Icon-twitter
      Copyright 2026 | All Rights Reserved
      Hacked By HimelHacked By Himel
      Sign inSign up

      Sign in

      Don’t have an account? Sign up
      Lost your password?

      Sign up

      Already have an account? Sign in
      Continue with Google

      Have Questions? WhatsApp Us