AI & LLM Security Pentesting & Bug Bounty
About Course
ADVANCED BUG BOUNTY HUNTING v2.0
BEGINNER TO EXPERT
Program Overview
An advanced offensive-security program designed to train security researchers, penetration testers and bug bounty hunters to assess modern AI/LLM applications, agents, RAG systems, MCP integrations, multimodal AI, AI browsers, coding assistants and agentic workflows.
The program covers the complete journey from AI fundamentals and reconnaissance to advanced exploitation, vulnerability chaining, bug bounty hunting and professional AI red teaming.
Core Focus
- LLM Application Security
- Prompt Injection & Jailbreaking
- AI Reconnaissance
- RAG & Vector Security
- AI Data & Model Poisoning
- AI Agent Security
- Excessive Agency & Tool Abuse
- MCP Security
- AI Browser & Coding-Agent Security
- Multimodal AI Security
- AI Business Logic
- AI Supply-Chain Security
- Automated AI Security Testing
- AI Bug Bounty & Vulnerability Research
- Professional Reporting & Attack Chaining
COURSE CONTENT
MODULE 01 AI & LLM SECURITY FOUNDATIONS
- AI, ML & Generative AI
- LLMs & Foundation Models
- Training vs Inference
- Tokens, Context & Model Behavior
- LLM Applications, APIs & SaaS
- AI Agents, RAG & Vector Databases
- AI Memory & External Integrations
- AI Security & Attack Surface
- AI Red Teaming & LLM Pentesting
- AI Bug Bounty & OWASP LLM Security
MODULE 02 LLM ARCHITECTURE & PENTESTING METHODOLOGY
- LLM Application Architecture
- System, Developer & User Instructions
- Context & Data Flow
- RAG & Agent Architectures
- Trusted vs Untrusted Content
- AI Security Boundaries
- AI Reconnaissance
- Threat Modeling
- Attack-Surface Mapping
- Vulnerability Validation & Reporting
MODULE 03 AI RECONNAISSANCE & ATTACK SURFACE DISCOVERY
- AI Endpoint & API Discovery
- Model Identification
- Prompt & Instruction Enumeration
- Tool, Plugin & Skill Discovery
- RAG & Memory Discovery
- External Integration Mapping
- Agent Capability Discovery
- AI Attack-Surface Mapping
MODULE 04 PROMPT INJECTION & SYSTEM PROMPT ATTACKS
- Direct Prompt Injection
- Instruction Hierarchy & Manipulation
- Context Manipulation
- Advanced Prompt Manipulation
- Obfuscation & Encoding
- Multi-Turn Attacks
- Indirect Prompt Injection
- System Prompt Leakage
- Tool & Agent Instruction Leakage
- Data Exfiltration Through Injection
- Persistent & Connector-Based Injection
MODULE 05 GANDALF PROMPT INJECTION LAB
- Gandalf Environment
- Instruction Boundary Testing
- Progressive Prompt Attacks
- Adaptive Attack Development
- Context Isolation Testing
- Model Behavior Analysis
- Structured Prompt-Injection Methodology
MODULE 06 AI DATA EXPOSURE & OUTPUT SECURITY
- Sensitive Information Exposure
- Context & Memory Leakage
- Credential & Token Exposure
- Unsafe AI Output
- Output Validation & Sanitization
- AI-Generated HTML, SQL & Commands
- AI-to-XSS / SQL Injection Scenarios
- Unsafe API Interactions
- Downstream Vulnerability Chaining
MODULE 07 JAILBREAKS, GUARDRAILS & MODEL SECURITY
- AI Guardrails & Safety Controls
- Jailbreak Methodologies
- Multi-Turn & Obfuscated Jailbreaks
- Encoding & Language-Based Bypasses
- Guardrail Testing
- Frontier Model Comparison
- Hallucination & Model Reliability
- AI Decision & Overreliance Risks
MODULE 08 RAG, VECTOR & AI DATA POISONING
- RAG Architecture
- Document Ingestion & Retrieval
- Embeddings & Vector Databases
- Retrieval Manipulation
- Vector & Embedding Attacks
- Unauthorized & Cross-User Retrieval
- Knowledge-Base Poisoning
- RAG Poisoning
- Training-Data Poisoning
- Persistent AI Manipulation
MODULE 09 AI SUPPLY CHAIN & MODEL SECURITY
- AI Supply-Chain Architecture
- Open-Source Models & Dependencies
- Plugins, Skills & Third-Party Tools
- Malicious Components
- Model Integrity
- Model Manipulation
- Model Fingerprinting
- Model Extraction & Behavioral Cloning
- AI API Abuse
MODULE 10 AI AGENTS & EXCESSIVE AGENCY
- AI Agent Architecture
- Planning, Memory & Tool Invocation
- Agent Attack Surface
- Permissions & Identity
- Excessive Agency
- Over-Privileged Tools
- Tool Input & Output Manipulation
- Tool Chaining
- Unauthorized Agent Actions
- Agent-Based Data Access & Exfiltration
MODULE 11 AGENT HIJACKING & ADVANCED AGENTIC SECURITY
- Goal Hijacking
- Workflow Manipulation
- Agent Identity & Privilege Abuse
- Agent Impersonation
- Memory & Context Poisoning
- Rogue Agents
- Inter-Agent Communication
- Multi-Agent Attacks
- Cascading Failures
- Advanced Agent Red Teaming
MODULE 12 AI BUSINESS LOGIC & ENTERPRISE AI
- AI Business Logic Vulnerabilities
- Policy & Decision Manipulation
- Workflow Abuse
- Human Approval Bypass
- Enterprise AI Attack Scenarios
- Financial & Compliance AI
- Invoice & Vendor Workflows
- Automated Approvals
- AI Authorization Abuse
- FinBot Security Scenarios
MODULE 13 MCP, AI BROWSERS & CODING AGENTS
MCP Security
- MCP Architecture
- Tool & Server Enumeration
- Tool Poisoning
- MCP Prompt Injection
- File & Path Security
- Permission Analysis
- Cross-Tool Attack Chains
AI Browser Security
- Computer-Use Agents
- Browser Permissions
- Cookies & Sessions
- Browser Prompt Injection
- Data Exfiltration
- Account & File Access
- Browser Agent Abuse
Coding-Agent Security
- AI IDEs & Coding Assistants
- Repository Attacks
- Instruction-File Injection
- Dependency Manipulation
- Secret Exposure
- Tool & Filesystem Abuse
- Command Execution Scenarios
MODULE 14 MULTIMODAL AI SECURITY
- Image Prompt Injection
- Hidden Visual Instructions
- EXIF & Metadata Attacks
- Steganographic Injection
- QR-Based Attacks
- Audio Injection
- Video-Based Attacks
- Multimodal Jailbreaks
- Cross-Modal Attack Chains
- AI-to-Tool & AI-to-Data Attacks
MODULE 15 AI AVAILABILITY & AUTOMATED SECURITY TESTING
- AI Denial of Service
- Context Exhaustion
- Recursive Agent Workflows
- Request Amplification
- Expensive Inference
- AI Security Testing Tools
- Garak
- Promptmap
- Agentic Radar
- MCP Scanning
- Automated Prompt Testing
- False Positive / False Negative Validation
MODULE 16 AI BUG BOUNTY & PROFESSIONAL RED TEAMING
- AI Target Discovery
- AI Bug Bounty Methodology
- Vulnerability Research
- Attack Hypothesis Development
- Vulnerability Validation
- Impact Assessment
- AI Vulnerability Chaining
- AI → Traditional Vulnerability Chains
- Professional PoC Development
- Severity & Impact Analysis
- Bug Bounty Reporting
- Enterprise AI Red Teaming
PRACTICAL MODULE PROMPT AIRLINES
AI/ML Security Challenge
- AI Reconnaissance
- Attack-Surface Discovery
- Prompt Manipulation
- Context Abuse
- Information Discovery
- Security-Boundary Testing
- Multi-Stage Attack Reasoning
- Vulnerability Validation
PRACTICAL MODULE TMG SECURITY CUSTOMIZED LLM SECURITY LAB
TMG AI SECURITY PLAYGROUND
A proprietary vulnerable AI environment developed specifically for TMG Security students.
Beginner
- AI Discovery
- Prompt Injection
- Instruction Boundaries
- Information Exposure
Intermediate
- Indirect Injection
- System Prompt Exposure
- Context Leakage
- RAG Security
- AI Business Logic
Advanced
- Agent Manipulation
- Tool Abuse
- Excessive Permissions
- Memory Poisoning
- MCP Security
- Browser & Coding-Agent Attacks
Expert
- Multi-Stage AI Attacks
- Data Exfiltration
- Agent Privilege Abuse
- Cross-Component Attack Chains
- Multimodal Attacks
- AI → Traditional Vulnerability Chains
- Enterprise AI Scenarios
FINAL CAPSTONE FULL AI RED TEAM ASSESSMENT
Students perform an end-to-end security assessment against an AI-powered application.
Reconnaissance
- AI Functionality
- Endpoints
- Models
- Tools
- Integrations
Vulnerability Discovery
- Prompt Injection
- Data Exposure
- RAG
- Agents
- Tools
- MCP
- Output Security
- Multimodal Attacks
Exploitation & Validation
- Vulnerability Confirmation
- Proof-of-Concept
- Impact Demonstration
- Attack Chaining
Final Deliverable
- Attack-Surface Map
- Vulnerability Report
- Severity
- Evidence
- Attack Chain
- Business Impact
- Remediation
- Professional Bug Bounty Report
Note: Mostly all the mentioned content will be taught live and with poc findings recording.
Trainers : Mayank Gandhi
Benefits :
- Get ISO Certified Certification
- Live Targets to hunt