Pwned Labs AI Systems Attack & Defense Bootcamp - Professional Edition
Launches 20 October. Early bird pricing: $349 until launch, then $399.
Hands-on AI and agentic attack and defense training focused on real-world attack paths across LLM applications, RAG pipelines, and agentic systems.
Ideal for: application security engineers, penetration testers, security consultants, red and purple teamers, detection engineers, and developers shipping LLM-backed features. No prior AI security experience required.
Designed for modern LLM-backed and agentic applications, teaching operators to execute the tradecraft and assess AI-driven workflows end-to-end
Pwned Labs AI Systems Attack & Defense Bootcamp - Professional Edition Overview
AI systems are much more than just a chatbot!
This on-demand bootcamp and structured learning path teaches practical techniques for attacking and defending LLM-backed and agentic applications. You will work through prompt injection, RAG and embedding poisoning, tool and agent abuse, and MCP and CI/CD agent attack paths using techniques drawn from real AI security assessments.
After completing the bootcamp and associated learning path, you will validate your skills in a fully hands-on, unproctored exam that requires completing an end-to-end exploitation chain.
The exam environment is dynamic, with scenarios changing regularly to reflect real-world AI and agentic attacks and ensure certification credibility.
Prerequisites and key learning outcomes
You should be comfortable with HTTP, reading JSON, and using the command line. Familiarity with Python or curl helps for some labs, and lab guides cover both. No prior AI security experience is required.
After completing the bootcamp and passing the exam, you will demonstrate proficiency in:
- Understanding how LLM applications, RAG pipelines, and agentic systems are built and where they break
- Identifying and exploiting direct and indirect prompt injection in shipped LLM applications
- Poisoning RAG across documents, tickets, wikis, and embedding stores, and making retrieval attacks reliable
- Finding tool-abuse and excessive-agency paths in agentic systems and reducing their blast radius
- Tracing agentic compromise across CI/CD agents and MCP-connected tool servers
- Detecting AI attacks in telemetry: prompts, tool calls, retrieval hits, and side effects
- Applying the same tradecraft across AWS Bedrock, Azure AI Foundry, Google Vertex AI, and self-hosted stacks
- Delivering a defensible technical readout: attack chain, message-level evidence, root causes, and recommended detections
What you get
You get ongoing access to the full AI and agentic security curriculum, organized into four pillars that align to the four sessions. Each pillar includes its own learning path so you can hit the ground running before the session starts.
- Lifetime access to the latest session recordings, updated slides and command guides, bootcamp labs, and all future course updates
- 45 days of Academy lab access for the learning paths tied to each session, starting from when you redeem your voucher rather than from purchase, with no deadline to claim and extendable with subscription
- Direct preparation for the AISRTP certification exam
- More information on the bootcamp, learning paths, and the AISRTP exam is available here
Focus on trending techniques and tradecraft
The Pwned Labs AI Systems Attack & Defense Bootcamp - Professional Edition covers attacker tradecraft drawn from real AI and agentic security assessments, generalized into vendor-neutral, teachable patterns, including activity attributed to groups such as TeamPCP, whose Mini Shai-Hulud worm hijacks CI/CD pipelines and targets AI coding agents. Labs simulate realistic LLM-backed and agentic applications with live tools, retrieval, and agent workflows.
You will learn how to:
- Reproduce tradecraft from real AI and agentic findings
- Execute attacks using current AI red-team tooling and manual tradecraft
- Design controls and detections that reduce blast radius
Meet the team
Our instructors are on hand in Discord to help whenever you need it.
Ian Austin is a security researcher and educator with a career spanning over 20 years in technical, security and leadership roles for global enterprises.
Ian was Head of Content at Hack The Box, a leading online platform for cybersecurity training and assessment. He also participated in the Green Team of Locked Shields, a NATO cyber defense exercise, contributing to the design and execution of realistic scenarios.
He is the founder of Pwned Labs, providing gamified and immersive cloud security labs for red and blue teams.
How it works
Start immediately with on-demand access. Work through the learning path and labs at your own pace. Your purchase includes 45 days of lab access and two AISRTP exam attempts. The 45 days begins when you redeem your voucher rather than at purchase, and there is no deadline to claim it. Lab access is extendable with subscription. Support is available via Discord.
Ask your employer to fund AISRTP
Need employer funding approval? Use our ready-made employer funding request to outline the value of the Pwned Labs AI Systems Attack & Defense Bootcamp - Professional Edition and the AISRTP certification.
Prefer to self-fund? You can enroll immediately.

