<aside> 🛡️

A complete, hands-on field guide to attacking & securing AI systems — by Virdoex_hunter

21 chapters: prompt injection → jailbreaks → RAG poisoning → agent & MCP exploitation → model extraction → evasion → defenses → reporting. Every chapter has fresh examples, safe hands-on labs, real tooling, quick-revision checklists, and interview questions. Free & open — for authorised testing and education only.

</aside>

👋 Why I made these

I'm Deepak (Virdoex_hunter) — I do application security and offensive work by day and bug bounty on the side. I got pulled into AI red teaming the way a lot of us did: clients started shipping LLM features and nobody could tell me how to actually test them. So I worked through a full AI red teaming course, ran the labs myself, and wrote everything down in the way I'd have wanted it explained — plain, hands-on, and honest about what works vs what just sounds cool.

These are those notes, cleaned up and shared. I've added my own examples, extra techniques, real-world cases/CVEs, and runnable labs on top of the source material. Payloads are kept as [RESTRICTED] placeholders on purpose — the point is to understand and defend, not to hand out ready-made harmful prompts. Everything here is for authorised testing and learning only.

If something helps you, that genuinely makes my day — ping me on the links at the bottom. 🙏

🚀 Start Here


📚 Core Course

Chapter 01 — LLM Basics, Web LLM Pipeline & Intro to AI Red Teaming

Chapter 02 — Prompt Injection

Chapter 03 — Jailbreaking

Chapter 04 — Multi-Turn Attacks

Chapter 05 — Output Control Attacks

Chapter 06 — Token Smuggling

Chapter 07 — Social Engineering Attacks

Chapter 08 — Community Jailbreaks, Outcomes & the OWASP LLM Top 10

Chapter 09 — Practical Lab Walkthroughs (Sessions 1 & 2)