<aside> 🛡️
A complete, hands-on field guide to attacking & securing AI systems — by Virdoex_hunter
21 chapters: prompt injection → jailbreaks → RAG poisoning → agent & MCP exploitation → model extraction → evasion → defenses → reporting. Every chapter has fresh examples, safe hands-on labs, real tooling, quick-revision checklists, and interview questions. Free & open — for authorised testing and education only.
</aside>
I'm Deepak (Virdoex_hunter) — I do application security and offensive work by day and bug bounty on the side. I got pulled into AI red teaming the way a lot of us did: clients started shipping LLM features and nobody could tell me how to actually test them. So I worked through a full AI red teaming course, ran the labs myself, and wrote everything down in the way I'd have wanted it explained — plain, hands-on, and honest about what works vs what just sounds cool.
These are those notes, cleaned up and shared. I've added my own examples, extra techniques, real-world cases/CVEs, and runnable labs on top of the source material. Payloads are kept as [RESTRICTED] placeholders on purpose — the point is to understand and defend, not to hand out ready-made harmful prompts. Everything here is for authorised testing and learning only.
If something helps you, that genuinely makes my day — ping me on the links at the bottom. 🙏
Chapter 01 — LLM Basics, Web LLM Pipeline & Intro to AI Red Teaming
Chapter 04 — Multi-Turn Attacks
Chapter 05 — Output Control Attacks
Chapter 07 — Social Engineering Attacks
Chapter 08 — Community Jailbreaks, Outcomes & the OWASP LLM Top 10