Course Outline
Module 1 — AI Systems for Security Engineers
Lab: Lab 01 — 01-Introduction
Comprehensive architectural analysis.
Topics:
- Distinction between LLMs and conventional applications
- AI inference pipeline structures
- Prompt processing flows
- Retrieval-Augmented Generation (RAG) architecture
- Embeddings and vector database integration
- Agentic workflow orchestration
- External tool invocation mechanisms
- AI gateway implementations
- Copilot functionality
- Model Context Protocol (MCP) and agent communication standards
- Limitations of WAF visibility in AI contexts
- Gaps in WAF monitoring capabilities
Key insight: Standard Web Application Firewalls (WAFs) frequently lack the ability to monitor content once prompts have been transmitted to the model.
Module 2 — OWASP GenAI Top 10
Lab: none — interactive recap/discussion
Primary categories of AI-specific vulnerabilities.
Topics:
- Prompt Injection
- Insecure Output Handling
- Training Data Poisoning
- Model Denial of Service
- Supply Chain Vulnerabilities
- Disclosure of Sensitive Information
- Excessive Agency
- Vector/Embedding Vulnerabilities
- Misinformation Generation
- Unbounded Resource Consumption
Include:
- Divergences from traditional OWASP standards
- Alignment of defensive controls (WAF, gateway, application layer)
- Scope of effectiveness for each control
- Limits and failure points of each control
Module 3 — Prompt Injection Detection
Lab: Lab 02 — 02-Prompt-Injection
Analogous to the historical emergence of SQL injection risks.
Topics:
- Direct prompt injection vectors
- Indirect prompt injection vectors
- Concealed instruction techniques
- Document-based exploitation methods
- HTML/Markdown injection tactics
- Jailbreak pattern recognition
- Context override manipulation
- Role confusion exploitation
Detection methodologies:
- Keyword-based heuristic analysis
- Semantic classification techniques
- Prompt structure linting
- Enforcement of instruction boundaries
- Allow/deny policy configurations
- AI-specific regular expression patterns
Hands-on labs:
- Simulation of chatbot attacks
- Evading basic filtering mechanisms
- Implementing multi-layered detection systems
Module 4 — AI-Aware WAF Rules
Lab: Lab 03 — 03-WAF-Basics
Adaptation of WAF rule sets for AI environments.
- Topics:
- Securing LLM endpoints
- Protection of inference APIs
- Token-based rate limiting strategies
- Inspection of prompt volume and size
- AI-specific signature development
- Anomaly detection in conversation patterns
- Abuse patterns in multi-turn interactions
- Attempts at model enumeration
- Scraping of inference outputs
- Prevention of denial-of-wallet attacks
Examples:
- Safeguarding /v1/chat/completions endpoints
- Defense of streaming API interfaces
- Mitigation of recursive agent invocation
Module 5 — Securing RAG Pipelines
Lab: Lab 04 — 04-RAG-Security
A significant emerging attack surface.
Topics:
- Threats to vector databases
- Embedding data poisoning
- Malicious PDF/document injection
- Manipulation of retrieval processes
- Semantic poisoning techniques
- Hidden instructions within source documents
- Cross-document data contamination
- Data exfiltration through retrieval mechanisms
Defensive measures:
- Sanitization of ingested data
- Implementation of trust scoring
- Isolation of metadata
- Tracking of document provenance
- Configuration of retrieval policies
- Data segmentation strategies
Case study: “Injection of poisoned documents to compromise AI assistant integrity.”
Module 6 — Agentic AI Security
Lab: Lab 05 — 05-Agent-Security
High-risk operational areas.
Topics:
- Excessive agency behaviors
- Abuse of connected tools
- API chaining vulnerabilities
- Uncontrolled autonomous loops
- Privilege escalation risks
- Memory poisoning attacks
- Indirect tool execution exploits
- Agent identity impersonation
- Credential leakage incidents
- Multi-agent interaction attacks
Defensive measures:
- Application of least privilege to agents
- Implementation of approval gates
- Deployment of runtime policy engines
- Sandboxing environments
- Use of scoped credentials
- Whitelisting of permitted tools
- Human-in-the-loop oversight
This section addresses critical operational and business impact concerns typically prioritized by management.
Module 7 — API Security for AI
Lab: Lab 06 — 06-Denial-of-Wallet
The API-centric nature of AI systems.
Topics:
- API gateway configurations
- Security risks in GraphQL AI implementations
- Misuse of MCP/API interfaces
- JWT security measures
- AI plugin integrity
- Authentication of autonomous agents
- Delegated authorization frameworks
- Secret management practices
- Implementation of signed prompts
- AI-specific API inventory management
Alignment with: OWASP API Security Top 10
Module 8 — Detection Engineering & SOC Integration
Lab: Lab 07 — 07-Detection
Operational defense capabilities.
Topics:
- AI telemetry collection
- Prompt logging standards
- Token usage analytics
- Anomaly detection systems
- Semantic SIEM pipeline integration
- Indicators of compromise for AI
- Threat hunting for LLM abuse
- Runtime observability for AI
Examples:
- Identification of coordinated jailbreak campaigns
- Detection of automated agent misuse
- Recognition of model scraping activities
Module 9 — Cloud WAFs and AI Security
Lab: none — interactive recap/discussion
Vendor-specific implementation strategies.
Topics:
- AWS WAF application to AI APIs
- Azure WAF configurations
- Cloudflare AI Gateway capabilities
- General API gateway frameworks
- Envoy AI filtering mechanisms
- Kong AI Gateway features
- NGINX AI security patterns
Comparison:
- Traditional WAF vs. AI gateway vs. application-layer guardrails
- Proxy-based inspection vs. semantic filtering
Module 10 — Building a Layered AI Defense
Lab: Lab 08 — 08-Layered-Defense
Fundamental strategic conclusion:
No single security layer is sufficient to secure AI systems; a standalone WAF is particularly insufficient.
Participants construct a multi-layered model:
- WAF
- API gateway
- AI gateway
- Guardrails
- Runtime monitoring
- Identity and authorization
- Sandboxing
- Human approval processes
- Observability
- Incident response
This approach aligns with the “multi-layer security” paradigm.
Module ↔ Lab map
Labs are executed in sequential order, corresponding to module progression.
The curriculum comprises 10 modules and 8 labs; Modules 2 and 9 are interactive discussions without associated labs.
Each lab is explicitly linked to its corresponding module in this outline.
- Lab 01 (Module 1)
- Folder: 01-Introduction
- Title: Analysis of AI system traffic and wire-level data
- Lab 02 (Module 3)
- Folder: 02-Prompt-Injection
- Title: Simulating chatbot attacks and evading basic filters
- Lab 03 (Module 4)
- Folder: 03-WAF-Basics
- Title: Development of AI-aware WAF rules
- Lab 04 (Module 5)
- Folder: 04-RAG-Security
- Title: Simulation of RAG pipeline poisoning
- Lab 05 (Module 6)
- Folder: 05-Agent-Security
- Title: Implementation of autonomous agent security controls
- Lab 06 (Module 7)
- Folder: 06-Denial-of-Wallet
- Title: Detection of denial-of-wallet attack vectors
- Lab 07 (Module 8)
- Folder: 07-Detection
- Title: Monitoring of AI abuse patterns in logs
- Lab 08 (Module 10)
- Folder: 08-Layered-Defense
- Title: Construction of a layered AI defense architecture
Capstone
Participants defend a simulated enterprise AI assistant infrastructure.
Simulated attack scenarios include:
- Prompt injection
- Tool abuse
- Credential theft
- Retrieval poisoning
- Excessive API consumption
- Agent privilege escalation
Teams will implement:
- WAF rule sets
- AI gateway policies
- Runtime detection mechanisms
- Guardrail configurations
- Incident response protocols
Requirements
- Participants must possess foundational knowledge of HTTP/API security, proxies/reverse proxies, authentication, OWASP Top 10, REST APIs, and basic cloud networking
Audience
- Security engineers and Application Security (AppSec) specialists
- SOC analysts and detection engineers
- API security engineers
- Cloud, API, and platform security professionals
- DevSecOps engineers
- Security architects
- WAF and network security specialists
- AI platform engineers
Testimonials (3)
inventory and identifying the different risk exposures within AI
Gary Cook - Cybersecurity and Information Technology Risk Division
Course - Introduction to AI Trust, Risk, and Security Management (AI TRiSM)
I really enjoyed learning about AI attacks and the tools out there to begin practicing and actively using for security testing. I took a lot of knowledge away which I didn't have at the beginning and the course met what I hoped it would be. My favorite part shown from the training was Comet Browser and was amazed at what it could do. Definitely something will be looking into more. Overall it was a great course and enjoyed learning all OWASP GenAI Top 10.
Patrick Collins - Optum
Course - OWASP GenAI Security
The profesional knolage and the way how he presented it before us