One-day hands-on training · Austin, TX

Applied Hacking for AI Systems.

A practical, one-day AI security training in Austin on finding and fixing the security flaws in AI and LLM applications, taught by the team that tests AI agents for a living.

Next cohort
Wed, Oct 21, 202610am–4pm CDT
Location
Austin, TX
Duration
One day
Format
In person
Level
Intermediate
Includes
Certificate + labsComplete slides + private Discord

Early-bird price

$349$549

You save $200 on the regular price.

A recent SecureLayer7 AI security master class cohort in the room

A recent master class

Who it is for

Built for the people who ship and defend AI.

A code editor whose output flows into a neural network, with one node highlighted01

Developers shipping AI features

You build LLM or agent features and want to find the flaws yourself before they reach production.

A magnifier over layered application panels catching a highlighted crack02

AppSec and security engineers

You test applications for a living and need AI and LLM attacks in your toolkit, hands-on.

A radar-style risk map of connected nodes with the centre node ringed03

Technical leads who own AI risk

You are accountable for AI risk and want to see the attacks first-hand so you can guide your team.

What you earn

A certificate, and the skill behind it.

You leave with a certificate of completion for the training, and something harder to put on a slide: the hands-on ability to find and fix the flaws in AI and LLM applications, and a repeatable way to test the ones your own team ships.

Sample SecureLayer7 certificate of completion for the Applied Hacking for AI Systems training
Sample SecureLayer7 certificate of completion for the Applied Hacking for AI Systems training

The day

The syllabus, module by module.

You attack a real, deliberately vulnerable AI application through the day, then learn to defend it. Each module pairs a short briefing with a hands-on lab.

  1. 01

    The AI attack surface

    How LLM and AI features actually get built and shipped, and where that pipeline breaks. The web flaws that resurface in AI clothing, plus the two maps you use all day: the OWASP Top 10 for LLM applications and MITRE ATLAS.

  2. 02

    Threat-modeling an AI system

    Before you attack, you map. Where the trust boundaries sit in a real LLM or multimodal deployment, which inputs the model actually trusts, and where one crossed boundary becomes a breach. You threat-model a live, vulnerable app as a group.

  3. 03

    Prompt injection, hands-on

    Direct and indirect injection: why a model cannot separate your instructions from an attacker’s, and how hidden text in inputs, documents, and tool output takes over its behavior. You run the attacks yourself against public and custom endpoints.

  4. 04

    Jailbreaking production models

    Getting a shipped model to ignore its own guardrails: the bypass patterns that keep working, why they work, and where a jailbreak actually matters once it is wired into an application. Hands-on against real models.

  5. 05

    RAG and data leakage

    Poisoning what a retrieval system feeds the model, and pulling out the data the app was never meant to reveal. You attack the knowledge layer of a working RAG pipeline.

  6. 06

    Agents, tools, and MCP

    Excessive agency, tool and connector abuse, and the moment an agent starts doing the attacker’s work with its own access. Lab against an agent wired to real tools and an MCP server.

  7. 07

    AI supply-chain risk

    Unsafe model formats that run code the moment they load, malicious packages posing as AI SDKs, and the open-source models and datasets you inherit without reading. What you can and cannot trust in the AI supply chain.

  8. 08

    Red-team it, then harden it

    A repeatable way to red-team your own AI features, scored against the OWASP LLM Top 10 and MITRE ATLAS so findings stay consistent. Then the defenses that hold, and how to tell them from the ones an attacker walks straight through. Capstone lab: attack the full application, then harden it.

Your trainer

Taught by the people who test AI for a living.

Sandeep Kamble

Founder & CTO, SecureLayer7

Sandeep is the founder and CTO of SecureLayer7, with fourteen years in offensive security. Most of that has gone into building the offensive tooling behind SecureLayer7’s autonomous pentesting and AI red team work, and under his leadership the team has delivered hundreds of LLM and AI application pentests. He still finds the bugs himself: a remote code execution in n8n, a SQL injection in Spring AI, and fuzzing work against the V8 JavaScript engine, among others. The training comes straight from that work, not from theory, so what you practise in the lab is what actually shows up in the field.

Sandeep Kamble, Founder & CTO, SecureLayer7

Want this run privately for your team, in Austin or on site? Tell us your goals and we will scope it.

Ask about private training

By the end

What you walkaway with.

An eye for AI flaws

You can spot the common AI and LLM vulnerabilities in a codebase or a running app, not just name them.

A way to test your own

A repeatable method to red-team the AI features your team ships, so testing does not stop at the classroom door.

Real attack experience

A full day running real attacks in a safe lab, against an app built to break the way production apps do.

Proof you did it

A certificate of completion, and the confidence to bring this back to your team.

Before you book

Training questions,answered.

Show all 8 questions

Reserve your seat

Spend a day learning to break AI, safely.

Seats for the Austin training are limited to keep it hands-on. Reserve yours and we will confirm the date, venue, and price with you.

Ask about private training