Course

AI Red Teaming Foundations

By Wanderson Leandro de Oliveira

AI Red Teaming Foundations is the on-ramp to offensive security testing of AI systems — not a collection of exploits, but the mental model you need before a single exploit makes sense. You will learn what actually happens inside a large language model (tokens, context windows, sampling), why the line between "instructions" and "data" is the root cause of almost every prompt injection attack, and how to map the real attack surface around a modern AI application: the chatbot itself, the RAG pipeline, the agents and tools it calls, the MCP servers it talks to, the vector database behind it, and the infrastructure underneath all of it. From there, the course teaches formal threat modeling with STRIDE, attack trees and data flow diagrams, and situates two frameworks you will use constantly in this field — the OWASP Top 10 for LLM Applications and MITRE ATLAS. Every technique is framed around authorization: written scope, rules of engagement, and responsible disclosure, exactly as in traditional penetration testing, but adapted to the unique failure modes of AI systems. The final modules set up your local lab (Docker and Ollama) and introduce the DARE Vulnerable AI Suite — the hands-on target you will use in the next courses — and close with writing your first vulnerability finding and scoping a full mock assessment of a corporate chatbot. By the end, you will think like an AI red teamer even before you run your first attack.

Course content

Welcome to AI Red Teaming

How LLMs Actually Work

Where Trust Boundaries Live

Threat Modeling for AI Systems

Setting Up Your Lab

Writing Your First Finding