{"product_id":"attacking-defending-ai-systems-mcp-rag-ai-agents-through-aigoat","title":"Attacking \u0026 Defending AI Systems, MCP, RAG, AI Agents through AIGoat","description":"\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eName of Training:\u003c\/b\u003e Attacking \u0026amp; Defending AI Systems: MCP, RAG, AI Agents and Agentic Kill Chains through AIGoat \u003cbr\u003e\u003cb\u003eTrainer(s):\u003c\/b\u003e Nalinikanth Meesala, Farooq Mohammad \u003cbr\u003e\u003cb\u003eDates:\u003c\/b\u003e November 08 – 09, 2026 \u003cbr\u003e\u003cb\u003eTime:\u003c\/b\u003e 9:00 am – 5:00 pm \u003cbr\u003e\u003cb\u003eVenue:\u003c\/b\u003e Exhibition World Bahrain \u003cbr\u003e\u003cb\u003eCost:\u003c\/b\u003e 1200 BHD\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cspan style=\"color: rgb(224, 21, 21);\"\u003e\u003cstrong\u003eImportant Note:\u003c\/strong\u003e This training is exclusively available to \u003cstrong\u003egovernment entities and participants from GCC countries\u003c\/strong\u003e.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eEveryone is building with LLMs. Very few are asking, “How do we break this?”\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003ePrompt injection is trivially exploitable in most production AI systems. RAG pipelines leak context they were never supposed to expose. AI agents with tool access are a privilege escalation waiting to happen. Model Context Protocol is an attack surface most teams haven't even started thinking about. The vulnerability classes are real, the potential impact is significant, yet the industry is still largely operating without clear visibility into them.\u003cspan style=\"background: yellow; mso-highlight: yellow;\"\u003e\u003c\/span\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eThis is two days of fixing that.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eAIGoat is an open-source platform of deliberately vulnerable LLM pipelines, real prompt processing, real RAG, real tool-calling workflows, RAG, AI agents, all built to be broken. Every topic follows the same rhythm: exploit it, understand exactly why it works, then build and test the defense yourself. You will be attacking and defending real AI system architectures from the first hour.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003ePrompt Injection:\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e You bypass content restrictions and system instructions with plain-English prompts, covering direct and indirect techniques. Then you explore the defenses: examining strict prompt templates, input whitelists, and post-response filters, and immediately testing how well those mitigations hold up against the attacks.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eJailbreaking \u0026amp; Excessive Agency:\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e You force an AI assistant to violate its role and reach external systems it was never supposed to touch. Then you lock it down: capability isolation, output moderation APIs, retrieval-guard policies. You will see exactly how much the attack surface disappears when an agent is scoped correctly.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eRAG Pipeline Poisoning \u0026amp; Data Poisoning:\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e You inject malicious content into retrieval pipelines and fine-tuning data to manipulate model behavior. Then you implement the countermeasures, content moderation queues, trust scoring, segregated pipelines and verify they actually catch what you just did.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eSensitive Data \u0026amp; System Prompt Exfiltration:\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e You trigger hidden prompt leakage and secret exfiltration through debug modes and adversarial probing. Then you apply redaction, secrets store separation, and environment-specific access controls and probe \u003c\/span\u003ethe defenses to confirm they hold.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eAI Agent Exploitation:\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e Goal hijacking, tool misuse, identity and privilege abuse, agentic supply chain vulnerabilities. You work through each attack path against live agent architectures, then implement memory isolation and capability segmentation to contain the blast radius. You will leave understanding exactly how much damage a compromised agent can do and what it actually takes to limit it.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eMCP Exploitation:\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e Model Context Protocol is the newest and least-understood attack surface in AI systems. You will exploit it hands-on and understand the architectural patterns that constrain it.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eThreat Modeling for AIsystems (LLMs, RAG, MCP, Agents)\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e: Before chaining anything, you learn to predict chains. Most AI threat modeling stops at the component level STRIDE, MITRE ATLAS, MAESTRO which is precisely why chained compromise gets missed in review after review. You model the four boundaries that actually matter (context, retrieval, tool\/action, memory) and reason in paths rather than components, Then take the method back and apply those learnings to the AI solutions you’re building.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eThe Agentic Kill Chain.\u003c\/b\u003e This is the module that sets this course apart, drawn directly from our conference research on chained agentic compromise. You run a complete five-stage chain - \u003cb\u003e\u003cspan style=\"font-family: 'Arial Unicode MS'; mso-fareast-font-family: 'Arial Unicode MS'; mso-bidi-font-family: 'Arial Unicode MS';\"\u003eRecon → Poison → Hijack → Persist → Impact\u003c\/span\u003e\u003c\/b\u003e end to end against a live recruiting-copilot agent. A single uploaded document delivers indirect prompt injection, a poisoned MCP tool description, and a memory sleeper payload. The result is two separate breaches from one artifact: an immediate integrity failure, and a delayed confidentiality breach that fires on a scheduled job long after the attacker is gone. You then map the chain against OWASP Agentic AI Top 10 (ASI01–ASI10) and identify which single control breaks it.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eComposite chains across tenant boundaries.\u003c\/b\u003e The advanced extension: how isolation controls in multi-tenant agentic platforms fail \u003ci\u003ecompositionally\u003c\/i\u003e. Lateral movement through shared vector memory, agent-to-agent trust abuse, and persistent memory write-back where every individual boundary holds when tested alone, and the chain still gets through. You will learn the distinction between \u003cb\u003eboundary-independent\u003c\/b\u003e and \u003cb\u003eboundary-assuming\u003c\/b\u003e controls, and why most platform security reviews only test the latter.\u003cspan style=\"color: #212121;\"\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eWe close with a timed 8–10 challenge CTF where the techniques become targets. No walkthroughs, no safety net - just you, the attack surface, and the clock.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eYou leave with a forkable AIGoat lab, The AI Attack \u0026amp; Defense Playbook, a red-team checklist, kill-chain worksheet, and framework mappings. So that you can take the attacks home and start breaking, defending, and testing your own AI systems the week you get back.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cbr\u003e\u003c\/p\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: #212121;\"\u003eDay 1\u003c\/span\u003e\u003c\/h3\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_bg7wg7v6yqae\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: #212121;\"\u003e3.1 Welcome, Setup \u0026amp; AIGoat Onboarding\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eWorkshop goals, agenda, AIGoat account creation, environment health-check, sandbox access verified.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_nz3q9xi2g93s\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: #212121;\"\u003e3.2 LLM \u0026amp; AI Foundations \u003c\/span\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: black; background: yellow; mso-highlight: yellow;\"\u003e\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eHow LLMs differ from traditional applications from an attacker's perspective. Tokenization, context windows, system vs. user prompts, why deterministic security assumptions break down. Live demo of an LLM behaving unpredictably under adversarial input.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_ockbkwfyeros\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: black;\"\u003e3.3 Basics of RAG, AI Agents \u0026amp; Model Context Protocol (MCP)\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003eHow retrieval pipelines, tool-calling, and agent orchestration expand the attack surface. Live demo: agent calling an external API, MCP server interaction. \u003cspan style=\"background: yellow; mso-highlight: yellow;\"\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 115%; color: #212121;\"\u003e3.4 OWASP LLM Top 10: Mapped to Real Architectures\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eWalk through each category with a real-world breach scenario. Quick quiz to anchor the framework before labs begin.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; mso-pagination: widow-orphan; page-break-after: auto;\"\u003e\n\u003ca name=\"_wzhuh99gnc3w\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 115%; color: #212121;\"\u003e3.5 Threat Modeling AI Systems\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eThis module teaches you to model \u003cb\u003ehow an attacker moves across an AI system\u003c\/b\u003e, not just what can go wrong inside each component because traditional threat modeling can under-serve AI systems where behavior is non-deterministic, data can become instructions, trust boundaries shift at runtime, and the same artifact can act as both content and control flow.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo1; margin: 12.0pt 0in .0001pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eThink in attack paths, not isolated findings:\u003c\/b\u003e use STRIDE, MITRE ATLAS, and MAESTRO where they help, then connect findings across boundaries to uncover chained compromise.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo1; margin: 0in 0in 12.0pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eLab:\u003c\/b\u003e Threat-model a live AIGoat agent architecture. Map assets, attacker-controlled inputs, trust boundaries, and abuse paths; identify where one weakness can become the entry point for the next, then turn those paths into testable attack hypotheses.\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_47i0qikjfzk3\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: #212121;\"\u003e3.6 BREAK THE BOUNDARY\u003c\/span\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: black;\"\u003e\u003cbr\u003e\u003c\/span\u003e\u003cspan style=\"font-size: 11.0pt; line-height: 170%; color: black;\"\u003eCompromise what the AI sees, trusts, and depends on. \u003c\/span\u003e\n\u003c\/h3\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_j9wv52jim7do\"\u003e\u003c\/a\u003e\u003ci\u003e\u003cspan style=\"font-size: 11.0pt; line-height: 170%; color: black;\"\u003eLLM01 Prompt Injection, LLM04 Supply Chain, LLM08 Hidden Context Exposure \u003c\/span\u003e\u003c\/i\u003e\n\u003c\/h3\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_724p75ygyoda\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 11.0pt; line-height: 170%; color: black;\"\u003eLearn how attackers establish influence over an AI system by compromising its dependencies, manipulating retrieval, injecting instructions, and exposing hidden context. The focus is on finding the boundaries where data becomes instructions, trusted content becomes attacker-controlled content, and one weakness becomes the entry point for the next.\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_69fst14m5xes\"\u003e\u003c\/a\u003e\u003cb\u003e\u003cspan style=\"font-size: 11.0pt; line-height: 170%; color: black;\"\u003eAttack:\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"font-size: 11.0pt; line-height: 170%; color: black;\"\u003e Attack the AI's supply chain, vector and retrieval layer, prompt\/context boundary, and hidden application context. Chain supply-chain compromise, RAG manipulation, prompt injection, and context extraction to establish a foothold and uncover the system's capabilities and trust boundaries.\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_j3jw31h507fk\"\u003e\u003c\/a\u003e\u003cb\u003e\u003cspan style=\"font-size: 11.0pt; line-height: 170%; color: black;\"\u003eDefend:\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"font-size: 11.0pt; line-height: 170%; color: black;\"\u003e Explore provenance and integrity controls, retrieval isolation, content and instruction separation, context minimization, authorization boundaries, and trust controls. Re-run the attack paths to understand which defenses break the chain and where attackers can move around them.\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\"\u003e \u003c\/p\u003e\n\u003ch2 style=\"margin-bottom: 4.0pt; mso-pagination: widow-orphan; page-break-after: auto;\"\u003e\n\u003ca name=\"_xr3y3vrsds33\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 115%; color: #212121;\"\u003e3.7 CORRUPT THE MIND: Data, Model \u0026amp; RAG systems\u003c\/span\u003e\u003cb\u003e\u003cspan style=\"font-size: 17.0pt; line-height: 115%;\"\u003e\u003c\/span\u003e\u003c\/b\u003e\n\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-top: 14.0pt;\"\u003e\u003cspan style=\"color: black;\"\u003eManipulate what the AI knows, believes, and reveals. \u003cbr\u003e\u003c\/span\u003e\u003ci\u003eLLM02 Sensitive Information Disclosure, LLM05 Data \u0026amp; Model Poisoning, LLM07 Misinformation, LLM09 Vector \u0026amp; Embedding Weaknesses.\u003c\/i\u003e\u003cbr\u003e\u003cbr\u003eExplore what happens after an attacker gains influence: corrupt the information the AI relies on, make it produce misleading results, or extract information it should never reveal. Learn how poisoning, misinformation, and disclosure can reinforce each other across RAG, memory, and multi-step AI workflows.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eAttack: \u003c\/b\u003ePoison knowledge sources and persistent data, manipulate model outputs, induce false or misleading decisions, and extract sensitive information from prompts, context, retrieval, memory, and responses. Chain these weaknesses to turn a seemingly harmless manipulation into persistent compromise or data exposure.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eDefend: \u003c\/b\u003eExplore data provenance, retrieval authorization, validation, grounding, evidence verification, output controls, data minimization, and memory isolation. Re-test the same attack chains to understand whether the defenses prevent corruption, limit disclosure, or merely contain the impact.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e \u003c\/p\u003e\n\u003ch2 style=\"margin-bottom: 4.0pt; mso-pagination: widow-orphan; page-break-after: auto; border: none; mso-padding-alt: 31.0pt 31.0pt 31.0pt 31.0pt; mso-border-shadow: yes;\"\u003e\n\u003ca name=\"_jy8u0vax1yaw\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 115%; color: #212121;\"\u003e3.8 WEAPONIZE THE ACTION\u003c\/span\u003e\n\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-top: 14.0pt;\"\u003e\u003ci\u003e\u003cspan style=\"color: black;\"\u003eTurn AI influence into real-world impact.\u003cb\u003e \u003c\/b\u003e\u003c\/span\u003e\u003c\/i\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-top: 14.0pt;\"\u003eLLM03 Excessive Agency, LLM06 Unbounded Consumption, LLM10 Improper Output Handling\u003cbr\u003e\u003cb\u003e\u003cbr\u003e\u003c\/b\u003eMove from compromising the model to compromising what the system can do. Explore how excessive permissions, unsafe tool use, unvalidated model output, and uncontrolled resource consumption allow an attacker to turn AI influence into actions against real systems.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eAttack: \u003c\/b\u003eChain prompt injection or misinformation into tool invocation, privilege abuse, unsafe downstream execution, MCP interactions, code execution, data exfiltration, or resource exhaustion. Follow the attack across the AI's tool, identity, and downstream system boundaries.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eDefend: \u003c\/b\u003eExplore least-privilege capabilities, tool and identity isolation, scoped authorization, approval gates, output validation, execution boundaries, rate limits, circuit breakers, and runtime controls. Re-run the attack chains to determine whether the defenses stop the action, contain the blast radius, or simply move the attack to the next boundary.\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_5bdjpsrnkhvb\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: #212121;\"\u003e3.9 Wrap-Up \u0026amp; Q\u0026amp;A\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003e3.9.1\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e Recap the attacker methodology built so far.\u003cbr\u003e\u003cb\u003e3.9.2\u003c\/b\u003e Preview Day 2's deeper attack surfaces. \u003cbr\u003e\u003cb\u003e3.9.3 \u003c\/b\u003eOpen Q\u0026amp;A.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch3\u003eDay 2\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-top: 14.0pt; line-height: 170%; background: white;\"\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%;\"\u003e3.10 Day 1 Recap \u003cbr\u003e\u003c\/span\u003eQuick group exercise: threat-model an AI agentic feature using only what you learned yesterday. Sets the lens for Day 2's deeper attack surfaces.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e \u003c\/p\u003e\n\u003ch2 style=\"margin-bottom: 4.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_y4ijjwvsz5ei\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%;\"\u003e3.11 Attack \u0026amp; Defend: MCP Systems\u003c\/span\u003e\u003cspan style=\"background: #FF9900;\"\u003e\u003c\/span\u003e\n\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003eExplore MCP as the bridge between an AI model and the systems it can act upon. Learn how seemingly trusted tools, tool descriptions, parameters and MCP servers can become attack surfaces turning model influence into unauthorized actions.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eAttack: \u003c\/b\u003eMCP tool poisoning, malicious tool descriptions, indirect prompt injection through MCP, tool parameter manipulation, unauthorized tool invocation, excessive tool permissions, MCP server impersonation, malicious third-party packages, cross-tool attacks, and tool-call flooding. Chain untrusted content through MCP into privileged downstream actions.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eDefend: \u003c\/b\u003eExplore MCP server and tool provenance, tool allowlisting, capability restrictions, authentication and authorization, parameter validation, least-privilege identities, approval gates, tool-call limits and runtime monitoring. Re-run the attacks to test whether the controls actually prevent the tool from becoming the attacker's bridge into the system.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e \u003c\/p\u003e\n\u003ch2 style=\"margin-bottom: 4.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_4izo8ovq0ucd\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%;\"\u003e3.12 Attack \u0026amp; Defend: Hijacking AI Agents\u003c\/span\u003e\u003cb\u003e\u003cspan style=\"font-size: 17.0pt; line-height: 170%;\"\u003e\u003c\/span\u003e\u003c\/b\u003e\n\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003eASI01 Agent Goal Hijack, ASI06 Memory \u0026amp; Context Poisoning, ASI07 Insecure Inter-Agent Communication, ASI09 Human-Agent Trust Exploitation, ASI10 Rogue Agents\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003eExplore how attackers manipulate an agent's \u003cb\u003egoals, context, memory and decisions\u003c\/b\u003e. Learn how indirect instructions, poisoned memory, hidden context and compromised agent-to-agent communication can gradually move an agent away from its intended objective.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eAttack: \u003c\/b\u003eAgent goal hijacking, indirect prompt injection, memory and context poisoning, hidden-context extraction, false or manipulated information, inter-agent instruction manipulation, persistent attacks and rogue-agent behavior. Chain seemingly low-impact manipulations across context and memory to influence future decisions.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eDefend: \u003c\/b\u003eExplore context isolation, memory-write controls, instruction hierarchy, provenance, agent identity, inter-agent trust boundaries, behavioral monitoring and human verification. Re-run the attack chains to understand where the agent can be brought back within its intended boundaries.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e \u003c\/p\u003e\n\u003ch2 style=\"margin-bottom: 4.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_br7220z536jz\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%;\"\u003e3.13 Attack \u0026amp; Defend: Weaponizing AI Agents\u003c\/span\u003e\n\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003eASI02 Tool Misuse \u0026amp; Exploitation, ASI03 Identity \u0026amp; Privilege Abuse, ASI05 Unexpected Code Execution, ASI08 Cascading Failures, ASI09 Human-Agent Trust Exploitation\u003cbr\u003e\u003cb\u003e\u003cbr\u003e\u003c\/b\u003eOnce an attacker controls an agent's behavior, the next question is \u003cb\u003ewhat can the agent actually do?\u003c\/b\u003e Explore how tools, identities, permissions and autonomous actions can turn a manipulated agent into a pathway to real-world impact.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eAttack: \u003c\/b\u003eTool misuse, excessive permissions, identity and privilege abuse, MCP tool exploitation, unsafe output reaching downstream systems, command execution, unauthorized actions, recursive tool calls, resource exhaustion and cascading failures.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"line-height: 170%; background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eDefend: \u003c\/b\u003eExplore least-privilege capabilities, scoped identities, tool isolation, authorization boundaries, output validation, execution sandboxes, approval gates, action limits, circuit breakers and runtime monitoring. Re-run the same attack chains to determine whether the controls stop the action or merely move the attacker to another capability.\u003cspan style=\"color: #212121;\"\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_25a5ns5m3s0c\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 115%; color: black;\"\u003e3.14 The Agentic Kill Chain - Break the Chain\u003c\/span\u003e\u003cb\u003e\u003cspan style=\"font-size: 13.0pt; line-height: 115%; color: #212121;\"\u003e\u003c\/span\u003e\u003c\/b\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003ci\u003e\u003cspan style=\"color: #212121;\"\u003eMaps: ASI01–ASI10 + MITRE ATLAS\u003c\/span\u003e\u003c\/i\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cspan style=\"color: #212121;\"\u003eForget isolated vulnerabilities. \u003cb\u003eAttackers don't stop at the first finding. They chain them.\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cspan style=\"color: #212121;\"\u003eThe Agentic Kill Chain compresses the traditional cyber kill chain into five stages:\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003e\u003cspan style=\"font-family: 'Arial Unicode MS'; mso-fareast-font-family: 'Arial Unicode MS'; mso-bidi-font-family: 'Arial Unicode MS'; color: #212121;\"\u003eRECON → POISON → HIJACK → PERSIST → IMPACT\u003c\/span\u003e\u003cspan style=\"color: #212121;\"\u003e\u003c\/span\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cspan style=\"color: #212121;\"\u003eYou’ll learn how a single malicious artifact can move through an agent's context, memory, tools and trust boundaries - and how \u003cb\u003ebreaking just one link can break the entire attack\u003c\/b\u003e.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cspan style=\"color: #212121;\"\u003eEach stage maps to the relevant ASI categories and MITRE ATLAS techniques, giving you a common language for describing agentic attacks, assessing them, and reporting them inside your organization.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\"\u003e \u003c\/p\u003e\n\u003ch2 style=\"margin-bottom: 4.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_ejv6vc4ch5g3\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: black;\"\u003e3.1\u003c\/span\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%;\"\u003e5\u003cspan style=\"color: black;\"\u003e Full Chain Lab\u003c\/span\u003e - \u003cspan style=\"color: black;\"\u003eBreak an Agent, Then Break the Chain\u003c\/span\u003e\u003c\/span\u003e\u003cb\u003e\u003cspan style=\"font-size: 13.0pt; line-height: 170%; color: #212121;\"\u003e\u003c\/span\u003e\u003c\/b\u003e\n\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003ci\u003e\u003cspan style=\"color: #212121;\"\u003eMaps: ASI01, ASI02, ASI04, ASI06, ASI09\u003c\/span\u003e\u003c\/i\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eThis is where everything comes together.\u003c\/span\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cspan style=\"color: #212121;\"\u003eYou get a live recruiting copilot with résumé ingestion, an MCP-connected enrichment tool, and persistent candidate memory.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eRecon\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e - Find the agent's tools, memory boundaries and scheduled jobs.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003ePoison\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e - Plant an indirect prompt injection in a résumé and compromise the agent through a poisoned MCP tool description.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eHijack\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e - Turn the agent against its own ranking logic and trigger a visible integrity failure.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003ePersist\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e - Plant a sleeper payload in memory that survives the session.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003e\u003cspan style=\"color: #212121;\"\u003eImpact\u003c\/span\u003e\u003c\/b\u003e\u003cspan style=\"color: #212121;\"\u003e - Trigger the scheduled digest and watch the attack reach the candidate database \u003cb\u003elong after the original attacker is gone.\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cspan style=\"color: #212121;\"\u003eThen switch sides.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"background: white; margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cspan style=\"color: #212121;\"\u003eRun the chain again with defenses enabled - \u003cb\u003eone control at a time\u003c\/b\u003e - and discover which control actually breaks the chain, which only slows it down, and which \u003ci\u003elooks\u003c\/i\u003e protective but changes nothing.\u003cspan style=\"background: yellow; mso-highlight: yellow;\"\u003e\u003c\/span\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_86trmfgdvfrw\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: #212121;\"\u003e3.16 CTF Briefing\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eRules, scoring, challenge categories.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eTake off the gloves: 8 –10 timed challenges, spanning the OWASP LLM Top 10, RAG, MCP and agents. Attack. Chain it. Beat the clock. Climb the live scoreboard.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; line-height: 170%; mso-pagination: widow-orphan; page-break-after: auto; background: white;\"\u003e\n\u003ca name=\"_40qgstctlm28\"\u003e\u003c\/a\u003e\u003cspan style=\"font-size: 14.5pt; line-height: 170%; color: #212121;\"\u003e3.17 Awards, Takeaways \u0026amp; Wrap-Up\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-bottom: 12.0pt; background: white;\"\u003e\u003cspan style=\"color: #212121;\"\u003eWalk through winning solutions, highlight novel approaches. Distribute the Guardrail Playbook and Red-Team Checklist. AIGoat access details. Open Q\u0026amp;A and closing.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eIntermediate\u003c\/b\u003e - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eNo AI security or ML background is required. Day 1 opens with a ground-up primer on LLMs, RAG, agents, and MCP. If you have done web application penetration testing or application security work and can read code, you will be exactly where you need to be.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eStudents should be comfortable with:\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo2; margin: 12.0pt 0in .0001pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eWeb application fundamentals:\u003c\/b\u003e HTTP, REST APIs, JSON payloads\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l0 level1 lfo2;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eA terminal:\u003c\/b\u003e running Docker, executing scripts, basic Linux commands\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo2; margin: 0in 0in 12.0pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eReading Python:\u003c\/b\u003e you will modify short scripts (10–40 lines), not write from scratch\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eOptional pre-work (~1 hour):\u003c\/b\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l1 level1 lfo1; margin: 12.0pt 0in .0001pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003eSkim the OWASP Top 10 for Large Language Model Applications:\u003ca href=\"https:\/\/owasp.org\/www-project-top-10-for-large-language-model-applications\/\"\u003e\u003cspan style=\"color: windowtext; text-decoration: none; text-underline: none;\"\u003e \u003c\/span\u003e\u003c\/a\u003e\u003ca href=\"https:\/\/owasp.org\/www-project-top-10-for-large-language-model-applications\/\"\u003e\u003cspan style=\"color: #1155cc;\"\u003ehttps:\/\/owasp.org\/www-project-top-10-for-large-language-model-applications\/\u003c\/span\u003e\u003c\/a\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l1 level1 lfo1; margin: 0in 0in 12.0pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003eClone and skim AIGoat:\u003ca href=\"https:\/\/github.com\/AISecurityConsortium\/AIGoat\"\u003e\u003cspan style=\"color: windowtext; text-decoration: none; text-underline: none;\"\u003e \u003c\/span\u003e\u003c\/a\u003e\u003ca href=\"https:\/\/github.com\/AISecurityConsortium\/AIGoat\"\u003e\u003cspan style=\"color: #1155cc;\"\u003ehttps:\/\/github.com\/AISecurityConsortium\/AIGoat\u003c\/span\u003e\u003c\/a\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cspan style=\"font-size: 11.0pt; line-height: 115%; font-family: 'Arial',sans-serif; mso-fareast-font-family: Arial; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;\"\u003eThat is genuinely all. Everything else is taught from the ground up.\u003c\/span\u003e\u003c\/p\u003e\n\u003ch2 style=\"margin-bottom: 4.0pt; mso-pagination: widow-orphan; page-break-after: auto;\"\u003e\n\u003cspan style=\"font-size: 16.5pt; line-height: 115%; color: #212121;\"\u003e6. What Students Should Bring\u003c\/span\u003e\u003cb\u003e\u003cspan style=\"font-size: 17.0pt; line-height: 115%;\"\u003e\u003c\/span\u003e\u003c\/b\u003e\n\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo1; margin: 12.0pt 0in .0001pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003eLaptop running Windows 10\/11, macOS 12+, or a recent Linux distribution\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l0 level1 lfo1;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e8 GB RAM minimum (16 GB recommended)\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l0 level1 lfo1;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e20 GB free disk space\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l0 level1 lfo1;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003eModern web browser (Chrome or Firefox)\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l0 level1 lfo1;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003eAbility to install a small set of free tools listed in pre-work (terminal client, code editor)\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo1; margin: 0in 0in 12.0pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003eInternet access - the labs are cloud-hosted, and all heavy compute runs in the instructor-provided environment. No local GPU or local model required.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eNote on corporate devices:\u003c\/b\u003e students must be able to reach the cloud lab. Corporate-locked laptops that block outbound traffic to non-approved domains may not work. If in doubt, bring a personal device.\u003c\/p\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eParticipants leave with a practical \u003cb\u003eAI Attack \u0026amp; Defense Toolkit\u003c\/b\u003e they can take back and apply to their own AI solutions:\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l1 level1 lfo2; margin: 12.0pt 0in .0001pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003eCertification of participation verifiable on \u003ca href=\"https:\/\/aigoat.co.in\/\"\u003e\u003cspan style=\"color: #1155cc;\"\u003ehttps:\/\/aigoat.co.in\/\u003c\/span\u003e\u003c\/a\u003e\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l1 level1 lfo2;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eSlides + Reading List\u003c\/b\u003e - course material and curated resources for continuing the learning journey.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l1 level1 lfo2;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eWorkshop Playbook\u003c\/b\u003e - Documentation of the two day workshop activities and exercises\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l1 level1 lfo2;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eForkable AIGoat Lab\u003c\/b\u003e - the complete hands-on environment to continue experimenting after the training.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l1 level1 lfo2;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eAI Attack \u0026amp; Defense Playbook\u003c\/b\u003e - practical attack patterns, defensive approaches, and re-test guidance across LLMs, RAG, MCP and Agents.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l1 level1 lfo2;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eRed-Team Checklist\u003c\/b\u003e - a repeatable checklist for assessing AI applications and identifying attack paths.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin-left: .5in; text-indent: -.25in; mso-list: l1 level1 lfo2;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eKill Chain Worksheet\u003c\/b\u003e - map individual findings into end-to-end attack chains across context, retrieval, memory, tools and agents.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"text-indent: -.25in; mso-list: l0 level1 lfo1; margin: 0in 0in 12.0pt .5in;\"\u003e\u003c!-- [if !supportLists]--\u003e\u003cspan style=\"mso-bidi-font-weight: bold;\"\u003e\u003cspan style=\"mso-list: Ignore;\"\u003e●\u003cspan style=\"font: 7.0pt 'Times New Roman';\"\u003e      \u003c\/span\u003e\u003c\/span\u003e\u003c\/span\u003e\u003c!--[endif]--\u003e\u003cspan dir=\"LTR\"\u003e\u003c\/span\u003e\u003cb\u003eThreat modelling Workbook \u003c\/b\u003e- a template to perform threat modelling for AI systems\u003cb\u003e\u003c\/b\u003e\u003c\/p\u003e\n\u003ch2\u003e7. Trainer(s) Bio\u003c\/h2\u003e\n\u003ch3 style=\"margin-top: 14.0pt; mso-pagination: widow-orphan; page-break-after: auto;\"\u003e\u003cb\u003e\u003cspan style=\"font-size: 13.0pt; line-height: 115%; color: black;\"\u003eNalinikanth Meesala\u003c\/span\u003e\u003c\/b\u003e\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eNalinikanth Meesala is Head of Security, AI Products at Thoughtworks and co-creator of AIGoat, an open-source deliberately vulnerable AI system. With over 13 years in cybersecurity and product security engineering, his work centres on AI security, adversarial testing, and secure architecture for AI-driven systems.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eHis research targets attack surfaces unique to modern AI systems: prompt injection, RAG poisoning, Model Context Protocol exploitation, AI agent abuse, and AI supply-chain vulnerabilities. His current work on composite kill chains examines how isolation controls in multi-tenant agentic AI platforms fail when an attacker pivots across multiple trust boundaries in sequence - research presented at Black Hat and derived from a comparative security review of thirteen production and open-source agentic platforms.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eHe has delivered talks and hands-on training at DEF CON Training Middle East, Black Hat, XConf, Seasides, SecConf, OWASP meetups, and null community chapters, focusing on helping engineers and security professionals understand how to exploit modern AI systems and how to build them securely.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eWhen he is not breaking AI systems (ethically), he enjoys painting and sport, bringing the same curiosity and creativity into both art and cybersecurity.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eLinkedIn:\u003c\/b\u003e\u003ca href=\"https:\/\/www.linkedin.com\/in\/nalinikanth-m\/\"\u003e\u003cspan style=\"color: windowtext; text-decoration: none; text-underline: none;\"\u003e \u003c\/span\u003e\u003c\/a\u003e\u003ca href=\"https:\/\/www.linkedin.com\/in\/nalinikanth-m\/\"\u003e\u003cspan style=\"color: #1155cc;\"\u003ehttps:\/\/www.linkedin.com\/in\/nalinikanth-m\/\u003c\/span\u003e\u003c\/a\u003e\u003cu\u003e\u003cspan style=\"color: #1155cc;\"\u003e\u003c\/span\u003e\u003c\/u\u003e\u003c\/p\u003e\n\u003ch3 style=\"margin-top: 14.0pt; mso-pagination: widow-orphan; page-break-after: auto;\"\u003e\n\u003ca name=\"_drb9odb4u636\"\u003e\u003c\/a\u003e\u003cb\u003e\u003cspan style=\"font-size: 13.0pt; line-height: 115%; color: black;\"\u003eFarooq Mohammad\u003c\/span\u003e\u003c\/b\u003e\n\u003c\/h3\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eFarooq Mohammad is a security researcher and practitioner focused on securing modern applications and emerging AI-powered systems, and co-creator of AIGoat. His work spans application security, threat modelling, DevSecOps, and cloud security, with a sharp and growing focus on identifying and mitigating risk in LLM-based applications and AI-driven platforms. He works closely with engineering teams to embed security into the design and development of modern systems.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eIn recent years, Farooq has researched the attack surfaces introduced by AI systems - prompt injection, model jailbreaks, data exfiltration, RAG pipeline manipulation, and vulnerabilities in AI agents and tool integrations. He is particularly interested in practical AI red teaming and in translating offensive testing insight into defensive engineering patterns teams can actually adopt.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003eHe has delivered AI security workshops at the Seasides Conference and talks at XConf, SecConf, OWASP meetups, and null community chapters. Outside security research he enjoys cooking and travelling, bringing the same curiosity to both.\u003c\/p\u003e\n\u003cp class=\"MsoNormal\" style=\"margin: 12.0pt 0in 12.0pt 0in;\"\u003e\u003cb\u003eLinkedIn:\u003c\/b\u003e \u003ca href=\"https:\/\/www.linkedin.com\/in\/farooqmohammad\/\"\u003e\u003cspan style=\"color: #1155cc;\"\u003ehttps:\/\/www.linkedin.com\/in\/farooqmohammad\/\u003c\/span\u003e\u003c\/a\u003e\u003c\/p\u003e\n\u003ch2\u003e8. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e8.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e8.8\u003c\/strong\u003e \u003cspan\u003eBy purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49908106690803,"sku":null,"price":1200.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/Nalinikanth.png?v=1786917638","url":"https:\/\/me.shop.defcon.org\/products\/attacking-defending-ai-systems-mcp-rag-ai-agents-through-aigoat","provider":"DEF CON MIDDLE EAST","version":"1.0","type":"link"}