● HANDS-ON AI AppSec WORKSHOP
Move beyond basic prompt injection. Learn to identify, exploit, and mitigate critical vulnerabilities across the entire AI application lifecycle, from simple wrappers, RAG systems and autonomous agents to insecure output handling in an intensive 2-day hands-on AI security workshop.
This training is delivered through custom-built labs utilizing a dedicated lab environment to support intensive, hands-on exploitation of AI-integrated applications.
Across two intensive 5-hour sessions, you will adopt the attacker’s mindset to dismantle AI-driven architectures. You will work hands-on with real-world scenarios, exploiting Large Language Models (LLMs), bypassing safety filters, and hijacking autonomous agents to understand how to build truly resilient AI implementations.
● WHAT YOU’LL DO
Map Active Directory attack paths using BloodHound, LDAP enumeration, and graph-based analysis techniques.
Perform Kerberoasting, delegation abuse, ticket attacks, and credential-focused Active Directory exploitation techniques.
Identify and exploit common certificate-based attack paths including ESC1 and ESC8 misconfigurations.
Analyze permissions, object relationships, and privilege escalation opportunities hidden within Active Directory.
Investigate attack activity through Windows Event Logs, Wazuh detections, and network telemetry.
Validate defensive controls, identify detection gaps, and prioritize remediation actions that reduce attacker pathways.
● AGENDA
Attacking the Model & Data Layers
→ Introduction to AI AppSec & the LLM Threat Landscape
→ Direct vs. Indirect Prompt Injection
→ Advanced Jailbreaking & Bypassing Safety Filters
→ Training Data & RAG Context Poisoning
→ Lab: Breaking Model Alignment & Exploiting Insecure RAG
Exploiting Integrations & Autonomous Agents
→ Hijacking Autonomous Agents & Tool-Calling
→ Insecure Output Handling: AI-driven XSS and SSRF
→ Supply Chain Vulnerabilities & Insecure Plugins
→ OWASP Top 10 for LLMs: Defense-in-Depth for AI
→ Final Lab: Chaining AI exploits for full system compromise
● INSTRUCTORS

Veteran security leader and Founder of Grafos AI, the safe and secure AI agent platform that automates Infrastructure as Code (IaC) editing for developers. A leading voice in Agentic AI Security and a key contributor to the OWASP AI Exchange, Spyros specializes in deploying autonomous systems that enhance developer velocity without compromising architectural integrity. With nearly two decades of experience ranging from hands-on engineering to the CISO’s office, he is a frequent speaker at global stages like DEF CON and QCon, where he translates complex security theory into pragmatic, automated workflows.
● WHAT YOU’LL GAIN
→ Exploitation Mastery: Ability to perform complex multi-stage attacks on LLM-powered applications.
→ Architectural Insight: Deep understanding of how RAG and Agents introduce new attack vectors.
→ Strategic Defense: Practical skills to mitigate most attacks and build defence in depth auto-recovery and notification.
→ Adversarial Mindset: Expertise in red teaming stochastic systems to identify “unforeseeable” failure modes.
● REQUIREMENTS & PREREQUISITES
→ Technical Proficiency: Basic understanding of Python and Web AppSec (OWASP Top 10) fundamentals.
→ Tooling: Familiarity with API interaction tools (e.g., Postman, cURL) and basic command-line usage.
● BOOK YOUR SEAT
Join us for two days of hands-on AI security exploitation.
Syllabus:
Intro to GCP
Exploitation of GCP Services
Methodologies
Security Services
Syllabus:
Intro to AWS
Exploitation of AWS Services
Methologies
Common Detection Mechanisms
Syllabus:
Azure Basics
Exploitation of Azure Services
Methologies
Common Detection Mechanisms
Fundamentals and Setup
Advanced Techniques and Practical Application
Advanced Techniques and Practical Application
Fundamentals & Setup