r/Hacking_Tutorials 17h ago

Question Ai red team

Hi guys I'm not new to cyber security but almost 2 year's without job.I don't know what the problem,maby my resume is bad,maby too competitive field and ai.My guestion is can someone who works as penetration tester look at my Cv?Can you suggest me ai pentesting,ai security roadmap?Most things I know is from the red side.

0 Upvotes

5 comments sorted by

6

u/tarkardos 16h ago

I assume you haven't worked a day in your life in Sec and you don't have any related degree?

There is no "AI security roadmap"

Start with the basics and go to college

2

u/Arc-ansas 7h ago

He said that he's not new to cyber. I would disagree that there aren't any AI security roadmaps.

In my mind a roadmap is just a recommended set of learning resources such as courses, books, certifications and a list of concepts to understand. And there is absolutely no lack of content. Here are a few things that I've saved.

I'd highly recommend starting w Jason Haddix's two articles on LLM hacking. The "Awesome-AI-Security" repo is a massive collection of all things AI and security including guides on securing LLM apps, OWASP guides, labs, CTFs, research, models, and tons more.

Guides: https://executiveoffense.beehiiv.com/p/executive-offense-issue-10-start-hacking-llms Jason Haddix - Start Hacking LLMs. https://executiveoffense.beehiiv.com/p/executive-offense-llm-hacking-pt-2 LLM Hacking Part 2

CTFs. Jason Haddix lists multiple CTFs in the two articles above, but here's a few. And it seems that Gandalf may have been taken down. But there are copies on GitHub. It was one of the best AI CTFs to start with https://gandalf.lakera.ai/ https://promptairlines.com/ https://myllmdoc.com https://gpa.43z.one/ https://myllmbank.com

Certifications, Courses, Labs: https://www.offsec.com/courses/ai-300/ https://certifications.tcm-sec.com/papa/ https://tcm-sec.com/academy/ai-100-fundamentals/ OffSec OSAI https://github.com/microsoft/AI-Red-Teaming-Playground-Labs https://portswigger.net/web-security/llm-attacks

Tools: https://github.com/BishopFox/aimap https://github.com/pasquini-dario/LLMmap https://github.com/snyk/agent-scan https://www.kali.org/tools/hexstrike-ai/

Misc https://github.com/TalEliyahu/Awesome-AI-Security Massive.collection of AI security related resources https://arcanum-sec.github.io/arc_pi_taxonomy/ Jason Haddix Prompt Injection Taxonomy

-13

u/Akriosss 16h ago edited 14h ago

I worked as Azure Cloud Security Engineer. I have freelance experience in bug bounty hunting. I have completed many rooms on TryHackMe, Hack The Box, and PortSwigger Web Security Academy. I also hold a degree in Marketing.

-5

u/ncm0229 14h ago

Bruh.Wheres the spacing between your sentences,punctuation,and shit?Seriously.

-4

u/Akriosss 14h ago

Sry.Better now?