Adversary Intelligence: LLM Tradecraft
AI capability development and adoption are outpacing security teams’ ability to evaluate and secure these systems. Practitioners who understand how LLMs work, where they fail, and how adversaries use them are better positioned to apply AI effectively and defend the systems built around it. This course builds that technical foundation through LLM fundamentals, agent architecture, evaluation, threat modeling, offensive LLM tradecraft, and AI-assisted reverse engineering.
Cohort-style learning
This course is delivered in a cohort-style learning format. Before checkout, you will choose a 30-day window to register for. Access will begin on the start date, and you will be free to learn at your own pace throughout those 30 days until access expires.
Information list
Don't see a cohort that works for you? Visit the course webpage to sign up for updates on future cohorts, or cohort expansions for sold-out dates.
Dig into LLM tradecraft
An attacker perspective is woven throughout. Participants learn how adversaries are using and exploiting AI systems through prompt injection, jailbreaks, and weaknesses in AI infrastructure including insecure MCP configurations and overprivileged agent identities. Defensive patterns are addressed at the input, output, and infrastructure levels. Observability and evaluation methods are integrated across the course, giving participants tools to assess model behavior and measure the reliability of systems they build or inherit.
Labs run throughout every module using Codex and other leading AI technologies, covering agentic system development, threat modeling, reverse engineering and defensive security workflows. Participants leave with the technical depth to evaluate AI systems critically, hands-on experience applying leading AI technologies to real security workflows, and practical skills for assessing and securing agentic systems in real enterprise environments.
Participants will learn
- How to build and evaluate LLMs and agentic systems, including their architecture, limitations, and security implications in real enterprise environments
- How to identify and understand attacker techniques targeting LLMs and agentic systems, including prompt injection, jailbreaks, and exploitable weaknesses in AI infrastructure and agent design
- How to apply AI to defensive security workflows, including threat modeling, security testing, and AI-assisted reverse engineering using leading AI technologies
Course topics
- AI foundations and the evolution of machine learning, deep learning, and LLMs
- Tokenization, embeddings, attention mechanisms, context windows, and architectural limitations
- Prompting strategies and prompt-as-program design
- Agent architecture, tool calling, memory, MCP servers, and multi-agent coordination
- Coding agents and Codex workflows
- LLM observability and evaluation
- Threat modeling for LLM systems
- Jailbreaks, prompt injection, prompt leakage, instruction smuggling, and defensive patterns
- Attacking and securing AI infrastructure
- AI-assisted reverse engineering workflows
Who should take this course?
This course is intended for security practitioners, researchers, engineers, defenders, and technical leaders who need to understand how modern LLMs and agentic systems work, how adversaries target them, and how to evaluate and secure AI-enabled workflows in enterprise environments.
Prerequisites
Participants should be comfortable with technical security concepts and basic command-line workflows. Prior LLM security experience is not required, though familiarity with programming, security testing, threat modeling, or reverse engineering will help participants get the most from the labs.
About the course authors
Will Schroeder (@harmj0y) is a principal security researcher at SpecterOps and a longtime contributor to offensive security research and training. He has presented at major security conferences for more than a decade and has co-developed and taught Black Hat training courses, including Adversary Tactics: Red Team Operations. His research and open-source work includes the Veil-Framework, GhostPack, Empire/EmPyre, Nemesis, BloodHound, and the Certified Pre-Owned Active Directory Certificate Services whitepaper.
Lee Chagolla-Christensen (@tifkin_) is a principal security researcher at SpecterOps, where he researches and develops offensive techniques and capabilities. His work spans offensive AI, Windows and Active Directory, application security, and the systems that connect them. Lee’s research has resulted in multiple CVEs and new offensive tradecraft used across the industry, and he has contributed to open-source projects including BloodHound, Nemesis, GhostPack, SpoolSample, UnmanagedPowerShell, and KeeThief.