Advanced AI Red Teaming AI-300 (OSAI) Training
Applied Technology Academy is a premier provider of OffSec's newest certification, OSAI — hands-on offensive operations in AI environments. The AI-300 (OSAI) brings OffSec's offensive methodology to AI, with advanced red teaming for large language models and multi-agent systems.
Course Overview
The AI-300 (OSAI) is an enterprise-grade, hands-on offensive AI red teaming certification that proves your team can pressure-test LLMs and agent systems under realistic conditions. It is designed to develop practitioners who can think like adversaries in AI environments and keep pace as the threat landscape evolves. Core focus areas include offensive testing of LLMs and multi-agent systems; RAG compromise and control-surface abuse; AI supply-chain and infrastructure exploits; and post-exploitation with impact analysis that turns findings into real improvement. The certification culminates in a rigorous 48-hour exam built to validate real-world adaptability against novel AI attack surfaces.
Course Outline
- OSAI is delivered as modular, self-paced online training, with instructor-led training available. Eleven lab-driven modules:
- Module 1: Introduction to Red Teaming AI Systems
- How artificial intelligence systems change the traditional attack surface: the core concepts of AI cybersecurity, how adversaries target AI-enabled environments, and where AI attacks sit in the red team lifecycle.
- Module 2: Reconnaissance for AI Targets
- Identify and map AI applications, machine learning components and model infrastructure inside a target environment, discovering AI assets, dependencies and exposed services without alerting defenders.
- Module 3: Attacking AI Agents
- Manipulate AI agents by abusing prompt instructions, memory systems and tool integrations, influencing autonomous AI applications while maintaining stealth.
- Module 4: Attacking Multi-Agent Systems and A2A Protocols The architecture of multi-agent AI systems, and how adversaries exploit trust relationships between agents - message manipulation, agent impersonation and workflow corruption.
- Module 5: Exploiting RAG Pipelines
- How attackers compromise retrieval-augmented generation systems by poisoning knowledge sources and manipulating retrieval layers to control model outputs.
- Module 6: Attacking Embeddings The role of embeddings in machine learning systems, with attacks such as embedding inversion and information extraction to recover sensitive data from AI models.
- Module 7: Attacking Model Context Protocol and Tool Surfaces
- How orchestration layers and AI tool-integration frameworks can be abused to escalate privileges or execute unintended actions within AI systems.
- Module 8: Supply Chain Attacks on AI/ML Systems
- Targeting the AI supply chain - datasets, model weights, adapters and dependencies - and the techniques used to introduce malicious artifacts before deployment.
- Module 9: AI Infrastructure and Deployment Exploits
- Vulnerabilities in AI infrastructure, including cloud AI platforms, model servers and containerized machine learning workloads.
- Module 10: Threat Modeling for AI-Enabled Targets
- Identifying high-value AI assets, trust boundaries and potential attack paths across complex AI environments.
- Module 11: Assembling the Pieces - Capstone Red Team Engagement
- A full-spectrum red team engagement against a realistic enterprise AI environment, simulating how adversaries compromise production AI systems.
Intended Audience
OSAI is built for practitioners who need to assess and pressure-test AI-enabled systems the way real adversaries do:
- Red teamers and penetration testers expanding into AI
- Security professionals tasked with evaluating AI-enabled systems
- AI engineers who need to understand adversarial risk
- Security teams building an internal AI red teaming capability
Prerequisites
This course and certification are not an introduction to AI, nor to AI penetration testing. Prior AI experience is not required, but we recommend familiarity with LLMs and some basic LLM pentesting methodology. Learners should also have solid general offensive-security fundamentals — OSCP or equivalent hands-on experience is recommended.
Related training topics
Justify your training
Use this sample request letter — copy it into an email to your manager and personalize the bracketed details to make the case for the time and budget.
Sample training request letter
Subject: Request for AI & AI Security training from Applied Technology Academy
[Decision Maker Name],
I'm writing to request time and budget approval to complete Applied Technology Academy's course, Advanced AI Red Teaming AI-300 (OSAI) Training. The information below outlines how this training benefits our organization, the tasks I'll be able to perform after completing it, and relevant cost and funding details.
Course Description
Applied Technology Academy is a premier provider of OffSec's newest certification, OSAI — hands-on offensive operations in AI environments. The AI-300 (OSAI) brings OffSec's offensive methodology to AI, with advanced red teaming for large language models and multi-agent systems. Applied Technology Academy is an award-winning, SBA-certified woman-owned training provider (est. 2019) whose instructors are active practitioners. The course combines instructor-led training with practical exercises, real-world examples, and computer-based activities designed to reinforce job-relevant skills. It also includes formal hands-on labs for applied, learn-by-doing practice in a live environment.
Course Objectives
Once I've completed the course, I'll have job-ready skills in AI & AI Security that I can apply immediately to our work.
Expected Organizational Benefits
After completing this course, I will be better equipped to apply these skills directly to our projects, reduce our reliance on outside expertise, strengthen our team's capabilities, and share what I learn with colleagues.
Expected Cost & Funding
Course fee: [request an itemized quote at the link below]. Applied Technology Academy supports multiple funding paths that may reduce or cover this cost: GSA MAS purchasing and government purchase orders, military credentialing funding (Army CA, AF COOL, CG COOL), VA GI Bill and VR&E, ATA Flexible Spending, and student financing. Private team cohorts are available if colleagues should attend with me.
Conclusion
This training provides practical, hands-on experience I can apply immediately to strengthen our work in AI & AI Security. Additional course information is available at https://appliedtechnologyacademy.com/offsec-training/advanced-ai-red-teaming-ai-300-osai-training/.
Thank you for your consideration,
[Your Name]
Design training around your team, not the other way around.
Talk to a training advisor about private cohorts, funding paths and program management.