Skip to main content
This page aggregates cross-platform resources to practice LLM Attacks (Prompt Injection): retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills. Coverage: 10 challenges across 2 platforms — 8 PortSwigger · 2 TryHackMe. 0 with a Spanish writeup, 0 with a video writeup.

Where to start

Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.
  1. PortSwiggerExploiting AI agents to exfiltrate sensitive information (Apprentice) · 🇬🇧
  2. PortSwiggerExploiting AI agents to perform destructive actions (Apprentice) · 🇬🇧
  3. PortSwiggerExploiting insecure output handling in LLMs (Apprentice) · 🇬🇧
  4. PortSwiggerExploiting LLM APIs with excessive agency (Apprentice) · 🇬🇧
  5. TryHackMeAdvent of Cyber 2024 (Easy · ~1440 min) · 🇬🇧
  6. TryHackMeCupidBot (Easy · ~60 min) · 🇬🇧

Curated resources

PortSwigger labs practicing LLM Attacks (Prompt Injection) (8)

TryHackMe rooms practicing LLM Attacks (Prompt Injection) (2)


Back to the full glossary Last updated: 2026-08-13