Where to start
Ordered by actual difficulty. At the same level: isolated lab first, then the guided room, and the full machine last.- PortSwigger — Exploiting AI agents to exfiltrate sensitive information (Apprentice) · 🇬🇧
- PortSwigger — Exploiting AI agents to perform destructive actions (Apprentice) · 🇬🇧
- PortSwigger — Exploiting insecure output handling in LLMs (Apprentice) · 🇬🇧
- PortSwigger — Exploiting LLM APIs with excessive agency (Apprentice) · 🇬🇧
- TryHackMe — Advent of Cyber 2024 (Easy · ~1440 min) · 🇬🇧
- TryHackMe — CupidBot (Easy · ~60 min) · 🇬🇧
Curated resources
PortSwigger labs practicing LLM Attacks (Prompt Injection) (8)
TryHackMe rooms practicing LLM Attacks (Prompt Injection) (2)
← Back to the full glossary Last updated: 2026-08-13