All Modules AI IN SECURITY

AI in Security · Complete Guide

Eight chapters covering AI from both sides of the fight: how attackers use generative AI for phishing, deepfakes, and adversarial ML; how to secure your own LLM applications against prompt injection (OWASP LLM Top 10); how AI assists SOC triage, threat hunting, and detection engineering; how to secure AI/ML systems themselves (MITRE ATLAS, MLOps, RAG risk); and the governance frameworks (NIST AI RMF, EU AI Act) shaping how organizations manage AI risk. Built for analysts and engineers who need to understand AI as both a new attack surface and a new defensive tool.

8 CHAPTERS
~11 HRS CONTENT
BEGINNER to ADVANCED SKILL RANGE
SEP 2026 LAST UPDATED
MODULE PROGRESS 0 / 8 chapters complete
LLM security prompt injection OWASP LLM Top 10 MITRE ATLAS AI-assisted triage NIST AI RMF EU AI Act AI governance

ALL CHAPTERS

/
01
BEGINNER 25 min

AI and ML Foundations for Security

AI, ML, and LLM terminology in plain language, supervised vs unsupervised learning, and where AI already sits in the security stack.

AI terminology machine learning types large language models
02
BEGINNER 30 min

AI-Powered Threats

LLM-generated phishing, voice cloning and deepfakes, AI-assisted malware, adversarial ML evasion and data poisoning, and MITRE ATLAS.

AI-powered threats deepfakes adversarial ML
03
INTERMEDIATE 35 min

Prompt Injection & LLM Application Security

Direct vs indirect prompt injection, jailbreaking, the OWASP Top 10 for LLM Applications, and defensive approaches with honest limitations.

prompt injection OWASP LLM Top 10 jailbreaks
04
INTERMEDIATE 30 min

AI in the SOC: Detection & Triage

UEBA and anomaly detection, AI-assisted alert triage, SOC copilots, where AI triage breaks down, and adoption guidance.

AI-assisted triage SOC copilots anomaly detection
05
INTERMEDIATE 35 min

AI-Augmented Hunting & Detection Engineering

AI-assisted hypothesis generation, natural-language-to-query drafting, and AI-assisted false positive tuning, with human validation at every stage.

AI-assisted hunting natural language to query hypothesis generation
06
ADVANCED 35 min

Securing AI & ML Systems

Model theft and extraction, AI supply chain security, MLOps security, RAG and vector database risk, and MITRE ATLAS as a threat-modeling reference.

model security MLOps security MITRE ATLAS
07
ADVANCED 30 min

AI Governance, Risk & Compliance

Shadow AI, the NIST AI Risk Management Framework, the EU AI Act's phased timeline, AI red teaming, and bringing governance and security together.

NIST AI RMF EU AI Act shadow AI
08
ADVANCED 20 min

Building an AI Security Program

The AI security tooling landscape, a practical maturity ladder, org models for owning this work, and where to go next in H3AD-LEARN.

AI security program maturity model program ownership

PREREQUISITES & OUTCOMES

WHAT YOU SHOULD KNOW

  • No prior data science, machine learning, or prompt-engineering background required, Chapter 1 builds the vocabulary from scratch
  • Basic familiarity with SOC workflows and MITRE ATT&CK helps for Chapters 4 and 5 (the SOC Operations and Threat Hunting modules are good primers if either is unfamiliar)
  • No coding or model-training experience required, this module teaches security implications of AI, not how to build models
  • General security fundamentals (the Fundamentals module) are assumed as baseline vocabulary throughout

WHAT YOU WILL KNOW AFTER

  • How to recognize AI-enhanced phishing, deepfakes, and adversarial ML techniques, and what MITRE ATLAS catalogs
  • How prompt injection works, direct vs indirect, and how it maps to the OWASP Top 10 for LLM Applications
  • How AI is used for SOC triage and threat hunting today, and where human review still has to stay in the loop
  • How to think about securing an organization's own AI/ML systems: model theft, supply chain, MLOps, RAG risk
  • What the NIST AI RMF and EU AI Act actually require, and how shadow AI creates real security risk
  • How to reason about AI security program maturity and where this work fits inside a security organization

RECOMMENDED TOOLS

H3AD-SEC tools that pair directly with this module's content.