Read the free interactive preview of AI Security From PsyOps to CyberOps Start Reading Free →
INTERACTIVE TRAINING

How LLM & Agent Attacks Work

Part one walks through how a modern LLM agent actually processes a request — context, reasoning, tool calls. Part two overlays the same architecture with how attackers exploit each stage, grounded in patterns documented across OWASP's LLM and Agentic Top 10s and MITRE ATLAS.

Knowledge Base Docs, wikis, tickets User web / mobile / voice Context Window — System Prompt — Retrieved Knowledge — Conversation History — User Input LLM Core Thought → Action next-token loop Tool Layer APIs · DBs Ticketing · MCP Final Answer
Knowledge Base Docs, wikis, tickets User web / mobile / voice Context Window — System Prompt — Retrieved Knowledge — Conversation History — User Input LLM Core Thought → Action next-token loop Tool Layer APIs · DBs Ticketing · MCP Production Systems Attacker direct input Poisoned Document planted in the index Attacker Server data exfil target

Where this comes from

This walkthrough is a synthesis of patterns documented across public security research and industry conference talks (DEF CON, Black Hat, BSides) on LLM and agent security, structured against the vocabulary in OWASP's Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications, and MITRE ATLAS. It's a teaching simplification of the architecture, not a diagram of any specific product.

SEE WHERE YOUR OWN SYSTEMS STAND

This is what we test for in every engagement.