AI-300 · OSAI — OffSec AI Red Teamer (roadmap alignment)
Study-planning crosswalk for OffSec's Advanced AI Red Teaming (AI-300) exam, which earns the OffSec AI Red Teamer (OSAI / OSAI+) certification. As of a 2026-07-30 exam audit, all 11 modules were researched against the exam and gap-filled to full offensive depth (71 subtopic gaps closed, 153 sources added across 15 weeks). The table maps each module to its week(s) — the 26-week book is now a complete OSAI prep path. Official course: offsec.com/courses/ai-300.
The exam (verified)
- 📝 24-hour proctored, hands-on red-team engagement in a private VPN — compromise a realistic AI-enabled enterprise environment (not multiple-choice; OSCP-style practical) (OffSec · Red Team Guide).
- 🤖 Open-book and AI encouraged — notes, online resources, and LLM/AI assistants are not just allowed but a core part of the assessment. One passing candidate used ~4.1B tokens in 24h (~$6.4k API-equivalent) (candidate review).
- 🎓 Prereq: OSCP-level offensive fundamentals (pentest concepts, networking, Linux/Windows, scripting); basic LLM familiarity + basic LLM-pentest methodology recommended. Not an intro.
- 🏷️ OSAI never expires; OSAI+ expires 3 years (maintain via continuing-education paths). ~65h content; ~40 ISC² CPEs. Sold as a $1,749 course+exam bundle or a $2,749/yr Learn One subscription (OffSec · NICCS/CISA listing).
- ℹ️ One partner site lists a 48-hour exam; OffSec's own materials and every first-hand review say 24h — confirm on the official exam FAQ when you schedule.
Syllabus → roadmap crosswalk
| # | AI-300 module | Roadmap week(s) | Coverage |
|---|---|---|---|
| 1 | Introduction to Red Teaming AI Systems | W8 Threat Modeling · W14 Automated Red Teaming | ✅ full |
| 2 | Reconnaissance for AI Targets | W13 Agentic Pentesting · W19 Infra Hardening | ✅ full — deepened: Shodan/FOFA/Censys dorks, AI port map, native-API enum, AIMap, 5-phase recon |
| 3 | Attacking AI Agents (prompts, memory, tools) | W5 Agentic Core · W9 Prompt Hacking · W14 · W21 Agentic Safety | ✅ full |
| 4 | Attacking Multi-Agent Systems & A2A | W6 Agentic Design + Multi-Agent · W15 (protocol) | ✅ full |
| 5 | Exploiting RAG Pipelines | W4 RAG Systems · W12 RAG Poisoning | ✅ full |
| 6 | Attacking Embeddings (inversion, extraction) | W4 · W11 Adversarial ML | ✅ full — deepened: embedding inversion, membership inference, data extraction |
| 7 | Attacking MCP & Tool Surfaces | W7 MCP · W15 Workflow/Protocol Hijacking | ✅ full (roadmap's deepest area) |
| 8 | Supply Chain Attacks on AI/ML | W16 Supply Chain & Lifecycle | ✅ full |
| 9 | AI Infrastructure & Deployment Exploits | W19 Infra Hardening · W13 Agentic Pentesting | ✅ full |
| 10 | Threat Modeling for AI-Enabled Targets | W8 Threat Modeling | ✅ full |
| 11 | Capstone — full-spectrum Red Team Engagement | W26 Capstone Red Team Simulation | ✅ full |
Coverage after the 2026-07-30 exam audit: every module was researched against the exam and gap-filled non-destructively — all 15 mapped weeks now self-assess as full OSAI coverage (71 subtopic gaps closed, 153 offensive sources added). The two former thin spots are closed:
- 🔍 Recon of AI targets — Shodan/FOFA/Censys dorks, an AI-service port/banner map, native-API enumeration, AIMap, and a 5-phase recon methodology (added to W13 & W19).
- 🧬 Embedding attacks — embedding inversion, membership inference, and data extraction (added to W11).
Each filled week carries an offensive "🎯 OSAI exam depth" section with concrete techniques, tools, real CVEs, and hands-on 🧪 drills — attacker-POV, not survey.
Exam-day strategy (from a candidate who passed)
- 🤖 Build your "agent" early — the AI red-team assistant you'll drive during challenges/exam. Have a first version before the capstone module, and start small and iterate (bigger ≠ better).
- 🧠 Reflect with the agent after each challenge — a short planning/brainstorm to improve it.
- ✍️ Don't over-rely on AI — read the content, do the exercises, take good notes and summaries.
- 🧪 Practice manually first — a local LLM (Ollama + an open-weight model) to drill prompt injection before formal training. (review)
- 🔓 If Claude refuses offensive-security work, enrol in Anthropic's Cyber Verification Program (adjusted safeguards for verified security professionals) — the roadmap's own tooling (VulnHunter, autonomous researchers in W14) assumes this.
Cert & prep resources
- 🎓 OffSec AI-300 official course & cert — syllabus, pricing, enrolment.
- 📄 OSAI exam FAQ — format, proctoring, attempt validity.
- ✍️ AI-300/OSAI candidate review (somecanadian) — first-hand exam + prep experience.
- 🧭 Red Team Guide — OSAI review 2026 — independent format/scope breakdown.
- 📰 OffSec announcement — 24-hour AI red-team challenge.
- 📚 Underpinning methodology (open-book allies): The Hacker's Playbook 3; The Web Application Hacker's Handbook (injection/API abuse); OWASP LLM Top 10 — all already in this roadmap's foundations and Prompt-Hacking weeks.
🎯 How to use this: work the roadmap week-by-week; when you finish a mapped week, tick it and you've covered that AI-300 module. Prioritise the ⚠️ partial rows (recon, embeddings) for extra hands-on before scheduling the 24-hour exam.