Skip to content
Reference

AI-300 · OSAI — OffSec AI Red Teamer (roadmap alignment)

AI-300 · OSAI — OffSec AI Red Teamer (roadmap alignment)

Study-planning crosswalk for OffSec's Advanced AI Red Teaming (AI-300) exam, which earns the OffSec AI Red Teamer (OSAI / OSAI+) certification. As of a 2026-07-30 exam audit, all 11 modules were researched against the exam and gap-filled to full offensive depth (71 subtopic gaps closed, 153 sources added across 15 weeks). The table maps each module to its week(s) — the 26-week book is now a complete OSAI prep path. Official course: offsec.com/courses/ai-300.

The exam (verified)

  • 📝 24-hour proctored, hands-on red-team engagement in a private VPN — compromise a realistic AI-enabled enterprise environment (not multiple-choice; OSCP-style practical) (OffSec · Red Team Guide).
  • 🤖 Open-book and AI encouraged — notes, online resources, and LLM/AI assistants are not just allowed but a core part of the assessment. One passing candidate used ~4.1B tokens in 24h (~$6.4k API-equivalent) (candidate review).
  • 🎓 Prereq: OSCP-level offensive fundamentals (pentest concepts, networking, Linux/Windows, scripting); basic LLM familiarity + basic LLM-pentest methodology recommended. Not an intro.
  • 🏷️ OSAI never expires; OSAI+ expires 3 years (maintain via continuing-education paths). ~65h content; ~40 ISC² CPEs. Sold as a $1,749 course+exam bundle or a $2,749/yr Learn One subscription (OffSec · NICCS/CISA listing).
  • ℹ️ One partner site lists a 48-hour exam; OffSec's own materials and every first-hand review say 24h — confirm on the official exam FAQ when you schedule.

Syllabus → roadmap crosswalk

# AI-300 module Roadmap week(s) Coverage
1 Introduction to Red Teaming AI Systems W8 Threat Modeling · W14 Automated Red Teaming ✅ full
2 Reconnaissance for AI Targets W13 Agentic Pentesting · W19 Infra Hardening ✅ full — deepened: Shodan/FOFA/Censys dorks, AI port map, native-API enum, AIMap, 5-phase recon
3 Attacking AI Agents (prompts, memory, tools) W5 Agentic Core · W9 Prompt Hacking · W14 · W21 Agentic Safety ✅ full
4 Attacking Multi-Agent Systems & A2A W6 Agentic Design + Multi-Agent · W15 (protocol) ✅ full
5 Exploiting RAG Pipelines W4 RAG Systems · W12 RAG Poisoning ✅ full
6 Attacking Embeddings (inversion, extraction) W4 · W11 Adversarial ML ✅ full — deepened: embedding inversion, membership inference, data extraction
7 Attacking MCP & Tool Surfaces W7 MCP · W15 Workflow/Protocol Hijacking ✅ full (roadmap's deepest area)
8 Supply Chain Attacks on AI/ML W16 Supply Chain & Lifecycle ✅ full
9 AI Infrastructure & Deployment Exploits W19 Infra Hardening · W13 Agentic Pentesting ✅ full
10 Threat Modeling for AI-Enabled Targets W8 Threat Modeling ✅ full
11 Capstone — full-spectrum Red Team Engagement W26 Capstone Red Team Simulation ✅ full

Coverage after the 2026-07-30 exam audit: every module was researched against the exam and gap-filled non-destructively — all 15 mapped weeks now self-assess as full OSAI coverage (71 subtopic gaps closed, 153 offensive sources added). The two former thin spots are closed:

  • 🔍 Recon of AI targets — Shodan/FOFA/Censys dorks, an AI-service port/banner map, native-API enumeration, AIMap, and a 5-phase recon methodology (added to W13 & W19).
  • 🧬 Embedding attacks — embedding inversion, membership inference, and data extraction (added to W11).

Each filled week carries an offensive "🎯 OSAI exam depth" section with concrete techniques, tools, real CVEs, and hands-on 🧪 drills — attacker-POV, not survey.

Exam-day strategy (from a candidate who passed)

  • 🤖 Build your "agent" early — the AI red-team assistant you'll drive during challenges/exam. Have a first version before the capstone module, and start small and iterate (bigger ≠ better).
  • 🧠 Reflect with the agent after each challenge — a short planning/brainstorm to improve it.
  • ✍️ Don't over-rely on AI — read the content, do the exercises, take good notes and summaries.
  • 🧪 Practice manually first — a local LLM (Ollama + an open-weight model) to drill prompt injection before formal training. (review)
  • 🔓 If Claude refuses offensive-security work, enrol in Anthropic's Cyber Verification Program (adjusted safeguards for verified security professionals) — the roadmap's own tooling (VulnHunter, autonomous researchers in W14) assumes this.

Cert & prep resources

🎯 How to use this: work the roadmap week-by-week; when you finish a mapped week, tick it and you've covered that AI-300 module. Prioritise the ⚠️ partial rows (recon, embeddings) for extra hands-on before scheduling the 24-hour exam.