Quick reference: Practice platforms
Index view. These platforms appear in context within their relevant week sections in
resources.md(Weeks 9, 12, 13, 15).
| Platform | Phase | What |
|---|---|---|
| HackAPrompt | 2 | Prompt injection CTF |
| Gandalf (Lakera) | 2 | LLM password extraction game |
| CAISP Labs | 3 | MLSecOps browser-based |
| OffSec AI-300 Labs | 2 | Enterprise AI red team |
| FinBot CTF (OWASP) | 1-2 | Agentic AI finance bot |
| SANS SEC535 Labs | 2 | AI-driven recon + exploitation |
| Mindgard | 2 | Free AI security risk evaluation |
| Microsoft LLMail-Inject | 2-3 | Adaptive prompt injection |
| PortSwigger WebSecAcademy AI Labs | 2-3 | Indirect prompt injection against AI-powered security scanners; routing-based SSRF [Apr-28 recon] |
| OS-Harm / OSWorld | 3 | Computer-use agent safety |
| TCM Securing AI Applications | 3 | 5hr defensive course: prompt hardening, input validation, PII detection, rate limiting (from PAPA cert provider) [Apr-29] |
| Secwiser Hack AI Defenses | 2 | Gamified: prompt injection, tool abuse, data exfil, jailbreaks, vector weaknesses [Apr-29] |
| Dreadnode Crucible | 2-3 | 70+ AI/ML security CTF challenges; used at Black Hat; API + web UI; 214K+ attack attempts analyzed [Apr-29] |
| Wiz AI Security CTF | 2 | 5-level progressive prompt injection challenge [Apr-29] |
| HackThisAI | 2 | CTF-style adversarial ML challenges (GitHub, 113 stars) [Apr-29] |
| Object-capability SQL CTF | 3 | $1K bounty sandbox break |