PASS THE OSAI CERT: A Guide Series for OffSec's AI Red Teamer Certification
An independent, hands-on study series for the OSAI (OffSec AI Red Teamer) exam. Technical notes, real commands, and the offensive-AI concepts you need, one module at a time.
This is the home page for PASS THE OSAI CERT, our study series for OffSec’s OSAI (OffSec AI Red Teamer) certification, the practical exam that follows the AI-300 “Advanced AI Red Teaming” course. OSAI is a 24-hour, proctored, open-book exam, and it’s a full red team engagement against an AI-enabled enterprise environment, not an isolated LLM sandbox. You start from a public entry point, pivot into an internal network, and work through recon, exploitation, privilege escalation, and lateral movement across hosts that converge on a Domain Controller, with AI-focused targets (LLM apps, agents, RAG pipelines, and the infrastructure behind them) sitting next to traditional ones. The exam expects you to use AI as part of your own toolkit the whole way through, and you need 75 of 100 points to pass. It rewards people who can think like an attacker about a stack most pentesters have never had to map, without letting the classic network and Active Directory work slip.
We wrote this series for the person staring at that syllabus wondering where to even start. Each module takes one phase of the engagement and turns it into something you can actually practice, with the commands, the signals to look for, and the reasoning behind each one.
Who this is for
You’re comfortable with classic pentesting (think OSCP-level recon, enumeration, and exploitation) and you want to extend that muscle to AI systems: LLM APIs, RAG pipelines, agent frameworks, vector databases, and self-hosted model servers. You don’t need to be a machine-learning engineer. You do need to be willing to learn what these components are, how they talk to each other, and where they leak.
The modules
The series grows one module at a time, following the shape of a real engagement.
Reconnaissance
Before you can exploit an AI system, you have to find it and map it. This module covers the whole recon phase, from understanding the stack to pulling it apart passively and actively.
- Recon Part 1: Mapping the AI Attack Surface. The anatomy of an AI-enabled system and a recon taxonomy to organize everything that follows.
- Recon Part 2: Passive Reconnaissance of AI Systems. Fingerprinting the stack from HTTP responses and mining public code and artifacts, all without touching the target adversarially.
- Recon Part 3: Active Reconnaissance of AI Systems. Service discovery, model fingerprinting, and RAG pipeline mapping with direct probes.
Coming later
Future modules will follow the same structure through the rest of the engagement: exploitation (prompt injection, jailbreaks, tool and agent abuse, supply-chain attacks) and post-exploitation. We’ll add them here as they publish, so bookmark this page as your index.
DSEC Labs runs offensive engagements against real AI systems for a living. If you want the professional version of what this series teaches, see our AI red teaming work.