AI and machine learning · Free · ₹0
AI Security and the OWASP Top 10 for LLMs
The security course for people who have already built something with an LLM: the attack surface a model adds, all ten 2025 OWASP LLM risks one at a time, indirect injection and zero-click agent attacks, what leaks out through a chatbot, securing agents with identity and least privilege, the OWASP MCP and agentic guidance, red-teaming with MITRE ATLAS, and the NIST-based governance a plant or a GCC can actually enforce.

Inside the course



From the lessons

Why an LLM is a new attack surface
IBM Technology

LLM01: prompt injection and its defences
IBM Technology

LLM02 and LLM07: what leaks out
Vandana Verma

LLM05 and LLM06: output handling and excessive agency
Vandana Verma

LLM10: unbounded consumption and the cost of running AI
Vandana Verma

Agent identity, privilege and delegation
IBM Technology
Lesson frames belong to the creators named in the Credits below and are shown from YouTube.
What you will learn
Threat-model an AI feature by its parts; name and defend against all ten OWASP LLM risks; trace an indirect injection from a poisoned document to an executed action; write the rule for what may be pasted into a public chatbot; check the provenance of a model, dataset or plugin before it is used; scope an agent's tools, identity and permissions so it cannot act beyond its brief; review a connector before wiring it in; plan a pen test of an LLM feature; and fill the register entry and AI-use policy that make the whole thing auditable.
- Draw an AI feature as its parts and mark where an outsider's text can enter
- Name all ten 2025 OWASP LLM risks and sort a real incident into the right one
- Trace an indirect injection from a poisoned document to an executed action
- Write the one-page rule on what may and may not be pasted into a public chatbot
- Scope an agent's tools, identity and permissions to the least it actually needs
- Plan a pen test of an LLM feature and fill the AI register entry behind it
Course content
15 modules · 49 lessons · 9h 21m
In order, at whatever pace suits you. Each module ends with a practice task that builds on the last, and a short quiz.
- 01Why an LLM is a new attack surface4 lessons34m
- 02The OWASP Top 10 for LLM applications2 lessons40m
- 03LLM01: prompt injection and its defences4 lessons57m
- 04Indirect injection, promptware and zero-click attacks3 lessons36m
- 05LLM02 and LLM07: what leaks out4 lessons36m
- 06LLM03 and LLM04: supply chain, data and model poisoning4 lessons26m
- 07LLM05 and LLM06: output handling and excessive agency4 lessons29m
- 08LLM08 and LLM09: retrieval weaknesses and misinformation4 lessons34m
- 09LLM10: unbounded consumption and the cost of running AI4 lessons37m
- 10Securing AI agents: architecture and zero trust4 lessons45m
- 11Agent identity, privilege and delegation3 lessons41m
- 12OWASP guidance for agentic applications and MCP2 lessons40m
- 13Testing AI systems: MITRE ATLAS, pen-testing, adversarial AI3 lessons1h 5m
- 14Governance: NIST AI RMF and a rule people can follow4 lessons41m
- 15Final assessment0 lessons0m
Requirements
- Who it is for
- Intermediate. Best after any LLM, RAG or AI agent course in the track. Some IT or OT security background helps, but no coding is required.
- Software
- None required. A free chatbot account is enough for the leakage and grounding exercises.
- Hardware
- None.
AI Security and the OWASP Top 10 for LLMs at a glance
AI Security and the OWASP Top 10 for LLMs is a free, self-paced online ai and machine learning course from EDWartens India with 15 modules, 9h 21m of video lessons, written notes, practice tasks and assessments, and an optional verifiable certificate.
- Price
- ₹0, free for good. No trial, no card. Comparable classroom training of this length costs about ₹5,999.
- Format
- 15 self-paced modules, 9h 21m of video, written notes, a practice task per module and one final assessment.
- Level
- Intermediate. Intermediate. Best after any LLM, RAG or AI agent course in the track. Some IT or OT security background helps, but no coding is required.
- Brand
- Vendor-neutral
- Software
- None required. A free chatbot account is enough for the leakage and grounding exercises.
- Hardware
- None.
- Certificate
- Optional EDWartens Certificate of Completion, verifiable by code. Not a vendor credential.
- Video lessons by
- IBM Technology, Vandana Verma, Jeff Crume (independent creators, credited below)
- Language
- English
A shareable EDWartens certificate
Finish every module and pass the final assessment, and the optional EDWartens certificate is yours. It carries a unique verification code on a public page anyone can check, so it stands up when a recruiter looks it up. See it below.
- Add it to your LinkedIn profile in one click
- Link it from a CV or portfolio, the URL is permanent
- Publicly verifiable by code, not a PDF anyone can edit
- Issued by EDWartens India, the training centre itself
The course itself stays free whether or not you ever buy one.
Stuck? Ask a practising engineer
A free course usually means a comment section and hope. This one does not. Every module has an Ask-your-trainer panel that reaches the same engineers who teach our paid programme: people who commission panels for a living, not moderators.
- Questions answered in the context of the module you are on
- The same engineers who teach the AEP programme
- Career tools, CV help and public job listings included
- Your progress and notes stay in your account for good
Pairs well with
PLC programming · FreeSiemens TIA PortalFrom zero electrical knowledge to a working, simulated S7-1200 program, for nothing.
PLC programming · FreeSiemens TIA Portal in Three HoursThe first three hours of the Siemens TIA Portal course, cut to end on a win: what a PLC is, how it is wired, a project configured in TIA Portal, and your first ladder program running in simulation. Finish it in an evening or two, earn a certificate, and carry straight on into the full course.
PLC programming · FreeTIA Portal: Build a MachineOne machine, start to finish. Take a bottle filling line from a written specification and an I/O list to a structured S7-1200 program with a fill station, a capper, a reject sorter and an operator screen with alarms, then test it against a written record and archive it for hand-over. The lessons are the reference; the machine is yours, and it is what you submit.
Instrumentation · FreeInstrumentation for PLC EngineersThe half of the loop that is not code. Follow one measurement from the transmitter in the field, down the 4-20 mA loop, into the analog card, through NORM_X and SCALE_X into engineering units, out again to a valve, and back to the control room when the reading is wrong.Learner reviews
No reviews yet
Reviews here are written only by learners who have finished every module of AI Security and the OWASP Top 10 for LLMs, and they are published exactly as written. Finish the course and yours will be the first.
Common questions
Who is it for?
Engineers who have already put an LLM, a RAG chatbot or an agent near company data, and IT or OT security people who now have AI systems on their asset list. It is the security counterpart to the building courses in the AI track.
What do I need to know first?
You should have seen an LLM application from the inside, so any LLM, RAG or agent course in the track first. Some IT or OT security background helps but is not assumed, and no coding is required. Every task is done on paper against a system you already work with.
Is this the OWASP certification?
There is no OWASP certification for the LLM Top 10. The OWASP Top 10 for LLM Applications is a free published document that anyone may read, and this course teaches you to apply it to a real system. This course is not a security certification of any kind and does not prepare you for one.
Is this a hacking course?
No. It is defensive: threat modelling, controls, agent permissions, governance and incident response. The testing module covers how an authorised test of an LLM feature is scoped, run and written up, not how to attack somebody else's system.
How long is it?
Fourteen modules plus a final, about nine hours of video and roughly fourteen hours in total once the notes, practice tasks and quizzes are counted. A module a day for a fortnight works well.
Is the course really free?
Yes. Every module, practice task and assessment. You create an account so your progress is saved and the assessments can be marked. The certificate is the only paid item, and only if you want it.
What certificate do I get?
An EDWartens Certificate of Completion, issued when you have finished every module and passed the final at 60 per cent, with a verification code anyone can check. It is not a vendor credential and is never described as one.
Who made the video lessons?
The creators named in the Credits block at the foot of this page, on their own YouTube channels. EDWartens did not make the videos and the creators are not affiliated with EDWartens. What EDWartens wrote is the study plan, the notes, the practice tasks and the assessments.
What you walk away with
Your certificate for AI Security and the OWASP Top 10 for LLMs
Finish the course, pass the final, and this is the document with your name on it.

Verifiable by anyone
A unique certificate number and a public verification page. A recruiter checks it in ten seconds.
Adds to LinkedIn in one click
Issuer, credential ID and URL prefilled, with 5 matching skills to pin to your profile.
QR code on the certificate
Scans straight to the verification page, so a printed copy proves itself.
Names what you can do
Lists the topics covered, from the llm attack surface: model, system prompt, retrieval, tools and output to testing with mitre atlas and governance under the nist ai risk management framework.
A permanent link
Put it on a CV, a portfolio or an application. The URL never changes.
Earned, not attended
Issued only after every module and a final assessment at 60%, with 3 attempts. That is why it stands up.
Learning is free. The certificate is optional.
Add it now and pay only when you have finished the course, or come back for it later. One-off, ₹559, GST included, with a receipt.
Issued by EDWartens India (Wartens Automation Private Limited) as a Certificate of Completion for this self-paced course. It is not a vendor certification, a university award or a CPD-accredited activity, and it does not certify competence on live equipment. Delivered electronically; see the refund policy.
Credits
Who made the video lessons
The video lessons in this course were created by the people below, not by EDWartens. Every lesson streams from its creator's own YouTube channel; EDWartens neither hosts nor sells that footage, and the creators are not affiliated with EDWartens and do not endorse this course. What EDWartens wrote is the study plan, the notes, the practice tasks and the assessments.
- IBM Technologythe attack-surface, prompt injection, promptware kill chain, zero-click, shadow AI, corpus poisoning, LLMjacking, agent security, zero trust, MITRE ATLAS and NIST AI RMF explainers
- Vandana Vermathe risk-by-risk walkthrough of LLM01 to LLM10, the first look at the OWASP MCP Top 10, and the OWASP Securing Agentic Applications guide
- Jeff Crumethe long adversarial AI session on evasion, model inversion, model theft and deepfakes
If you are one of these creators and would like a lesson removed or credited differently, write to info@wartens.com.