PromptFu

Curriculum

From how these systems fail to how you test them

Tracks are a real sequence. 00 through 03 build the offensive foundation, 05 and 06 are the defensive and methodological spine, and 04, 07–09 are reference depth you can reach for in any order. Roughly 28 hours end to end.

00

Introduction

Two modules, mostly hands-on. What a language model actually does, what your app really sends it, and what changes when it thinks first.

01

Foundations

The conceptual spine. Eight models that make every later module make sense.

02

Offense: Model Layer

Attacks on the model's behaviour: jailbreaks, encoding, multi-turn, reasoning-model surfaces.

03

Offense: Agentic

The core of the course. Where the attacker never talks to the agent, and where the money is.

04

Offense: Data & Supply Chain

The attacks that never go through the prompt: poisoning, backdoors, artifacts, extraction.

05

Defense

The controls that actually survive an adaptive attacker, plus an honest table of the ones that don't.

06

Methodology & Operations

How the work is actually run: threat models, invariants, adaptive testing, measurement, reporting.

07

Tooling

Tools chosen by the question they answer, and why generic scanners miss your real bug.

08

Threat Landscape

What attackers are actually doing with AI right now. The fastest-decaying content here, refreshed monthly.

09

Governance & Career

Regulation as it actually stands, programme design, and how to get hired doing this.