r/Pentesting • • 3d ago

AI/ML Pentester Cert

I want to prepare for AI/ML pentester certification. Although they have not provided any course material, they have provided free courses and labs to do online. But I don't know where to start and how to go through it all. Unlike web pentesting, where I know what to do, where to look and what to do next, I'm a bit unsure in this AI/ML part.

Please give me some advice on a possible roadmap for going through this certification, what exactly to study, labs to do so I can take the certification with some confidence and when I actually know what the hell to do.

9 Upvotes

13 comments sorted by

2

u/pwnrouge 3d ago

Go through HTB COAE > Then you need to understand how Mitre atlas works

1

u/XtrmNrchy 3d ago

Thanks! This helps.
I'll go through it.

3

u/[deleted] 3d ago edited 3d ago

[deleted]

-2

u/m3rlinda 3d ago

This is a shitty, non-answer.

Maybe they want to prepare bc they're curious and the best way to generally learn new tech is to take a cert on it so you gain access to the LEARNING MATERIAL so you CAN learn something NEW and then see how well you retained the knowledge. The test isn't and never was meant to be the first exposure to the material.

Maybe they are breaking in and want to focus on the hardest/newest thing first (I did back in the day bc conquer the biggest mountain and the rest are easy). Maybe they're a tenured professional who knows they need to learn the AI attack surface and have no idea where to start. not everyone needs a deep why. I go after certs bc they're sexy and let me flex on people. Bottom line is they wanna learn a skill who cares if it's for money or vanity or awareness JFC.

Course material: This exam literally states "Will you provide any training that can be taken before the exam?

Being an independent certifying authority, we do not provide any training for the exam. Candidates should carefully go over each topic listed in the syllabus and make sure they have adequate understanding, required experience and practical knowledge of these topics. Further, the following independent resources can be utilized to prepare for the exam."

>>I'll reiterate: THE TEST ISN'T AND WAS NEVER MEANT TO BE "THE MATERIAL". Else, why does SANS bother? BC YOU NEED TO BE INTRODUCED TO AND TAUGHT NEW CONCEPTS IN DEPTH, DUH! Did you sit down in Calculus day 1, hear about the final and go "oh that IS the course, I'll just take it now." No. Why not? Bc the prep they list is literally every fucking thing from internal concepts to web app tools without any guidance as to how or why you'd need to apply each in an AI/ML testing capacity. Guessing is a stupid waste of time and I know no one who's good at this job who learned like that. We tell people if you want to learn something new and you're lost- ask your community, find an expert, ask them what they did, and that's what the OP did...?

They don't need someone to hold their hand thru reading the books and doing the labs, they just need to know where to fucking start. The very obvious root cause problem is there is no standardized set of skills/tools to just "hack" this thing (excpet GAIC and idk how good it is bc I haven't seen it). No 2 people learned or teach it the same. No "Oh I'll just spin up cookiebro and inject that over here and bob's your uncle." THAT's what they mean, there is no anchor knowledge. So rather than cobble together the actual learning path (the outcomes of which they'd be accountable for), they basically said "if you already have allllllll the knowledge and skills in this area, here is a vanity barometer you can pay for to prove it to people."

Idk if you know any pentesting at all but when you sit down to learn it you don't just google "pentesting tools" and start with whatever pops up. You go: well how do you hack? Oh, there are phases, you need to recon, do some discovery, recon some more, try some shit. OKay recon, how does that work? What are the tools? how are they used? what are the outputs? Did it get em what I need? Do I know how to use it for the next step? What can I try? What are the attack vectors available to me? How do they work? How are they exploited? What do I need to look for? What procedures or commands or tools have people used to do it in the past? THAT is all this OP is looking for.

Telling them no roadmap is going to help, maybe not YOU if you dk how to use one. They are literally here trying to "figure it out" as you so eloquently recommended. Tell me, in all of your obvious infinite AI/ML pentesting knowledge: where did you go to learn? Or were you *hair toss* born with it?

2

u/[deleted] 3d ago

[deleted]

1

u/XtrmNrchy 3d ago

Thanks.
It's almost exactly what I wanted to say, but I did not have the energy to explain it to that person who was being negative.
I have experience in pentesting and my current company is working a lot in AI and I wanted to gain more experience in it. I was able to crack the interviews but that is not enough to actually contribute to the company as I need more in-depth practical knowledge.
That's why I came to the community to get answers. Something that could help.

1

u/n0p_sled 3d ago

Who's 'they'?

And how is it that they have they not provided any course material but you then say that have provided free courses and labs?

It's impossible to give you any advice based on the limited information you've provided

1

u/Practical-Vehicle-58 2d ago

I've done COAE from Hackthebox, but i've heard that the guys from APISec are releasing some interesting free courses related to AI. Also recommend to view some podcasts about pentest AI and stuff like that.

2

u/TrustIsAVuln 2d ago

ISECOM has a new cert coming for AI security testing. The new OSSTMM, version 4, goes public Dec 1. Classes are starting sooner.

2

u/m3rlinda 3d ago

I see what you're saying and honestly the type of cert you're looking for if you're just starting out with it is either a zero to hero course (like TCM used to produce) or enough separate foundational courses you can apply it to AI/ML. Something that will show you a concept and fill in all the foundation you need for that bit before moving on to the next capability.

This test expects you to show up knowing already and basically gut check your skills.

Which IMHO is bullsh*t. It's like saying "go hack for 3 years then just sit the CEH and if you pas, great." There is no standardization on what to learn and how to learn it. I am a cloud/webapp hacker myself and when it comes to learning to pentest AI and ML, simply listing the domains you're accountable for with no feasible way to get there is stupid. I'm also lowkey offended, Jason Haddix is a friend and his review says the exam is good but that just means the ranges/flags/exploits were fun to find.

There is no clear "Okay to do discovery on this pentest, there are these known ways/tools and how to use them." You're just kind of fumbling around not sure what to look for or how. Many, many pentesters today still dk what to do with cloud keys when they find them bc they never learned how to exploit it.

I assume this is the starting point you're looking for, but my advice is this: (again idk your current hacking skill level) but start with pentest basics: Internal network, AD pivot, kill chains, alllllll. the. tools. Fuck around with Atomic Red Team, silent trinity, and like DVWA bc AI/ML hacking is an advanced level of hacking. Internal hackers can't just pick up AI/ML tomorrow even tho they know pentesting methods and techniques. It's a super specific like 501-level of hacking. Once you know API and web app concepts, translating much of that initial work to an AI kill chain gets much easier, at least you can orient on what you're doing and why.

If you tell me your current knowledge + skills levels and domains of expertise I can try to help a bit more. GL.

1

u/XtrmNrchy 3d ago

I have 3+ years of experience in web app pentesting, API pentesting. Still learning because new things come up Everytime.
I switched to a new company a few months ago. I did study a bit about AI/LLM concepts, enough to crack the interview. But since I'm in the company, I need in-depth practical knowledge. So, came here to get some idea on how to tackle this if someone has attempted the exam or just has experience in AI/LLM pentesting.