RedTeamKit emblem RED TEAM KIT
600+ Get the Kit
Trusted by 100+ security teams

Break any AI system before an attacker does

Your assessment lands when every test proves a real control gap. 150 modular attack plays turn a folder of jailbreaks into a defensible engagement. These cards show you how.

See the plays
One-time payment · No subscription · 12 months of updates
LIVE · AI THREAT FEED

Same rigor practiced by teams securing frontier AI

Microsoft Google OpenAI Anthropic NVIDIA verizon IBM ORACLE Meta Salesforce HackerOne

Organizations represented among contributors to and users of the open AI Red Teaming Guide. No sponsorship or endorsement implied.

Grounded in the open AI Red Teaming Guide

Sound familiar?

You collect jailbreaks for inspiration — yet the report still feels thin.

Prompts in a spreadsheet don't prove impact. You need coverage tied to the system's real architecture, evidence that reproduces, and findings an executive can act on. That's the difference between "we tried some attacks" and a defensible assessment.

The plays

Each card shows you how to break one part of an AI system

Grouped into stacks by attack surface — each play maps to a real control, with expected safe behavior and the evidence you need to capture.

PI-001HIGH
Indirect prompt injection
Hidden instructions in retrieved content redirect the model.
PROMPT INJECTION
Stack of 28 plays
RAG-014CRITICAL
Cross-tenant retrieval
A crafted query surfaces documents from another tenant.
RETRIEVAL
Stack of 24 plays
MCP-011CRITICAL
Over-permissioned tools
An agent invokes actions it should never be able to reach.
TOOLS & MCP
Stack of 22 plays
MEM-004HIGH
Persistent memory poison
A planted instruction survives into a clean session.
MEMORY
Stack of 18 plays
Coverage lens

Good tests find bugs. The best find the ones that end the engagement.

COPILOT
Support assistant
What it can leak
Its own system prompt
Internal tool schema
Another user's ticket
RAG PIPELINE
Knowledge search
What it can leak
Cross-tenant documents
Unpublished records
Source credentials
AGENT
Task automator
What it can leak
Unapproved tool calls
Chained privilege escalation
Data exfil to a webhook
What's inside

Turn plays into findings that hold up in the room

150

Attack play library

Every play maps to a control, with safe behavior and evidence defined — with 20 interactive starter plays that run in the hosted dashboard.

12

Editable templates

RoE, intake, threat model, finding report, executive readout, release gates.

Live risk tracker

Score findings across 16 modules and watch severity classify automatically.

Worked example

A completed fictional assessment showing how every asset fits together.

🔒 Trusted secure checkout · one-time payment VISA MASTERCARD AMEX APPLE PAY
The anatomy

Every card is built to be executed, not just read.

Five fields on every play tell you exactly what to run, why it matters, and what proves it — so you spend time testing, not deciding what to test.

1
What it is — the attack, in one line
2
Why it works — the underlying weakness
3
When to use it — the precondition to check first
4
What to run — the exact procedure and payloads
5
What proves it — the evidence and the control validated
PLAY · ASI04 HIGH
Memory poisoning across sessions
PRECONDITION
Long-term memory is enabled for the account.
EXECUTE
Plant a persistent false instruction via a normal turn.
EVIDENCE
A fresh session inherits the poisoned instruction.
CONTROL
Validate memory-write scoping and provenance checks.
Think different

From a pile of prompts to a program

BEFORE

Without the kit

Copy, paste, pray
You reuse jailbreaks from Twitter and hope they apply.
Coverage gaps
No way to know which attack surfaces you missed.
Findings that slide
Screenshots without reproducible evidence get waved off.
One-off engagement
Nothing carries forward into regression or the next release.
AFTER

With the kit

Architecture-driven
Select plays from the system's real attack surface.
Mapped coverage
Tie every test to NIST AI RMF, OWASP, and MITRE ATLAS.
Evidence that lands
Reproducible proof and a scored severity per finding.
A standing program
Exploits become permanent regression tests and release gates.
Complete toolkits

Six stacks. Seven stages. One system.

Not a linear PDF — a working deck to shuffle, combine, and remix around your target.

Prompt injection
Direct & indirect
28
Retrieval
RAG & data boundaries
24
Tools & MCP
Function calling
22
Memory
Persistence & poisoning
18
Multi-agent
Trust & delegation
20
Resource control
Cost & availability
16
What practitioners say

The unfair advantage, in their words

★★★★★

I pull this out at the start of every engagement. It helped me think beyond prompts — and charge more for the work.

I
Igor
Offensive security consultant
★★★★★

The way the plays link to controls is my favourite part. I started spotting coverage gaps in our copilot immediately.

Y
Yung
AI security lead
★★★★★

Refreshing to use a resource that's actually practical and not full of nothing. Experienced-level depth.

D
Danesha
Red team co-founder
★★★★★

We ran our first governed LLM assessment in a week instead of a quarter. It's an operating system, not a checklist.

A
Aidan
Director of security
★★★★★

Most resources are written around tooling. This one ties tests to evidence and controls — what I need to sell findings upward.

J
Jared
Security PM
★★★★★

Easy to skim, but a surprising amount of depth once you connect the plays into a full attack tree.

M
Mia
Security engineer
One purchase. Yours to keep.

Choose your level of access

Dashboard access plus the full downloadable files. Twelve months of updates included.

INDIVIDUAL
For one practitioner — personal, portfolio, or internal work.
$249one time
150 structured attack plays
12 editable templates
Interactive risk tracker
Northstar worked example
12 months of updates
One-time Individual license · Twelve months of v1.x updates.
MOST LEVERAGE
CONSULTANT
For consultants delivering authorized paid assessments.
$499one time
Everything in Individual
Commercial-use license
Client discovery & SOW
Client-ready reporting
Engagement pricing worksheet
Source files may not be redistributed.
TEAM
For internal teams of up to ten users.
$1,499one time
Everything in Individual
Up to 10 internal users
Shared assessment workbook
Program charter
60-min implementation session
Need more than ten? Request enterprise.

Questions?

Is this a course or a certification?+

No. It is a professional implementation kit delivered through a secure hosted dashboard, with the full source files as a paid download. No video lessons, no certification.

Why a deck of plays instead of an ebook?+

It's an active working tool — shuffled, combined, and remixed around your target. There is no single linear path; you assemble the plays your system actually needs.

Can I use it with clients?+

Yes, with the Consultant License — use and customize the assets for authorized paid engagements and deliver client-specific reports. You may not redistribute the source files.

Do I need to be an offensive specialist?+

No. Each play explains what to run, why it works, and what proves it, so security engineers and consultants can execute confidently.

Does it include real offensive exploits?+

It focuses on safe, synthetic, authorized testing patterns. It must not be used against systems without explicit written permission. Stripe securely processes payment; after checkout, RedTeamKit emails a six-digit verification code so you can activate a password-protected account and reach the licensed dashboard.

RedTeamKit emblem

Ship assessments teams trust

150 plays, 12 templates, a live risk tracker, and a worked example — delivered through the hosted dashboard, yours to keep.

Read the free guide
One-time payment · authorized security testing only