Unfiltered feedback from hunters, red teamers, and security leaders who've taken Arcanum training, pulled straight from X, LinkedIn, and the class chat.
If you ever get the opportunity to take The Bug Hunter's Methodology by @Jhaddix do it! Seriously, it is 100% worth the investment. Many courses teach techniques, but his does that in addition to context, real examples, and how to approach a target! 10/10 recommendation!@_ghsinfosec · The Bug Hunter's Methodology · via X
Every review below is quoted verbatim from a student. Filter by course.
The best god damn money I've ever spent...Jonathan Dunn XSSDoctor
Just had an incredible weekend taking @JHaddix's #TBHM course! Mind-blowing tips & tricks for bug bounty hunting. Even if your skills are at a Black Belt level you should take it! The group chats with other fellow hackers were constantly flowing with side content!Marco Figueroa Mozilla
I've always been a big fan of Jason Haddix. From Bug Hunter Methodologies to Recon and now Attacking AI, I've learned and adapted a lot from his mindset and the way he approaches complex problems. The tools and frameworks Jason shares are something I personally found very easy to apply. For me, following his work through papers, discord discussions, and the Arcanum trainings has 10x'ed my research skills and overall efficiency.Thoufeeque N S Security @ Advance
Huge shoutout to the @Jhaddix TBHM course for the incredible value it offers. Spotted a vulnerability within 24 hours and secured a four-digit bounty. Didn't expect such a speedy return on investment!@tedixh1
Honest thoughts about @jhaddix's Bug Bounty Hunter Methodology live bootcamp: Even if you've watched all his free TBHM videos, it's 10000% worth it. He takes the time to go deeper into recon and reveals a bunch of his secrets 🕵️ Day was awesome and can't wait for tomorrow!@d3mondev
Day 2 of TBHM Live by @Jhaddix is a wrap! It was a great weekend full of learning. I have a WHOLE list of tools, tricks, ideas to follow up on and test! Would recommend it to anybody! Also some really dope classmates in my section :)Gunnar Andrews @G0LDEN_infosec
There is a lot of "trainings" or "courses" flying around the infosec world atm. But if you ARE in the market for some top tier learning, check out @Jhaddix's TBHM course. I just listened in for the third time, and it is worth every single cent of the price. Gets better every time.Gunnar Andrews @G0LDEN_infosec
Here is a fantastic win I scored, after 2 months of applying @Jhaddix TBHM live. There are few skill-based courses that deliver like his. Cannot recommend the class enough!@1oad3d
Day 1 of @Jhaddix's Bug Hunters Methodology Live course completed. Not only did he live up to his mythic status, but the atmosphere and community engagement was next level. Knowledge compounded. Cannot recommend enough.@0xKilotel
As a career pentester and red teamer, I am getting my money's worth of info from @Jhaddix bug bounty training. I've learned several new tricks and tools to incorporate into my workflow. Great course!@kafkaesqu3 Career pentester & red teamer
Just completed the first day of TBHM Live Class of @Jhaddix, and man was I impressed. The course is packed with valued info, and it's well worth the money. I think it's even underpriced, and yeah, never in my entire life have I sat through a 6-hours class without a single yawn 😎Erik @ErikPham141
I attended @Jhaddix's #TBHM live training. Thanks to @Jhaddix for hosting this amazing training! If you are interested in learning about bug hunting or just need some new tricks for web app pentesting, you should attend one of his trainings.Phillip Wylie @PhillipWylie
Just finished up 16++ jam packed awesome hours of @Jhaddix Bug Hunter course! Probably the best course I've ever taken, everyone in the class was so helpful and kind!D4NGLZ @GroovySolutionz
This is my fourth time sitting in this class. It just continues to evolve and get better. I have always and will continue to highly recommend this course to anyone who wants to level up. @Jhaddix is an awesome teacher and the class collaboration is incredible.BostonHacker @0xM4rk7homas
TBHM live complete! Truly awesome course by @Jhaddix. He lets you in on all the bug bounty secrets. Definitely recommend for intermediate and advanced skills. Jason is super open and gives you bleeding edge info. Thank you for the awesome class!Reno Zenere @r3n0zzz
Day 1 of @Jhaddix's TBHM class done. Truly awesome course. No matter how many times I take it, I always seem to take away a wealth of knowledge. Highly recommend!@un1tycyb3r
Amazing day 2 of @Jhaddix the bug hunters methodology course. Real content not just regurgitated stuff. Genuine insights. Recommended!@carbonmanx
Just finished Day 2 of @Jhaddix TBHM training, and it was fantastic! Today, we delved into Application Analysis, learning about testing modern web apps, tools, tips and tricks, Jason gathered from his 20 years of experience. Highly recommend this training for everyone!@ins387
I've had the chance to attend a few short workshops with Jason Haddix over the years, catching pieces of his 3-day flagship course along the way. This week, I finally took the full class—and it delivered exactly what I was hoping for (and then some). The Arcanum Information Security Bug Hunter's Methodology course is also available on demand. If you're working in red teaming, bug bounty, or pentesting and haven't experienced it yet, I highly recommend it.Penelope Rozhkova, CISSP Cybersecurity Consultant · Speaker · Mentor
This course delivered a highly structured, real-world approach to modern web application security testing from reconnaissance and attack surface mapping to vulnerability discovery workflows that align closely with current bug bounty and red team practices. A big thank you to Jason Haddix for distilling years of offensive security experience into a methodology that's both practical and deeply technical. The clarity around recon pipelines, prioritization, and mindset is something I have applied immediately in my testing workflow and got some cool bugs. Also grateful to Arcanum Information Security for providing access to such high-quality, hands-on cybersecurity training that genuinely elevates skillsets rather than just scratching the surface.Akash Dubey Senior Consultant, Cybersecurity, EY · OSCP+
Had a blast attending the "Attacking AI" course by Arcanum Information Security. Jason Haddix goes out of his way to share his hard-earned knowledge and experience, not only through the course material but also by answering every single question you throw during the Q&A. Highly recommended if you want to begin your journey into the different ways GenAI can be broken and how it will affect everyone's lives.Eduardo Urias
Shoutout to Jason Haddix — Arcanum Attacking AI is a practical course for testers. Fun fact, as a returning student the cost is 10% to reup with the changing material to stay current.Christina M.
Happy to share that I recently had the pleasure and honor of attending the Attacking AI training from Arcanum Information Security, taught by none other than Jason Haddix. There was a ton of case studies, practical hands-on labs, and a full attack taxonomy that was shared with the class. However one of my favorite parts of any talk/lecture from JHaddix is the mindset he imparts to each student. I remember learning how to approach ANY webapp from watching his Bug Hunters Methodology talks and applying the mindset he would share. This course is no different. After building enough context, Jason takes the time to do on-the-fly threat modeling of new and upcoming AI-enabled applications with individual students. This really changes it from feeling like a lecture and more like a mutual discussion where we explore points of attacker ingress, identify sensitive data handling, and begin thinking of target-specific objectives when approaching with an adversarial mindset. Although there are plenty of practical attacks, intents, and evasions shared throughout the course, the biggest takeaway for me is always the mindset. I can't say thank you enough for this wonderful knowledge share! But thank you again!! Stickers for the whole crew next I see y'all! 😁✌️Ron Twist
This week, I participated in the Attacking AI training with Jason Haddix and the team at Arcanum Information Security, and it was a fantastic course. I was fortunate enough to receive this training at no cost when I met Jason at Defcon, and I'm incredibly thankful to Jason and the Arcanum Team for this opportunity to learn about Attacking AI. This course taught me about common AI architectures and how to understand them, utilizing prompt injection with a methodology and techniques to bypass LLM safeguards. It also emphasized the importance of a customer-centric approach in AI security, helping to identify what is important to the customer and which assets they would like to protect within the applications. We explored AI offensive tooling and labs that reinforced these concepts in practice. I learned a great deal throughout this course and look forward to building on this knowledge in the future. I highly recommend it for anyone interested in the evolving field of AI and security.Cris Trevino
Grateful to have had the opportunity to take Jason Haddix's fantastic training on Attacking AI this week. This was a real eye-opener into the emerging field of LLM and AI Agent security, and I'm excited to take what I learned here to continue exploring how to attack and secure these systems.David R.
I just wrapped up two full days of learning with the Attacking Artificial Intelligence course from Arcanum and am coming out of it with a wealth of resources, hands-on experience from real-world challenges, and an inspiring community of practitioners who are all committed to learning and growing together. Jason Haddix is a great teacher, very technical and actively working in the field, his guidance made the learning even more impactful. Thanks for all the tips, good songs and taxonomies.Michelle Cersosimo
I just completed the "Attacking AI" training course by Arcanum Information Security with Jason Haddix. What made this training stand out was its disciplined, attacker-focused approach to AI threat modeling — treating AI systems not as black boxes, but as layered attack surfaces that can be mapped, tested, and jailbroken. It was especially valuable to see how quickly subtle design decisions in AI-enabled workflows can introduce exploitable conditions. The real-world engagement examples reinforced that these weaknesses don't just exist in theory — they're actively leveraged when sound methodology meets opportunity. A solid reminder that as AI evolves, offensive fundamentals still drive impact, just applied in new and rapidly expanding contexts. Strong, practical training with clear relevance for anyone building, testing, or securing AI systems.Daniel Svoboda
I assumed prompt injection was old news by now. I was surprised to learn it's still the dominant attack vector against LLM systems, something the Attacking AI course really drove home. Jason Haddix's course does a fantastic job mapping out the current landscape of AI security and helping you understand the mindset needed to break these systems. Coming from a traditional offensive security background, I expected a lot of new techniques. What I didn't expect was how much mileage attackers are still getting out of the fundamentals, just applied to a new surface. If you're in security and interested in AI red teaming, it's definitely worth a look.Jon Otano
Just completed the "Attacking AI" training by Arcanum Security with Jason Haddix. Really enjoyed the focus on AI threat modeling and attacker methodology — breaking down how to map the AI attack surface and systematically evaluate where things can go wrong in AI-enabled systems. One of the best parts was seeing real examples from previous engagements, which made the methodology much more concrete. It's always interesting to see how these attacks actually show up in the wild and how small design decisions can open up bigger risks. Great training and a lot of useful takeaways for anyone building or assessing AI systems. 🙌Jorge Carvalho
I just took a course from the hacking legend himself Jason Haddix. For me the journey from Data Scientist role to more of an AI security engineer has been an interesting journey from building up apps in the NLP space to now finding ways to break them. As Generative AI becomes more deeply integrated into our tools at Kaiser, I've quickly learned that the best defense is an even better offense. You simply cannot protect a system at this scale until you know exactly how to break it. Despite the lack of departmental budget for external training, I knew I needed the "instructor-level" insights found in Jason Haddix's "Attacking AI." It was a personal investment, but for the security of our members, it was a non-negotiable. There's a reason Jason is known as the instructor who teaches the other instructors in the offensive security space. Day 1: a solid foundation — the essential groundwork for what follows, with basic skills put into practice. Day 2: this is where the course completely shifts gears. Jason pulls back the curtain on the specific, "behind-the-scenes" offensive methodologies used by him and the BASI group — the top 1% in the world — and seeing their approach to LLMs was a total game-changer. Jason also stayed 2 hours past the course time making sure he answered everyone's questions in the chat. If you are looking to transition into AI hacking or want to understand the modern threat landscape from the best in the business, this course is the only way to learn how the world's top practitioners actually operate. HANKS (inside joke) Jason for the awesome course!Justin H.
Just wrapped up an intensive 2-day Attacking AI training with Arcanum Information Security! 🛡️🤖 Jason Haddix delivered an incredible deep dive into AI threat modeling, prompt injection, jailbreaking, and the specialized tradecraft required for attacking AI systems. If you're looking to sharpen your offensive security skills for the AI era, I highly recommend this course. It's essential knowledge for anyone breaking AI systems.Rodney Helsens
I recently attended Arcanum Information Security's 2-day Attacking AI training led by Jason Haddix. The course provided a broader perspective on offensive AI security, covering AI architectures, ecosystem-level risk, red teaming approaches, application-layer considerations and practical methods for assessing modern AI systems. It was a valuable opportunity to strengthen my understanding of how AI systems can be evaluated, challenged and secured as the threat landscape continues to evolve. Definitely a course I'd recommend to anyone looking to build a stronger foundation in AI security.Firat Hilmi Kaplan
Just completed an outstanding "Red Blue Purple AI" training with Jason Haddix that explored how to leverage AI in cybersecurity from a Red Team perspective. The session was packed with practical strategies, including creating custom ChatGPT prompts to streamline and enhance cybersecurity workflows. Highly recommend this training for anyone eager to integrate generative AI into their security operations.Bharanisai M.
In my 7 years of learning all the security things I have never walked away from a machine, article, course, etc. with the amount of desire and inspiration to just dive into the things I learned from it. It not only gives you the knowledge required to start doing some cool things with AI, but for the ones with a mind built for discovery (i.e. the hackers), it lays all the carrots you need to just dive into the rabbit hole and see what you come out with.Kristoffer Sketch
I'm happy to share that I've completed a new training on "Red Blue Purple AI"… It was wonderful and so much to learn, explore and brainstorm in the world of LLM, prompt engineering and security. It is just the beginning & this rabbit hole goes deep.Rishi N.
This past week, I attended the Red Blue Purple AI course by Arcanum Information Security, and it was an incredible experience. Jason Haddix once again delivered a pioneering course, this time diving into security and AI. The depth of the technical content was impressive, and the active participation of some of my security heroes made it even more outstanding.Michael Medenblik
Day 2 of Jason Haddix's Red Blue Purple AI delivered powerful insights into using AI for creating everything from policy development, working bypasses, detection rules all the way to a functional vCISO bot — you name it. The class was truly extraordinary, with myself having multiple lightbulb moments. Phenomenal job! Highly recommend you take this when it's next available.Daniel Pajtak
A huge thank you to Jason Haddix from Arcanum Security for the fantastic class: Red, Blue, Purple AI!... I thoroughly enjoyed the sessions and am eagerly looking forward to more classes with Jason. I've got my eye on the Bug Hunters Methodology class next. 👀 Shout out to anyone looking to dive deeper into becoming an LLM power user, improving at manipulating models, writing bots, and developing innovative systems and use cases. Jason's class is a must!Peter Drybrough
All I can say is "WOW"! Day 1 of Jason Haddix's Red Blue Purple AI course delivered! From understanding the pros and cons of different large language models to learning how to build customized agents. This is a must course for anyone wanting to understand the technology horizon.Tyson Benson Senior Product Cybersecurity Analyst, ZF Group
My favorite AI Security course so far! AI Security Course from Arcanum Information Security. Jason Haddix and his team put this great 2 day course together. Not easy as things change from day to day in this space. Well done Jason and thank you.Guy Nadeau
Another great course by Jason Haddix at Arcanum Information Security. The content was fantastic and conversations with Jason and the rest of the students was extremely valuable.Russel Van Tuyl VP of Services, SpecterOps
Just wrapped up the incredible Red, Blue, Purple AI class with Jason Haddix and Arcanum Information Security, and it was amazing! This course offered an unparalleled deep dive into AI Red Teaming, a crucial discipline for anyone serious about AI security. We explored advanced techniques for probing and identifying vulnerabilities in AI systems, learning directly from the best in the field. The emphasis on understanding adversarial AI and developing robust defenses was invaluable. It's clear that as AI adoption accelerates, the demand for skilled AI Red Teamers will only grow. Huge thanks to Jason Haddix and the Arcanum team for such an insightful and empowering experience. If you're looking to elevate your AI security expertise, especially in red teaming, I can't recommend this class enough!Simar Girn, CISM Senior Security Leader, Booz Allen Hamilton
RED BLUE PURPLE AI is the first instructor-led training I've taken in the topic... It was thorough without being slow, and to my delight very current. Arcanum Information Security courses are just qual.. 100%Ryan Williams Editor, HVCK Magazine
Sitting in @Jhaddix RED BLUE PURPLE AI class and it's fantastic. Next time it comes available you need to get in!Daniel Miessler Founder, Unsupervised Learning
Just wrapped the Red Blue Purple AI course by @Jhaddix. If you're looking to go from zero to AI power user security hero, you should take this course. Excellent content.Tom Porter @porterhau5
Thoroughly enjoyed @Jhaddix's Red Blue Purple AI class. Woke up early this morning to go over my notes, play with new AI tools, and build useful bots.Jason @pubal
Just finished Red Blue Purple AI with @Jhaddix, what a fantastic course! So many practical applications including the latest with MCP.Dave Martin @sl1nki3283
Big thanks to @Jhaddix and @arcanuminfosec for an excellent Red, Blue, Purple AI class! Now I have even more projects to add to the list.Skylar @SecurityWard
Day 1 of @Jhaddix Red, Blue, Purple AI done! I've been jumping on all I can re: AI Sec and I gotta say, it's an awesome experience! Tons of knowledge consolidated and digestible. All that + the collaborative space has me hype for day two!Garr @GarrGhar
Taking @Jhaddix Red/Blue/Purple AI course and it's full of great content. Feel like I got a very rich starting point for super charging our work. Very psyched to see what we can do!Joe (GonzoSec) @jsark983
Last week, I spent two long and incredibly exciting evenings diving deep into the "Red Blue Purple AI" training—and it was absolutely worth it! The course delivered outstanding insights into leveraging LLMs like GPT and Claude for cybersecurity with hands-on, real-world applications. What truly made it exceptional was the trainer, Jason Haddix from Arcanum Information Security—fantastic in every way, combining deep expertise with clarity and enthusiasm. I'm thrilled to bring these new skills into my role as Technical Lead Security Services at Arctic Wolf, where AI-driven approaches will help us innovate and strengthen security operations. Highly recommended for anyone looking to 10× their impact in security through AI!Sascha Hänsch Technical Lead Security Services, Arctic Wolf · CISSP, OSCP
Really enjoyed Red Blue Purple AI from Jason Haddix and Arcanum Information Security! So much information to still digest 😄 #AI for the win! Definitely recommend this course! Thank you Jason!Chris Danowski SpecterOps
This week, I completed the "Red Blue Purple AI" course offered by Arcanum Information Security and instructed by Jason Haddix! The course provided a wealth of information, enhancing my understanding, bringing me to a new level. It revealed gaps in my knowledge that I wasn't even aware of. For those in the cybersecurity field that are working with AI, I strongly suggest considering this course.Paul Linger
Thank you Jason Haddix and Arcanum Information Security for the awesome training 🙏 Back in July, I completed the Red Blue Purple AI course, which explored how AI models are reshaping everything from reconnaissance and exploitation to incident response and security strategy. It gave me a clear perspective on how AI models and custom agents can be integrated into offensive, defensive, and purple team workflows to drive more efficient and effective operations. More recently, I wrapped up the Attacking AI course 🎯 This training deepened my understanding of how AI systems can be targeted in real-world environments. We explored areas such as threat modeling of AI pipelines, prompt injection, and advanced attacks against AI-integrated applications and APIs. The hands-on approach gave me practical knowledge I can apply in red team engagements and AI-driven security scenarios. I was also fortunate to attend DEF CON 33 this year and meet Jason in person 🤝 He was incredibly welcoming and it meant a lot to thank him directly for the impact his training has had on my security journey. Overall, I am grateful for these opportunities to learn and be part of this community. Both the courses and DEF CON sharpened my perspective on offensive AI and modern attack surfaces. Haanks! LolFernando M.
@Jhaddix's new Attacking AI course last week was absolutely phenomenal. Detailed overview of the attack surfaces. His own new framework for attacks and defenses. Stuff I've not seen anywhere else. If you're building or protecting AI systems, I highly recommend it!Daniel Miessler Founder, Unsupervised Learning
Two days of late night Attacking AI training from @Jhaddix and the folks of Arcanum-Sec. Brilliant zero to hero course, gave me a LOT of new ideas and things to research. Also made me appreciate threat modelling 🫣Adam Chester @_xpn_
I attended the "Attacking AI" training by @arcanuminfosec and it was my favorite training ever. I attend trainings every year (for over a decade), and this was my first by Arcanum. Here's why I loved it: @Jhaddix is an incredible speaker: can break down complex technical ideas in a digestible and accessible way, while keeping it fun and engaging. Good engagement is a superpower, and one way he does it is by mixing different media to accommodate learning styles: videos, lectures, hands on labs, links to articles, interviews… The material itself was well researched. The whole AI-security field is new and rapidly changing, and he did a great job condensing everything into one place. Made me feel on the bleeding edge of a new technological forefront. The takeaways are immediately useful. If I'm testing a web app and run into an AI prompt, I now know exactly what to do and how to tackle it. The students! Attendees themselves were awesome and eager to share info and anecdotes. The discord server is also a great place to hang out and collaborate. I'll be checking out the other courses, since I know this is super high quality stuff.solst/ICE @IceSolst
Last week I attended the Attacking AI class by @Jhaddix and @arcanuminfosec. TLDR; it was 🔥🤘 Jason is a natural teacher who always puts 1000% into any course he does. So much content, from fundamentals to cutting edge.XNL-h4ck3r @xnl_h4ck3r
The 2 day live class from @Jhaddix on Attacking AI is next level. If you are a pentester or bug hunter, this class is a must! Can't recommend it enough!Martin Voelk @martinvoelk
The Attacking AI course by Arcanum Information Security, taught by Jason Haddix, is very detailed and providing excellent setup information for learning to attack LLMs.Rey Bango Vulnerability Analyst, Horizon3.ai
Shout-out to the great work Jason Haddix is doing to train the cyber security world on Attacking AI. The training and content was 10/10 for his course. I could not recommend this more if you want to get more into the world of hacking LLMs. Jason's genuine passion and knowledge on the topic was on display for the entire day. Very inspiring stuff. I can't imagine how great the 2 day version of this course must be. Even with 1 day I felt like I learned so much. Really looking forward to trying everything out we learned in the course. Jason and his wife were such genuinely nice people too. What a great experience.Stu Skove Penetration Tester, KirkpatrickPrice
Just wrapped up the amazing Attacking AI live course by Arcanum Information Security and Jason Haddix. This was a great opportunity to learn from one of the best. To me, the most valuable part of this live course was the methodology for testing AI applications, along with real-world injections and scenarios that showed how a single prompt injection inside an agentic system can drill down into RCE. I really recommend anyone interested in offensive AI and testing LLM applications to take this course, you'll gain tons of insights.Tom Abai AI Security Researcher
I have been looking forward to taking the Arcanum Information Security course Attacking AI for a while now, and I have to say it is an excellent and comprehensive course. The main concepts I really enjoyed include: AI Systems Threat Modeling — this involved reviewing and dissecting AI case studies and mapping multiple parts of a system for possible attacks. Jason emphasizes the importance of strengthening the threat model muscle. The classroom participation during this section was amazing. AI Pentesting methodology — Arcanum provides a clear and thorough AI Pentesting process that fits naturally with the threat model. This is the core focus of the course and it does not disappoint. The prompt injection primitives and modular approach provide an excellent way of constructing prompt injections. Along with attacking AI there is also a solid focus on defending AI. And the amount of material Arcanum provides is vast. Overall, Jason is a great instructor who creates a collaborative environment where people feel comfortable asking questions. I truly enjoyed the class and it is clear that Jason is passionate about teaching and the security research he does.Luis Barragan Cybersecurity Architect · CISSP
Thrilled to share I've just completed an incredible live training workshop on "Attacking AI" put on by Arcanum Information Security. The course was overflowing with valuable content on relevant topics like Prompt Injection, Threat Modeling, Tooling, Attack Methodology and so much more. Huge thanks to Jason Haddix for the amazing instruction and great learning environment. Now time to put these new skills to work!Jakob Brinkhof Senior Security Consultant, TELUS
Grab a seat in the next live cohort or start an on-demand course today.