◆ Next live training: Red Blue Purple AI · Sep 1 & 3, 2026 · Attacking AI · Sep 22 & 24, 2026
HomeTrainingRed Blue Purple AI
Live Online · Sep 1 & 3, 2026

Red Blue Purple AI

Super-charge your day-to-day security workflow with AI tactics. A deep dive into using LLMs like GPT, Claude, and others to supercharge your work across all major domains of cybersecurity, taught live by Jason Haddix.

$2,000 USD LIVE · SEP 1 & 3, 2026 2 SESSIONS · 10AM-5PM MST ALL LEVELS
9/1 + 9/3
2026 · Live Online
2
Days · 10am–5pm MST
$2,000
USD · All Levels
v2.0
Latest Syllabus
Red Blue Purple AI course art
What you'll learn

Walk out with working AI workflows.

  • Evaluate and pick the right model (Claude, GPT, DeepSeek, Gemini, Llama 3) for security tasks and research
  • Apply privacy strategies for sensitive work: obfuscation, local-first models, Azure OpenAI
  • Engineer high-performance prompts with the Arcanum System Prompt Methodology and Systembot
  • Build domain-specific GPTs and micro-agents that take over repetitive security tasks
  • Augment recon and OSINT with custom GPTs like Subdomain Doctor and the Acquisition and Recon GPT
  • Accelerate web testing with LLM-assisted JavaScript analysis, filter bypass, CVE triage, and scanner scaling (Nuclei, Nessus)
  • Use the new Burp Suite AI features and extensions in day-to-day AppSec work
  • Extend red team ops with LLM-modified initial access payloads, Ducky Script, C2 research, and MCPs
  • Stand up SOC, DFIR, and threat hunting bots for ELK, Splunk, Suricata, YARA, OSQuery, and Wireshark
  • Automate IR playbooks, tabletops, exec briefings, and STIX data transformation
  • Drive AI-assisted code analysis and threat modeling with Semgrep, Snyk, and CodeQL workflows
  • Communicate risk and strategy at the CISO level with AI-generated executive briefs

What your employer gets

  • A practitioner who runs AI-accelerated offensive, SOC, DFIR, and threat hunting workflows across red, blue, and purple domains
  • Reusable prompts, bot templates, and the Arcanum System Prompt Methodology the whole team can adopt
  • Security bots and IR playbook automation mapped to tooling you already run: ELK, Splunk, Suricata, Burp Suite, Semgrep, and more
  • Force-multiplier output without head-count increases
  • Full class recordings, so the material can be reviewed on the team's own schedule
Course Description

Red Blue Purple AI, explained.

Over the past few years, I've had the privilege of straddling two passions: offensive security and generative AI. That obsession has snowballed into a series of talks, tools, and now, this course. Red Blue Purple AI is a deep-dive into using LLMs like GPT, Claude, and others to supercharge your work across all major domains of cybersecurity.

01

Built from practice, not theory

This course isn't just theory. It's built from real-world consulting, hands-on research, and daily workflows Jason uses as a practitioner.

02

Train, trick & optimize LLMs

We'll walk through not just how LLMs think, but how to train, trick, and optimize them to perform at a high level.

03

Leave with working bots

By the end, you'll have the knowledge to build domain-specific, high-performance bots that augment your workflow or even act autonomously.

See you in Red Blue Purple AI
Who This Is For

Practitioners who want to 10× their output.

If you're a security practitioner (offensive, defensive, or hybrid) or a curious leader looking to infuse AI into your security program, this course is for you.

RED / BLUE / PURPLE

Security engineers & teamers

Security engineers, SOC analysts, and red-, blue-, and purple-teamers who already know the fundamentals of their role but want to 10× their output.

SOLO / SMB

Consultants & small teams

Solo consultants and small teams that need "force-multipliers" without head-count increases.

EXEC

CISOs & security managers

Tech-savvy CISOs and security managers evaluating AI adoption for their operations.

Model IQ

// what you'll learn
  • Quick-start on LLM architecture, fine-tuning options, context windows, cost models

Prompt Engineering Patterns

// what you'll learn
  • Reusable templates for creating bots and agents

Bot Factory

// what you'll learn
  • Hands-on labs building GPTs and micro-agents that tackle repetitive tasks
v2.0 Syllabus

The full curriculum.

Every module from the current v2.0 syllabus. Expand each section for the complete topic list.

M01AI History & LLMs for Power Users
  • The modern rise of AI: GPT-3 onward
  • My own LLMs in action (e.g., Arcanum Cyber Security Bot, GPT Store bots)
  • Model evaluations: Claude, GPT, DeepSeek, Gemini, Llama 3, ++
  • My choices for security tasks, research, and user use cases
  • Privacy strategies: obfuscation, local-first, Azure OpenAI
  • LLM architecture basics: context windows, temperature, system prompts, RAG, Agents
  • MCP and MCP in Security
  • Chat interfaces vs APIs
  • Playgrounds for APIs
  • Cloud vs local models
  • Frontends: Ollama, LM Studio, OpenWebUI, Fabric, ++
M02Prompt Engineering
  • Problem solving for humans
  • Single-shot vs multi-shot
  • Chain-of-thought prompting
  • Metadata seeding
  • "Weird machine" tricks
  • The Arcanum System Prompt Methodology
  • Automation of best in class prompting via Systembot
M03New Ways to Use LLMs
  • NotebookLM
  • Browser "driving"
  • General agents
  • Streaming
  • AI aided development and best practices
  • Multiprompting
  • Automation frameworks
M04Breaking Down Security Programs
  • Mental modeling of Red, Blue, and Purple domains
  • Mapping day-to-day workflows to AI agents
  • Tools, pain points, and how AI fits into daily security tasks
M05Red AI (Offensive Security & AI)

Augmenting Recon, OSINT

  • Custom GPTs: Subdomain Doctor, Acquisition and Recon GPT
  • Phishing and pretexting with AI

Vuln Analysis and Exploitation (Web)

  • LLM-assisted AppSec testing questions
  • JavaScript Analysis
  • LLM assisted filter bypass
  • Web CVE Bot
  • Scaling automated scanners (Nuclei, Nessus)

Burp Suite

  • A complete overview of all new Burp Suite AI features and extensions

Vuln Analysis and Exploitation (Red Teaming)

  • Initial access payload modification with LLMs
  • Ducky Script
  • Extending your C2 and research capabilities with LLMs
  • MCPs for Red Teaming

Reverse Engineering · an overview of the current RE assist extensions and MCPs for:

  • Ghidra
  • IDA Pro
  • LLDB
  • RADARE
  • Binary Ninja

Automating Pentesting with AI

  • An overview of the open source space, research space, and startup space when it comes to automating hacking, with a breakdown of the most common architectures and technologies to achieve that goal

Misc

  • CloudSec, Privilege Escalation, Reporting with AI, and more
M06Blue AI (Defensive Operations & AI)

SOC, DFIR, and Threat Hunting bots

  • ELK Sec Bot
  • Splunk Bot
  • Suricata Bot
  • YARA
  • OSQuery
  • Wireshark
  • PolicyBot
  • IR playbook creation with Incident Responder Bot
  • Tabletop and exec briefing bots
  • STIX data transformation bot

The future of blue teaming: MCP SIEM

Vuln management

  • Best practices
  • Augmenting with LLMs
  • Automation approaches
M07Purple AI (Training & Simulation)

Code Analysis

  • Semgrep Bot
  • Snyk Bot
  • CodeQL resources
  • VulnHunter
  • MITRE ATT&CK
  • LLM-generated tabletops and security training tools
  • LLMs as force multipliers in program maturity and paved road security documentation
  • LLM Assisted Threat Modeling
M08Silver AI (Leadership, Strategy & Management)
  • AI for CISO-level decision making
  • Bots for risk communication and planning
  • Automation of executive briefs and strategic alignment
M09Future Tech and AI Research Frontiers
  • AI agents and autonomous security tools
  • The edge of AI-driven vulnerability discovery
  • Preparing for AGI-level assistants and ethical dilemmas
What's Included

Format, schedule & enrollment.

Live instructor-led training with recordings, so you can attend in real time or catch up on your own schedule.

Format

// included
  • Live Training and Q&A
  • Class Recordings Available Online
  • Certificate of Completion
  • Recommended Level: All Levels

Course Schedule

// live online
  • Day 1: Sept 1 · 10am-5pm MST
  • Day 2: Sept 3 · 10am-5pm MST

Enrollment

// $2,000 USD
  • Enroll online via Payhip
  • Bulk Purchases available
  • Instructor: Jason Haddix, CEO
Your Instructor

Taught by Jason Haddix.

JH
Jason Haddix
CEO · Lead Instructor

"Having dedicated years to the cybersecurity community, I've decided it's time to embark on a new journey: launching Arcanum Information Security, infused with a unique approach that sets us apart. At Arcanum, our mission is to make a tangible impact on the security community with world class, modern, and accessible training. In parallel to our training efforts, Arcanum aims to disrupt the consulting model with our unique consulting services."

Good to Know

Policies & access.

Refund & Access Policy

Because our training includes proprietary, cutting-edge content, all registrations are non-refundable. If you are unable to attend live sessions, full recordings will be provided following the conclusion of the course so you can access the material on your own schedule.

Can I buy seats for my whole team?

Yes. Bulk purchases and team discounts are available. Reach out and we'll set up seats and bulk pricing for your team.

Stay Looped In

Before class starts, plug in.

Ready for Red Blue Purple AI?

Live online, September 1st & 3rd, 2026 · $2,000 USD · recordings included.

★★★★★ Loved by students, Read the reviews →