# engagement
標記為「engagement」的 47 篇文章
紅隊方法論評量
以 9 道中級題目測試你對 AI 紅隊演練方法論(從範圍界定到報告,包括結構化方法、攻擊規劃與發現記錄)的理解。
專業技能評量
以 15 道中級題目測試你對 AI 紅隊演練方法論、報告撰寫、客戶演練與專業實務的知識。
Capstone:完整聊天機器人演練
完整 Capstone 演練:對生產級聊天機器人系統進行完整紅隊演練。
Capstone:以 PyRIT 進行完整演練
使用 Microsoft PyRIT 的完整紅隊演練,涵蓋攻擊策略設定、多輪編排與自動化評分。
完整紅隊委任:端對端
自範圍至攻擊執行、證據蒐集、影響評估、報告遞送與補救驗證之 AI 紅隊委任完整指南。
完整案件方法論
進行完整 AI 紅隊案件的全面方法論,將先前章節的所有技術整合為結構化專業評估。
委任規劃與範疇界定
如何規劃並界定 AI 紅隊委任的範圍,包括目標設定、交戰規則、成功判準與方法論選擇。
頂石專案:完整紅隊演練專案
針對包含聊天機器人、RAG、代理與 API 各層的多元件 AI 應用,進行完整 AI 紅隊演練的範圍界定、規劃、執行與報告撰寫。
完整案件模擬
端對端紅隊案件模擬,複製真實世界 AI 安全評估,從範圍界定到報告交付。
委託追蹤與專案管理
以結構化追蹤工具、進度指標、時間管理與 Kanban/Jira 範本管理 AI 紅隊委託。
紅隊 Methodology 概覽
A structured methodology for AI red team engagements: phases, deliverables, role definitions, and how AI-specific testing differs from traditional penetration testing.
Scoping & Rules of Engagement
Defining scope, rules of engagement, authorization boundaries, and success criteria for AI red team engagements, with templates and checklists for common engagement types.
代理 System 紅隊 Engagement
Complete walkthrough for testing tool-using AI agents: scoping agent capabilities, exploiting function calling, testing permission boundaries, multi-step attack chains, and session manipulation.
AI API 紅隊 Engagement
Complete walkthrough for testing AI APIs: endpoint enumeration, authentication bypass, rate limit evasion, input validation testing, output data leakage, and model fingerprinting through API behavior.
Chatbot 紅隊 Engagement
Step-by-step walkthrough for a complete chatbot red team assessment: scoping, system prompt extraction, content filter bypass, PII leakage testing, multi-turn manipulation, and professional reporting.
Full 演練: AI Code Assistant
End-to-end engagement for assessing an AI-powered code assistant with repository access.
Full 演練: Content Generation Platform
Full engagement walkthrough for a content generation AI platform with brand safety and copyright concerns.
完整演練:客戶分析 AI 安全評估
Red team engagement for an AI-powered customer analytics system processing sensitive behavioral data.
Full 演練: AI Developer Tools
End-to-end engagement for AI-powered developer tools with repository access and code execution capabilities.
Full 演練: Educational AI Platform
End-to-end engagement walkthrough for an AI-powered educational platform with student safety requirements.
Full 演練: AI Financial Advisor
Full engagement for assessing an AI financial advisor chatbot handling investment recommendations.
Full 演練: Government AI System
Full red team engagement for a government-deployed AI system with classification and compliance requirements.
Full 演練: Healthcare AI System
End-to-end engagement walkthrough for a healthcare AI system with HIPAA compliance requirements.
完整演練:內部知識機器人安全評估
Full engagement walkthrough for an internal enterprise knowledge bot with RAG and document access.
完整演練:多代理平台安全評估
Full red team engagement of a multi-agent platform with MCP servers and A2A communication.
Full 演練: SaaS Customer Chatbot
End-to-end engagement walkthrough for assessing a SaaS customer-facing chatbot with tool access.
Full 演練: ML Supply Chain Audit
End-to-end engagement walkthrough for auditing an organization's ML model supply chain security.
Multi-模型 System 紅隊 Engagement
Complete walkthrough for testing systems that use multiple AI models: model-to-model injection, routing logic exploitation, fallback chain abuse, inter-model data leakage, and orchestration layer attacks.
RAG System 紅隊 Engagement
Complete walkthrough for testing RAG applications: document injection, cross-scope retrieval exploitation, embedding manipulation, data exfiltration through retrieval, and chunk boundary attacks.
Full 演練: Autonomous Coding Agent
End-to-end engagement for an autonomous AI coding agent with repo access, CI/CD integration, and deployment.
Full 演練: AI Content Generation Platform
Red team engagement of an AI content generation platform used for marketing, SEO, and social media.
Full 演練: Multi-Tool Customer Support Agent
End-to-end engagement for a customer support agent with order management, refund processing, and CRM access.
Full 演練: DevOps AI Assistant
End-to-end engagement for a DevOps AI assistant with CI/CD, cloud infrastructure, and monitoring access.
Full 演練: Document Processing Pipeline
Full engagement of an AI document processing pipeline handling invoices, contracts, and compliance documents.
Full 演練: AI Education Platform
End-to-end engagement walkthrough for assessing an AI-powered education platform with tutoring and grading.
Full 演練: Government Citizen Services AI
Red team engagement of a government citizen services AI handling tax, benefits, and identity verification.
Full 演練: HR Benefits Chatbot
Full engagement walkthrough for an HR benefits chatbot with access to employee records and benefits administration.
Full 演練: AI Insurance Underwriting
Full engagement for an AI underwriting system with risk scoring, policy generation, and claims data access.
Full 演練: Legal Research AI System
Full red team engagement of a legal research AI with case law access, privilege management, and citation generation.
Full 演練: Enterprise Multi-Agent System
Full engagement of an enterprise multi-agent system with specialized agents for HR, IT, Finance, and Legal.
Full 演練: Retail Personalization AI
Red team engagement of an AI personalization engine with access to customer profiles and purchase history.
Full 演練: AI Security Copilot
Red team engagement of an AI security copilot with access to SIEM, vulnerability scanners, and threat intelligence.
Full 演練: Supply Chain AI Optimizer
End-to-end engagement for a supply chain AI with access to logistics, inventory, and supplier management systems.
Full 演練: Telehealth AI Assistant
End-to-end engagement for a telehealth AI assistant with appointment scheduling, symptom assessment, and EHR access.
委任啟動流程指南
啟動 AI 紅隊委任的逐步指南:客戶初次會議、範圍界定、交戰規則、法律協議、環境設置與工具選擇。
方法論導覽
AI 紅隊案件每個階段的逐步導覽:啟動、偵察、攻擊執行與報告撰寫。
How to Scope an AI 紅隊 Engagement
Comprehensive walkthrough for scoping AI red team engagements from initial client contact through statement of work, covering target enumeration, risk-based prioritization, resource estimation, boundary definition, and legal considerations.