hego.red - Practical AI/LLM Red Teaming Notes

Practical notes on AI/LLM red teaming

From zero to hero of AI hacking

hego.red is my personal notebook for hacking AI systems, cleaned up and shared. I went through hundreds of sources, articles, talks, courses, and research, and mixed them into one clear place, so you don't have to dig around. It is the guide I wish I had when I started, and it takes you from your first prompt injection to attacking real LLM apps.

Everything here is about what actually works on real targets, not just theory. You learn how LLMs break, all the main attacks (prompt injection, jailbreaks, indirect injection, stealing data, and abusing tools and agents), and a clear step by step way to test them that follows the OWASP LLM Top 10 and MITRE ATLAS. There are also worked, hands-on labs (including PortSwigger walkthroughs) so you can practice. It is all written from the attacker's point of view, so you can use it right away.

I keep it updated as things change and as I learn new tricks, so check back now and then. Start at Foundation, go through the tabs in order, tick the boxes as you go, and press / to search. A hands-on Lab is coming soon.

Only use this on systems you own or have clear permission to test. It is here for learning and real, authorized security work, nothing else. What you do with it is on you.

Built by hego.