

Direct vs Indirect Prompt Injection
In this free 30 minute lightning session, Max Robertson and Christian Urcuqui will use the TryHackMe platform to show, live, the practical difference between direct and indirect prompt injection: what each attack looks like, why they behave differently against real AI systems, and why the distinction matters when you're assessing an AI deployment.
This session is a preview of our full-day workshop, "Attacking AI Systems: Threat Model to Exploit" running on September 3. If you want a hands-on taste of what that day covers before committing, this is it.
Who this is for:
Security practitioners curious about AI as an attack surface
Pentesters and red teamers who want a clearer mental model of prompt injection types
Engineers and architects deploying AI who want to understand how it gets attacked
What you'll see:
A live walkthrough of direct prompt injection against an AI system on the TryHackMe platform
A live walkthrough of indirect prompt injection, including how attacker-controlled data becomes instructions
A breakdown of why the distinction changes how you'd defend against each
Hosted by:
Max Robertson, Senior Content Engineer at TryHackMe and lead of its AI Security Squad. Architect of the AI Security Learning Path and AI1 Cert.
Christian Urcuqui, Content Engineer at TryHackMe, Cyber AI researcher, author, and international speaker focused on AI security and cybersecurity education.