AI Threat Modelling - MegaCorp’s AI Assistant Exercise
Assess and mitigate enterprise AI/ML risks via systematic, defender-focused auditing.
AI Threat Modelling - MegaCorp’s AI Assistant Exercise
Assess and mitigate enterprise AI/ML risks via systematic, defender-focused auditing.
Disclaimer: This blog post is based on a walkthrough hosted on TryHackMe and it is intended for educational purposes only.
This room is defender-focused, you’ll learn to evaluate and document AI threats, not exploit them.
Learning Objectives
- Identify AI-specific assets and attack surfaces that don’t exist in traditional applications
- Apply STRIDE threat categories to AI/ML system components with appropriate context
- Use MITRE ATLAS to enumerate adversarial techniques targeting AI systems
- Map OWASP LLM Top 10 risks to architectural components to identify where threats live and how to prioritise them
- Produce a structured threat assessment for an AI deployment
💪 Difficulty: Medium
🔗Link: https://tryhackme.com/room/aithreatmodelling

In a RAG-based system, which AI asset type is used to retrieve relevant context at query time?

An attacker gains access to MegaCorp’s model registry and swaps the production model for a modified version. Which AI-specific asset has been compromised?

An attacker injects crafted data points into a training pipeline over several months, gradually shifting the model’s decision boundaries. At which supply chain stage does the attacker inject the malicious data?

Which STRIDE category is insufficient for capturing the delayed, diffuse effects of training data poisoning?

What is the primary AI-specific manifestation of Information Disclosure in the STRIDE-AI mapping?

An attacker crafts prompts that cause an LLM to bypass its safety guidelines and content restrictions. Which STRIDE category does this map to?

Which OWASP LLM Top 10 (2025) entry addresses the risks of AI systems being granted too many permissions or too much autonomy?

An attacker drives your monthly inference bill from $15,000 to $180,000 without taking your service offline. What is this type of attack commonly called?

What does the acronym ATLAS stand for?

Which ATLAS case study described a self-replicating prompt injection worm that spread between AI agents via RAG email systems?

What is the ATLAS technique ID for Model Extraction?

How many of the OWASP LLM Top 10 entries affect the LLM Inference Endpoint?

An organisation notices their chatbot is rendering LLM output directly in the browser without sanitisation. Which OWASP entry does this fall under?

Which component in a typical LLM architecture is the primary one that needs hardening against data and model supply chain risks (LLM03)?

Practical: Threat Modelling MegaCorp’s AI Assistant
Click the green View Site button to open the AI Threat Modelling exercise: you’ll be selecting OWASP LLM Top 10 vulnerabilities, mapping them to architecture components, and justifying your choices to put your threat modelling instincts to the test. This task can be used to practice your knowledge of AI systems and threats. Good luck!
What’s the flag?

메타데이터
- post_id
- 35edaae3ef0d
- slug
- ai-threat-modelling-megacorps-ai-assistant-exercise-35edaae3ef0d
- url
- https://medium.com/@josepraveen/ai-threat-modelling-megacorps-ai-assistant-exercise-35edaae3ef0d
- canonical_url
- https://medium.com/@josepraveen/ai-threat-modelling-megacorps-ai-assistant-exercise-35edaae3ef0d
- author_url
- https://medium.com/@josepraveen
- status
- ok
- fetched_at
- 2026-08-30 21:26:28