AI Security Red-Team Simulation
Budget: $250 – $750 USD
Scope of Work
1. Environment Setup
- Deploy n8n workflow automation platform with a simple pipeline (e.g., webhook → OpenAI API → Google Sheets/Email).
- Deploy AgentScope for adversarial prompt injection and agent spoofing simulations.
- Deploy a minimal MITRE Caldera instance for one or two agent-based attacks (e.g., data exfiltration).
2. Attack Simulations
- Simulate prompt injection attacks targeting the n8n → LLM workflow.
- Simulate agent spoofing to hijack instructions or workflow logic.
- Simulate data exfiltration using Caldera agents (e.g., stealing logs or API keys).
3. Defense Hardening
- Implement basic prompt sanitization middleware for the n8n pipeline (regex/token checks).
- Add monitoring and alerting mechanisms for unusual inputs/outputs.
- Map all simulated attacks to MITRE ATT&CK techniques for formal documentation.
4. Deliverables
- Functional PoC lab environment (Dockerized preferred).
- Clear lab architecture diagram (showing workflow + attack paths).
- Attack/Defense demonstrations with logs and results.
- Final defense matrix showing attacks, MITRE mapping, and mitigation strategies.
(For additional information we can discuss more, and any valuable notes will be appreciated)
1. Environment Setup
- Deploy n8n workflow automation platform with a simple pipeline (e.g., webhook → OpenAI API → Google Sheets/Email).
- Deploy AgentScope for adversarial prompt injection and agent spoofing simulations.
- Deploy a minimal MITRE Caldera instance for one or two agent-based attacks (e.g., data exfiltration).
2. Attack Simulations
- Simulate prompt injection attacks targeting the n8n → LLM workflow.
- Simulate agent spoofing to hijack instructions or workflow logic.
- Simulate data exfiltration using Caldera agents (e.g., stealing logs or API keys).
3. Defense Hardening
- Implement basic prompt sanitization middleware for the n8n pipeline (regex/token checks).
- Add monitoring and alerting mechanisms for unusual inputs/outputs.
- Map all simulated attacks to MITRE ATT&CK techniques for formal documentation.
4. Deliverables
- Functional PoC lab environment (Dockerized preferred).
- Clear lab architecture diagram (showing workflow + attack paths).
- Attack/Defense demonstrations with logs and results.
- Final defense matrix showing attacks, MITRE mapping, and mitigation strategies.
(For additional information we can discuss more, and any valuable notes will be appreciated)