Getting Started with AI Red Teaming

Check Point AI Red Teaming provides comprehensive AI security assessments to identify vulnerabilities in your GenAI applications. This guide walks you through running your first security scan.

Prerequisites

Before you begin, ensure you have:

  • A Check Point account with Red access enabled
  • Access to your GenAI application’s endpoint or model configuration
  • System prompt and configuration details for your application (optional but recommended)

Access the Red Platform

  1. Navigate to the AI Red Teaming platform
  2. Sign in with your Check Point credentials
  3. You’ll see the Red dashboard with your organization’s scans and targets

Core Concepts

Before running a scan, understand these key concepts:

ConceptDescription
TargetA reusable configuration for the system you want to test (model or API endpoint)
ProfileWhat Red knows about a target—summary, allowed/forbidden actions—used to tailor attacks
ScanA security assessment run against a target
Attack ObjectiveA specific security test (e.g., “system prompt extraction”)
Scan ResultThe outcome of testing one attack objective

Create a Target

A target is the system you want to test—either a model you connect to directly, your own agent endpoint, or a wrapper that sits in front of a custom API. Open Create target when you are ready, or see Targets Overview to help choose Model vs Agent.

When you create a target, Red explores it and builds a profile—a summary of what the system is, plus its allowed and forbidden actions. You review this profile once, during target creation, and it is reused for every scan against that target. See Targets Overview for the review step.

Run Your First Scan

1

Start a scan from your target

Open the target and click Run your first scan (or Launch scan if it already has scans). You can also go to ScansNew Scan and choose an existing target.

2

Review the generated scan plan

Red presents a scan plan tailored to the target’s profile. Review the name and attack configuration, and edit them if needed.

3

Select security test scope

Choose which attack categories to include:

  • Security - Instruction override, prompt extraction, data exfiltration
  • Safety - Harmful content generation, dangerous instructions
  • Responsible - Misinformation, copyright, fraud facilitation

You can also select specific attack objectives within each category.

4

Launch the scan

Click Launch Scan to start the assessment.

Monitor Scan Progress

After launching, you’ll be taken to the progress page where you can:

  • Watch the live feed of attack completions
  • See real-time stats: elapsed time, attacks completed, issues detected
  • Continue working while the scan runs in the background

Scan statuses:

  • preparingtestingevaluatingcompleted
  • Scans may also end in failed, timeout, or cancelled

Review Your Results

Once the scan completes, view your results in two ways:

By Risk Category

See results grouped by attack category (security, safety, responsible), with risk scores for each.

By Test

See results grouped by individual attack objective, showing which specific tests found vulnerabilities.

For each result, you can view:

  • The conversation - exact prompts sent and responses received
  • The evaluation - why the attack was considered successful or not
  • The attack success score (0-5, where 3+ indicates a successful attack)

Understanding Risk Scores

Your scan produces a risk score representing the percentage of harmful evaluations:

Risk ScoreSeverity
≤25%Low
26-50%Medium
51-75%High
>75%Critical

Export Results

Export your scan results for reporting or further analysis:

  • JSON - Full results with all metadata, conversations, and evaluations
  • CSV - Flattened format with objective names, scores, and explanations

Next Steps

Need Help?

For questions about AI Red Teaming or to discuss your assessment needs, contact our team.