This talk presents a practical methodology and toolset, developed through two years of pentesting enterprise GenAI and LLM application use cases, for testing the security of LLM applications and GenAI features in real-world, time-constrained assessments. Rather than focusing on unsafe conversations or vague “AI risk”, we focus on concrete cybersecurity outcomes, exfiltration, XSS, DoS, and social engineering, through prompt injection.