16 tactics101 techniques35 mitigations
ATLASAdversarial ML attack surface
MITRE ATLAS · 16 tactics · 101 techniques · 69 sub-techniques · 35 mitigations. Authored by Adam Lundqvist.
Adversarial ML attack surface — designed for EU AI Act Art. 15 compliance pentesting.
SQUR ships annual TLPT against the ATLAS technique set as standard. Adversarial-ML coverage is not the same as IT-stack coverage — scope it explicitly when planning AI Act Art. 15 conformity.
Scope an AI pentest →Coloured by sub-technique depth
sub-technique depth
0
1
2-3
4-5
6+
AML.TA0000AI Model Access4 techniques
AML.T0040
AML.T0040 AI Model Inference API Access
No sub-techniques indexed
Tactic: ai-model-access · Click to inspect
AML.T0041
AML.T0041 Physical Environment Access
No sub-techniques indexed
Tactic: ai-model-access · Click to inspect
AML.T0044
AML.T0044 Full AI Model Access
No sub-techniques indexed
Tactic: ai-model-access · Click to inspect
AML.T0047
AML.T0047 AI-Enabled Product or Service
No sub-techniques indexed
Tactic: ai-model-access · Click to inspect
AML.TA0001AI Attack Staging6 techniques
AML.T0043
▾ 5
AML.T0043 Craft Adversarial Data
5 sub-techniques indexed
Tactic: ai-attack-staging · Click to inspect
AML.T0005
▾ 3
AML.T0005 Create Proxy AI Model
3 sub-techniques indexed
Tactic: ai-attack-staging · Click to inspect
AML.T0018
▾ 3
AML.T0018 Manipulate AI Model
3 sub-techniques indexed
Tactic: persistence, ai-attack-staging · Click to inspect
AML.T0042
AML.T0042 Verify Attack
No sub-techniques indexed
Tactic: ai-attack-staging · Click to inspect
AML.T0088
AML.T0088 Generate Deepfakes
No sub-techniques indexed
Tactic: ai-attack-staging · Click to inspect
AML.T0102
AML.T0102 Generate Malicious Commands
No sub-techniques indexed
Tactic: ai-attack-staging · Click to inspect
AML.TA0002Reconnaissance8 techniques
AML.T0000
▾ 3
AML.T0000 Search Open Technical Databases
3 sub-techniques indexed
Tactic: reconnaissance · Click to inspect
AML.T0095
▾ 1
AML.T0095 Search Open Websites/Domains
1 sub-technique indexed
Tactic: reconnaissance · Click to inspect
AML.T0001
AML.T0001 Search Open AI Vulnerability Analysis
No sub-techniques indexed
Tactic: reconnaissance · Click to inspect
AML.T0003
AML.T0003 Search Victim-Owned Websites
No sub-techniques indexed
Tactic: reconnaissance · Click to inspect
AML.T0004
AML.T0004 Search Application Repositories
No sub-techniques indexed
Tactic: reconnaissance · Click to inspect
AML.T0006
AML.T0006 Active Scanning
No sub-techniques indexed
Tactic: reconnaissance · Click to inspect
AML.T0064
AML.T0064 Gather RAG-Indexed Targets
No sub-techniques indexed
Tactic: reconnaissance · Click to inspect
AML.T0087
AML.T0087 Gather Victim Identity Information
No sub-techniques indexed
Tactic: reconnaissance · Click to inspect
AML.TA0003Resource Development13 techniques
AML.T0008
▾ 6
AML.T0008 Acquire Infrastructure
6 sub-techniques indexed
Tactic: resource-development · Click to inspect
AML.T0002
▾ 3
AML.T0002 Acquire Public AI Artifacts
3 sub-techniques indexed
Tactic: resource-development · Click to inspect
AML.T0016
▾ 3
AML.T0016 Obtain Capabilities
3 sub-techniques indexed
Tactic: resource-development · Click to inspect
AML.T0017
▾ 1
AML.T0017 Develop Capabilities
1 sub-technique indexed
Tactic: resource-development · Click to inspect
AML.T0019
AML.T0019 Publish Poisoned Datasets
No sub-techniques indexed
Tactic: resource-development · Click to inspect
AML.T0020
AML.T0020 Poison Training Data
No sub-techniques indexed
Tactic: resource-development, persistence · Click to inspect
AML.T0021
AML.T0021 Establish Accounts
No sub-techniques indexed
Tactic: resource-development · Click to inspect
AML.T0058
AML.T0058 Publish Poisoned Models
No sub-techniques indexed
Tactic: resource-development · Click to inspect
AML.T0060
AML.T0060 Publish Hallucinated Entities
No sub-techniques indexed
Tactic: resource-development · Click to inspect
AML.T0065
AML.T0065 LLM Prompt Crafting
No sub-techniques indexed
Tactic: resource-development · Click to inspect
AML.T0066
AML.T0066 Retrieval Content Crafting
No sub-techniques indexed
Tactic: resource-development · Click to inspect
AML.T0079
AML.T0079 Stage Capabilities
No sub-techniques indexed
Tactic: resource-development · Click to inspect
AML.T0104
AML.T0104 Publish Poisoned AI Agent Tool
No sub-techniques indexed
Tactic: resource-development · Click to inspect
AML.TA0004Initial Access7 techniques
AML.T0010
▾ 6
AML.T0010 AI Supply Chain Compromise
6 sub-techniques indexed
Tactic: initial-access · Click to inspect
AML.T0052
▾ 2
AML.T0052 Phishing
2 sub-techniques indexed
Tactic: initial-access, lateral-movement · Click to inspect
AML.T0012
AML.T0012 Valid Accounts
No sub-techniques indexed
Tactic: initial-access, privilege-escalation · Click to inspect
AML.T0015
AML.T0015 Evade AI Model
No sub-techniques indexed
Tactic: initial-access, defense-evasion, impact · Click to inspect
AML.T0049
AML.T0049 Exploit Public-Facing Application
No sub-techniques indexed
Tactic: initial-access · Click to inspect
AML.T0078
AML.T0078 Drive-by Compromise
No sub-techniques indexed
Tactic: initial-access · Click to inspect
AML.T0093
AML.T0093 Prompt Infiltration via Public-Facing Application
No sub-techniques indexed
Tactic: initial-access, persistence · Click to inspect
AML.TA0005Execution6 techniques
AML.T0011
▾ 4
AML.T0011 User Execution
4 sub-techniques indexed
Tactic: execution · Click to inspect
AML.T0051
▾ 3
AML.T0051 LLM Prompt Injection
3 sub-techniques indexed
Tactic: execution · Click to inspect
AML.T0050
AML.T0050 Command and Scripting Interpreter
No sub-techniques indexed
Tactic: execution · Click to inspect
AML.T0053
AML.T0053 AI Agent Tool Invocation
No sub-techniques indexed
Tactic: execution, privilege-escalation · Click to inspect
AML.T0100
AML.T0100 AI Agent Clickbait
No sub-techniques indexed
Tactic: execution · Click to inspect
AML.T0103
AML.T0103 Deploy AI Agent
No sub-techniques indexed
Tactic: execution · Click to inspect
AML.TA0006Persistence9 techniques
AML.T0018
▾ 3
AML.T0018 Manipulate AI Model
3 sub-techniques indexed
Tactic: persistence, ai-attack-staging · Click to inspect
AML.T0080
▾ 2
AML.T0080 AI Agent Context Poisoning
2 sub-techniques indexed
Tactic: persistence · Click to inspect
AML.T0020
AML.T0020 Poison Training Data
No sub-techniques indexed
Tactic: resource-development, persistence · Click to inspect
AML.T0061
AML.T0061 LLM Prompt Self-Replication
No sub-techniques indexed
Tactic: persistence · Click to inspect
AML.T0070
AML.T0070 RAG Poisoning
No sub-techniques indexed
Tactic: persistence · Click to inspect
AML.T0081
AML.T0081 Modify AI Agent Configuration
No sub-techniques indexed
Tactic: persistence, defense-evasion · Click to inspect
AML.T0093
AML.T0093 Prompt Infiltration via Public-Facing Application
No sub-techniques indexed
Tactic: initial-access, persistence · Click to inspect
AML.T0099
AML.T0099 AI Agent Tool Data Poisoning
No sub-techniques indexed
Tactic: persistence · Click to inspect
AML.T0110
AML.T0110 AI Agent Tool Poisoning
No sub-techniques indexed
Tactic: persistence · Click to inspect
AML.TA0007Defense Evasion15 techniques
AML.T0067
▾ 1
AML.T0067 LLM Trusted Output Components Manipulation
1 sub-technique indexed
Tactic: defense-evasion · Click to inspect
AML.T0015
AML.T0015 Evade AI Model
No sub-techniques indexed
Tactic: initial-access, defense-evasion, impact · Click to inspect
AML.T0054
AML.T0054 LLM Jailbreak
No sub-techniques indexed
Tactic: privilege-escalation, defense-evasion · Click to inspect
AML.T0068
AML.T0068 LLM Prompt Obfuscation
No sub-techniques indexed
Tactic: defense-evasion · Click to inspect
AML.T0071
AML.T0071 False RAG Entry Injection
No sub-techniques indexed
Tactic: defense-evasion · Click to inspect
AML.T0073
AML.T0073 Impersonation
No sub-techniques indexed
Tactic: defense-evasion · Click to inspect
AML.T0074
AML.T0074 Masquerading
No sub-techniques indexed
Tactic: defense-evasion · Click to inspect
AML.T0076
AML.T0076 Corrupt AI Model
No sub-techniques indexed
Tactic: defense-evasion · Click to inspect
AML.T0081
AML.T0081 Modify AI Agent Configuration
No sub-techniques indexed
Tactic: persistence, defense-evasion · Click to inspect
AML.T0092
AML.T0092 Manipulate User LLM Chat History
No sub-techniques indexed
Tactic: defense-evasion · Click to inspect
AML.T0094
AML.T0094 Delay Execution of LLM Instructions
No sub-techniques indexed
Tactic: defense-evasion · Click to inspect
AML.T0097
AML.T0097 Virtualization/Sandbox Evasion
No sub-techniques indexed
Tactic: defense-evasion · Click to inspect
AML.T0107
AML.T0107 Exploitation for Defense Evasion
No sub-techniques indexed
Tactic: defense-evasion · Click to inspect
AML.T0109
AML.T0109 AI Supply Chain Rug Pull
No sub-techniques indexed
Tactic: defense-evasion · Click to inspect
AML.T0111
AML.T0111 AI Supply Chain Reputation Inflation
No sub-techniques indexed
Tactic: defense-evasion · Click to inspect
AML.TA0008Discovery9 techniques
AML.T0084
▾ 4
AML.T0084 Discover AI Agent Configuration
4 sub-techniques indexed
Tactic: discovery · Click to inspect
AML.T0069
▾ 3
AML.T0069 Discover LLM System Information
3 sub-techniques indexed
Tactic: discovery · Click to inspect
AML.T0007
AML.T0007 Discover AI Artifacts
No sub-techniques indexed
Tactic: discovery · Click to inspect
AML.T0013
AML.T0013 Discover AI Model Ontology
No sub-techniques indexed
Tactic: discovery · Click to inspect
AML.T0014
AML.T0014 Discover AI Model Family
No sub-techniques indexed
Tactic: discovery · Click to inspect
AML.T0062
AML.T0062 Discover LLM Hallucinations
No sub-techniques indexed
Tactic: discovery · Click to inspect
AML.T0063
AML.T0063 Discover AI Model Outputs
No sub-techniques indexed
Tactic: discovery · Click to inspect
AML.T0075
AML.T0075 Cloud Service Discovery
No sub-techniques indexed
Tactic: discovery · Click to inspect
AML.T0089
AML.T0089 Process Discovery
No sub-techniques indexed
Tactic: discovery · Click to inspect
AML.TA0009Collection4 techniques
AML.T0085
▾ 2
AML.T0085 Data from AI Services
2 sub-techniques indexed
Tactic: collection · Click to inspect
AML.T0035
AML.T0035 AI Artifact Collection
No sub-techniques indexed
Tactic: collection · Click to inspect
AML.T0036
AML.T0036 Data from Information Repositories
No sub-techniques indexed
Tactic: collection · Click to inspect
AML.T0037
AML.T0037 Data from Local System
No sub-techniques indexed
Tactic: collection · Click to inspect
AML.TA0010Exfiltration6 techniques
AML.T0024
▾ 3
AML.T0024 Exfiltration via AI Inference API
3 sub-techniques indexed
Tactic: exfiltration · Click to inspect
AML.T0025
AML.T0025 Exfiltration via Cyber Means
No sub-techniques indexed
Tactic: exfiltration · Click to inspect
AML.T0056
AML.T0056 Extract LLM System Prompt
No sub-techniques indexed
Tactic: exfiltration · Click to inspect
AML.T0057
AML.T0057 LLM Data Leakage
No sub-techniques indexed
Tactic: exfiltration · Click to inspect
AML.T0077
AML.T0077 LLM Response Rendering
No sub-techniques indexed
Tactic: exfiltration · Click to inspect
AML.T0086
AML.T0086 Exfiltration via AI Agent Tool Invocation
No sub-techniques indexed
Tactic: exfiltration · Click to inspect
AML.TA0011Impact9 techniques
AML.T0048
▾ 5
AML.T0048 External Harms
5 sub-techniques indexed
Tactic: impact · Click to inspect
AML.T0034
▾ 3
AML.T0034 Cost Harvesting
3 sub-techniques indexed
Tactic: impact · Click to inspect
AML.T0112
▾ 2
AML.T0112 Machine Compromise
2 sub-techniques indexed
Tactic: impact · Click to inspect
AML.T0015
AML.T0015 Evade AI Model
No sub-techniques indexed
Tactic: initial-access, defense-evasion, impact · Click to inspect
AML.T0029
AML.T0029 Denial of AI Service
No sub-techniques indexed
Tactic: impact · Click to inspect
AML.T0031
AML.T0031 Erode AI Model Integrity
No sub-techniques indexed
Tactic: impact · Click to inspect
AML.T0046
AML.T0046 Spamming AI System with Chaff Data
No sub-techniques indexed
Tactic: impact · Click to inspect
AML.T0059
AML.T0059 Erode Dataset Integrity
No sub-techniques indexed
Tactic: impact · Click to inspect
AML.T0101
AML.T0101 Data Destruction via AI Agent Tool Invocation
No sub-techniques indexed
Tactic: impact · Click to inspect
AML.TA0012Privilege Escalation4 techniques
AML.T0012
AML.T0012 Valid Accounts
No sub-techniques indexed
Tactic: initial-access, privilege-escalation · Click to inspect
AML.T0053
AML.T0053 AI Agent Tool Invocation
No sub-techniques indexed
Tactic: execution, privilege-escalation · Click to inspect
AML.T0054
AML.T0054 LLM Jailbreak
No sub-techniques indexed
Tactic: privilege-escalation, defense-evasion · Click to inspect
AML.T0105
AML.T0105 Escape to Host
No sub-techniques indexed
Tactic: privilege-escalation · Click to inspect
AML.TA0013Credential Access6 techniques
AML.T0055
AML.T0055 Unsecured Credentials
No sub-techniques indexed
Tactic: credential-access · Click to inspect
AML.T0082
AML.T0082 RAG Credential Harvesting
No sub-techniques indexed
Tactic: credential-access · Click to inspect
AML.T0083
AML.T0083 Credentials from AI Agent Configuration
No sub-techniques indexed
Tactic: credential-access · Click to inspect
AML.T0090
AML.T0090 OS Credential Dumping
No sub-techniques indexed
Tactic: credential-access · Click to inspect
AML.T0098
AML.T0098 AI Agent Tool Credential Harvesting
No sub-techniques indexed
Tactic: credential-access · Click to inspect
AML.T0106
AML.T0106 Exploitation for Credential Access
No sub-techniques indexed
Tactic: credential-access · Click to inspect
AML.TA0014Command and Control3 techniques
AML.T0072
AML.T0072 Reverse Shell
No sub-techniques indexed
Tactic: command-and-control · Click to inspect
AML.T0096
AML.T0096 AI Service API
No sub-techniques indexed
Tactic: command-and-control · Click to inspect
AML.T0108
AML.T0108 AI Agent
No sub-techniques indexed
Tactic: command-and-control · Click to inspect
AML.TA0015Lateral Movement2 techniques
AML.T0052
▾ 2
AML.T0052 Phishing
2 sub-techniques indexed
Tactic: initial-access, lateral-movement · Click to inspect
AML.T0091
▾ 1
AML.T0091 Use Alternate Authentication Material
1 sub-technique indexed
Tactic: lateral-movement · Click to inspect