Lección 3 de 9 · 8 min
MITRE ATLAS: mapping an attack on an AI system
Learn how ATLAS organises tactics, techniques, mitigations and case studies, then map a real documented attack on an AI assistant step by step.
Por ahora esta página está en inglés.
If NIST AI RMF tells you how to organise AI risk work, MITRE ATLAS tells you what attackers actually do. ATLAS stands for Adversarial Threat Landscape for AI Systems, and its maintainers describe it as “a public knowledge base of adversary TTPs targeting AI systems”, where TTPs are tactics, techniques and procedures. Teams use it the way they use any threat knowledge base: to plan tests, to describe findings in a shared language and to check that defences cover realistic attack paths.
How ATLAS is organised
- Tactics are the adversary’s goals at each stage. The ATLAS matrix shows 16 columns: Reconnaissance, Resource Development, AI Attack Adaptation, Initial Access, AI Model Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration and Impact.
- Techniques are the ways a tactic is achieved, with sub-techniques for variants. In the data, tactic IDs look like AML.TA0005, techniques like AML.T0051 and sub-techniques like AML.T0051.001.
- Mitigations (AML.M####) are defensive measures linked to the techniques they reduce.
- Case studies (AML.CS####) are documented attacks, marked as either an incident or an exercise, with each step tied to a technique and a tactic.
The 2026.09 release of the ATLAS data, dated 15 September 2026, contains 16 tactics, 208 technique and sub-technique entries, 40 mitigations and 73 case studies. Releases are monthly, so cite the version you used. On the matrix you can filter by platform (predictive AI, generative AI, agentic AI, enterprise) and by maturity: feasible, demonstrated or realized. Those labels are a quick way to prioritise a test plan.
A worked example: Slack AI (AML.CS0035)
The case study “Data Exfiltration from Slack AI via Indirect Prompt Injection” is an exercise by the security firm PromptArmor, dated 20 August 2024. ATLAS summarises it this way: the attack relied on Slack AI ingesting a malicious prompt from a post in a public channel into its retrieval database, and then a victim user querying Slack AI, which caused the prompt to be retrieved and executed. The researchers targeted an API key stored in a private channel. Here is how ATLAS breaks the procedure into steps:
| Step | What the researcher did | ATLAS technique | Tactic |
|---|---|---|---|
| S00 | Crafted a message that would be retrieved when a user asks about the API key | Retrieval Content Crafting (AML.T0066) | AI Attack Adaptation |
| S01 | Crafted a prompt that makes the assistant reveal the key in a link | LLM Prompt Crafting (AML.T0065) | AI Attack Adaptation |
| S02 | Used an ordinary non-admin account in the workspace | Valid Accounts (AML.T0012) | Initial Access |
| S03 | Interacted with the assistant by posting in public channels | AI-Enabled Product or Service (AML.T0047) | AI Model Access |
| S04 | Posted the malicious content so it entered the retrieval index | RAG Poisoning (AML.T0070) | Persistence |
| S05 | The victim’s query retrieved the content and the assistant followed it | LLM Prompt Injection: Indirect (AML.T0051.001) | Execution |
| S06 | The assistant retrieved the key from the victim’s private channels | RAG Credential Harvesting (AML.T0082) | Credential Access |
| S07 | The response rendered as a link that sent the key to the researcher’s server | LLM Response Rendering (AML.T0077) | Exfiltration |
Notice what this mapping gives a defender. No step required breaking the model. Each depends on a design decision in the application: what the assistant may retrieve, whose content it indexes, what permissions it holds for the person asking, and how its output is rendered. That is why OWASP calls related weaknesses prompt injection, excessive agency or improper output handling: the same chain, seen from the vulnerability side. The next lesson covers that view.
Turning the map into a test plan
- List the assets and entry points of your system: data sources the model retrieves from, tools it can call, accounts it acts through.
- Pick the relevant platform filters, then start with the techniques at the demonstrated and realized maturity levels.
- Write each test as a short chain of tactics, as in the table, so a finding is a path and not an isolated trick.
- For each technique, look up its mitigations. ATLAS lists, for example, Human In-the-Loop for AI Agent Actions (AML.M0029), Restrict AI Agent Tool Invocation on Untrusted Data (AML.M0030), AI Agent Tools Permissions Configuration (AML.M0028) and AI Telemetry Logging (AML.M0024).
- Record the ATLAS IDs in your report. ATLAS also has a mitigation named AI Red Team (AML.M0035), which describes recurring, authorised, threat-informed exercises before deployment and throughout operation.
One caution: ATLAS shows what has been demonstrated, not what is likely in your organisation. A technique rated feasible may matter more to you than a realized one, depending on what your system exposes. Use the knowledge base to widen your thinking, then let your own architecture decide priorities.
Lo esencial
- ATLAS is a public knowledge base of adversary tactics, techniques, mitigations and case studies for AI systems, released monthly.
- A case study breaks an attack into steps, each mapped to a technique and a tactic, so a finding becomes a path.
- Filters for platform (predictive, generative, agentic, enterprise) and maturity (feasible, demonstrated, realized) help prioritise tests.
- Record ATLAS IDs and the release version in reports so others can reproduce and compare.
Ponte a prueba
1. In ATLAS, what is a case study?
- A list of laws
- A documented attack, marked as an incident or an exercise, whose steps are mapped to techniques and tactics — Correcto.
- A vendor comparison
- A defensive checklist
Case studies (AML.CS####) document real incidents or exercises and tie each step to an ATLAS technique and tactic.
2. In the Slack AI case study, how did the malicious instruction reach the assistant?
- By breaking the model’s weights
- By being posted in a public channel that the assistant indexed and later retrieved for a victim’s query — Correcto.
- By a network man-in-the-middle
- By a stolen administrator password
The researcher used an ordinary account to post content that entered the retrieval database; when a victim’s query retrieved it, the assistant followed it (indirect prompt injection).
3. Why should reports state the ATLAS release you used?
- ATLAS content and IDs change over time, with monthly releases — Correcto.
- ATLAS requires a licence per release
- Releases are yearly and identical
- It is only a formatting rule
ATLAS publishes monthly content updates (for example 2026.09), so techniques, mitigations and case studies can be added or revised.
Ponlo en práctica con FireAI
Pon esta lección en práctica en tu propio Mac.
- Reglas: app, sitio web, dominio, IP o un rango, para siempre o hasta que reinicies — Escribe una regla tan precisa como una sola dirección o tan amplia como un dominio entero.
- Investiga una conexión — Decide con los hechos delante, no con una advertencia vaga.
- El Mapa mundial — Ve a dónde va realmente tu información, no solo un nombre de host que tendrías que buscar tú mismo.
- Requests by country and upload spikes — See at a glance where your Mac talks to, and notice at once when it suddenly sends a lot of data somewhere.
- Listas de amenazas (opcional) — Compara tu tráfico con datos públicos de amenazas sin enviarlo a ningún sitio.
- Modos de seguridad: Casa, Cafetería, Paranoico, Bajo ataque — Ajusta la firmeza de FireAI al lugar donde realmente está tu Mac, en un toque.
Fuentes
- MITRE ATLAS: matrix for AI systems
- MITRE ATLAS data repository (versioning, ID conventions)
- MITRE ATLAS data release 2026.09 (YAML)
Ponlo en práctica en tu Mac
Prueba todas las funciones gratis durante 17 días, sin tarjeta.