Lektion 3 av 9 · 8 min
MITRE ATLAS: mapping an attack on an AI system
Learn how ATLAS organises tactics, techniques, mitigations and case studies, then map a real documented attack on an AI assistant step by step.
Den här sidan finns på engelska tills vidare.
If NIST AI RMF tells you how to organise AI risk work, MITRE ATLAS tells you what attackers actually do. ATLAS stands for Adversarial Threat Landscape for AI Systems, and its maintainers describe it as “a public knowledge base of adversary TTPs targeting AI systems”, where TTPs are tactics, techniques and procedures. Teams use it the way they use any threat knowledge base: to plan tests, to describe findings in a shared language and to check that defences cover realistic attack paths.
How ATLAS is organised
- Tactics are the adversary’s goals at each stage. The ATLAS matrix shows 16 columns: Reconnaissance, Resource Development, AI Attack Adaptation, Initial Access, AI Model Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration and Impact.
- Techniques are the ways a tactic is achieved, with sub-techniques for variants. In the data, tactic IDs look like AML.TA0005, techniques like AML.T0051 and sub-techniques like AML.T0051.001.
- Mitigations (AML.M####) are defensive measures linked to the techniques they reduce.
- Case studies (AML.CS####) are documented attacks, marked as either an incident or an exercise, with each step tied to a technique and a tactic.
The 2026.09 release of the ATLAS data, dated 15 September 2026, contains 16 tactics, 208 technique and sub-technique entries, 40 mitigations and 73 case studies. Releases are monthly, so cite the version you used. On the matrix you can filter by platform (predictive AI, generative AI, agentic AI, enterprise) and by maturity: feasible, demonstrated or realized. Those labels are a quick way to prioritise a test plan.
A worked example: Slack AI (AML.CS0035)
The case study “Data Exfiltration from Slack AI via Indirect Prompt Injection” is an exercise by the security firm PromptArmor, dated 20 August 2024. ATLAS summarises it this way: the attack relied on Slack AI ingesting a malicious prompt from a post in a public channel into its retrieval database, and then a victim user querying Slack AI, which caused the prompt to be retrieved and executed. The researchers targeted an API key stored in a private channel. Here is how ATLAS breaks the procedure into steps:
| Step | What the researcher did | ATLAS technique | Tactic |
|---|---|---|---|
| S00 | Crafted a message that would be retrieved when a user asks about the API key | Retrieval Content Crafting (AML.T0066) | AI Attack Adaptation |
| S01 | Crafted a prompt that makes the assistant reveal the key in a link | LLM Prompt Crafting (AML.T0065) | AI Attack Adaptation |
| S02 | Used an ordinary non-admin account in the workspace | Valid Accounts (AML.T0012) | Initial Access |
| S03 | Interacted with the assistant by posting in public channels | AI-Enabled Product or Service (AML.T0047) | AI Model Access |
| S04 | Posted the malicious content so it entered the retrieval index | RAG Poisoning (AML.T0070) | Persistence |
| S05 | The victim’s query retrieved the content and the assistant followed it | LLM Prompt Injection: Indirect (AML.T0051.001) | Execution |
| S06 | The assistant retrieved the key from the victim’s private channels | RAG Credential Harvesting (AML.T0082) | Credential Access |
| S07 | The response rendered as a link that sent the key to the researcher’s server | LLM Response Rendering (AML.T0077) | Exfiltration |
Notice what this mapping gives a defender. No step required breaking the model. Each depends on a design decision in the application: what the assistant may retrieve, whose content it indexes, what permissions it holds for the person asking, and how its output is rendered. That is why OWASP calls related weaknesses prompt injection, excessive agency or improper output handling: the same chain, seen from the vulnerability side. The next lesson covers that view.
Turning the map into a test plan
- List the assets and entry points of your system: data sources the model retrieves from, tools it can call, accounts it acts through.
- Pick the relevant platform filters, then start with the techniques at the demonstrated and realized maturity levels.
- Write each test as a short chain of tactics, as in the table, so a finding is a path and not an isolated trick.
- For each technique, look up its mitigations. ATLAS lists, for example, Human In-the-Loop for AI Agent Actions (AML.M0029), Restrict AI Agent Tool Invocation on Untrusted Data (AML.M0030), AI Agent Tools Permissions Configuration (AML.M0028) and AI Telemetry Logging (AML.M0024).
- Record the ATLAS IDs in your report. ATLAS also has a mitigation named AI Red Team (AML.M0035), which describes recurring, authorised, threat-informed exercises before deployment and throughout operation.
One caution: ATLAS shows what has been demonstrated, not what is likely in your organisation. A technique rated feasible may matter more to you than a realized one, depending on what your system exposes. Use the knowledge base to widen your thinking, then let your own architecture decide priorities.
Viktigt att minnas
- ATLAS is a public knowledge base of adversary tactics, techniques, mitigations and case studies for AI systems, released monthly.
- A case study breaks an attack into steps, each mapped to a technique and a tactic, so a finding becomes a path.
- Filters for platform (predictive, generative, agentic, enterprise) and maturity (feasible, demonstrated, realized) help prioritise tests.
- Record ATLAS IDs and the release version in reports so others can reproduce and compare.
Testa dig själv
1. In ATLAS, what is a case study?
- A list of laws
- A documented attack, marked as an incident or an exercise, whose steps are mapped to techniques and tactics — Rätt.
- A vendor comparison
- A defensive checklist
Case studies (AML.CS####) document real incidents or exercises and tie each step to an ATLAS technique and tactic.
2. In the Slack AI case study, how did the malicious instruction reach the assistant?
- By breaking the model’s weights
- By being posted in a public channel that the assistant indexed and later retrieved for a victim’s query — Rätt.
- By a network man-in-the-middle
- By a stolen administrator password
The researcher used an ordinary account to post content that entered the retrieval database; when a victim’s query retrieved it, the assistant followed it (indirect prompt injection).
3. Why should reports state the ATLAS release you used?
- ATLAS content and IDs change over time, with monthly releases — Rätt.
- ATLAS requires a licence per release
- Releases are yearly and identical
- It is only a formatting rule
ATLAS publishes monthly content updates (for example 2026.09), so techniques, mitigations and case studies can be added or revised.
Testa det med FireAI
Omsätt den här lektionen i praktiken på din egen Mac.
- Regler: app, webbplats, domän, IP eller ett intervall, för alltid eller tills du startar om — Skriv en regel lika precis som en adress eller lika bred som en hel domän.
- Undersök en anslutning — Bestäm dig med fakta framför dig, inte en vag varning.
- Världskartan — Se var din data faktiskt går, inte bara ett värdnamn du skulle behöva slå upp själv.
- Requests by country and upload spikes — See at a glance where your Mac talks to, and notice at once when it suddenly sends a lot of data somewhere.
- Hotlistor (valfritt) — Kontrollera din trafik mot offentlig hotdata utan att skicka den någonstans.
- Säkerhetslägen: Hem, Café, Paranoia, Under attack — Matcha FireAIs stränghet till var din Mac faktiskt är, med ett tryck.
Källor
- MITRE ATLAS: matrix for AI systems
- MITRE ATLAS data repository (versioning, ID conventions)
- MITRE ATLAS data release 2026.09 (YAML)
Omsätt det på din Mac
Prova alla funktioner gratis i 17 dagar, inget kort behövs.