Skip to content
PhiloCyber logo
Guide index

MITRE ATLAS — Technique to Chapter Index

Source
atlas-mapping.md
State
Editorial review
Edition
2026-draft
Estimated reading time
7 min

Draft chapter under editorial review

This material is available for early reading, but it has not reached the reviewed 1.0 release. Technical references, examples, and wording may change.

Every MITRE ATLAS technique referenced in the guide, with the chapter that covers it. Use this to jump into the relevant chapter for a specific ID, or to check coverage. Techniques that have emerged since the last official ATLAS revision but recur in current engagements are listed at the end of each relevant tactic section (or in the dedicated Emerging Techniques section) with the label "No ATLAS ID — tracked as emerging technique" rather than an invented identifier.

Reference: https://atlas.mitre.org/

Reconnaissance (AML.TA0001)

IDTechniqueChapter
AML.T0000Search for Victim's Publicly Available Research Materials03
AML.T0001Search for Publicly Available Adversarial Vulnerability Analysis03
AML.T0002Acquire Public ML Artifacts03, 11
AML.T0004Victim Website03
AML.T0006Active Scanning03
AML.T0013Discover ML Model Ontology03
AML.T0014Discover ML Model Family03
No ATLAS ID — tracked as emerging techniqueQuery-based black-box characterization of an unmonitored inference API (zero-SOC-visibility recon)03, 10, 15

Resource Development (AML.TA0002)

IDTechniqueChapter
AML.T0016Obtain Capabilities11 (surrogate models)
AML.T0017Develop Capabilities10 (adversarial suffixes), 11 (backdoors)
No ATLAS ID — tracked as emerging techniqueSlopsquatting — publishing malicious packages under names hallucinated by LLM code assistants11

Initial Access (AML.TA0003)

IDTechniqueChapter
AML.T0010AI Supply Chain Compromise11
AML.T0010.000AI Supply Chain Compromise: Hardware11
AML.T0010.001AI Supply Chain Compromise: ML Software11
AML.T0010.002AI Supply Chain Compromise: Data11
AML.T0010.003AI Supply Chain Compromise: Model11
AML.T0010.005AI Supply Chain Compromise: AI Agent Tool07, 11
AML.T0012Valid Accounts12
AML.T0044ML Model Access03, 13
No ATLAS ID — tracked as emerging techniqueMCP line jumping — invoking a tool or capability before the client-side approval/discovery flow completes07
No ATLAS ID — tracked as emerging techniqueMCP tool poisoning / rug pull — malicious instructions hidden in tool description metadata, or a benign tool swapped post-approval07, 11, 15
No ATLAS ID — tracked as emerging techniquemcp-remote CVE-2025-6514 — OS command injection via crafted authorization_endpoint response during MCP OAuth handshake07, 12
No ATLAS ID — tracked as emerging techniqueModel jacking — hijacking a hosted model endpoint or registry entry to serve attacker-controlled outputs under a trusted name11, 12

Execution (AML.TA0005)

IDTechniqueChapter
AML.T0011User Execution04 (jailbreak → user action), 11 (poisoned artifact load)
AML.T0011.000User Execution: Unsafe ML Artifacts09, 11
No ATLAS ID — tracked as emerging techniquenullifAI and other picklescan-bypass techniques for loading unsafe pickle artifacts past static scanners09, 11
No ATLAS ID — tracked as emerging techniqueGGUF/safetensors metadata abuse for smuggling executable payloads past format-based safety assumptions09, 11

Persistence (AML.TA0006)

IDTechniqueChapter
AML.T0018Backdoor ML Model09, 11
AML.T0018.000Poison Training Data09
AML.T0019Publish Poisoned Datasets09, 11
AML.T0020Poison Training Data06 (RAG-ingestion variant), 09
AML.T0081Model Registry Poisoning12
No ATLAS ID — tracked as emerging techniqueLoRA/adapter poisoning — sleeper-agent triggers embedded in a small adapter (CBA, CoLoRA-style attacks) rather than the base model09, 11, 15
No ATLAS ID — tracked as emerging techniqueMINJA — memory injection into an agent's persistent memory store to bias future reasoning or actions05, 09

Defense Evasion (AML.TA0007)

IDTechniqueChapter
AML.T0015Evade ML Model10
AML.T0043Craft Adversarial Data06, 09, 10, 13
AML.T0043.000Craft Adversarial Data: White-Box Attacks10
AML.T0043.001Craft Adversarial Data: Black-Box Attacks10, 15
AML.T0043.002Craft Adversarial Data: Transferability10, 15
AML.T0068LLM Prompt Obfuscation04
No ATLAS ID — tracked as emerging techniqueCharacter injection (zero-width characters, homoglyphs, Unicode tag blocks) for filter and tokenizer bypass04, 09
No ATLAS ID — tracked as emerging techniquePolicy Puppetry — framing a jailbreak prompt as a fake system/policy configuration document04, 15
No ATLAS ID — tracked as emerging techniqueCrescendo — multi-turn escalation that walks a model toward a disallowed output across several benign-looking turns04, 15
No ATLAS ID — tracked as emerging techniqueDeceptive Delight — embedding an unsafe request inside a sequence of benign narrative tasks04
No ATLAS ID — tracked as emerging techniqueSkeleton Key — a single-turn instruction that requests a warning-label prefix in place of a refusal04
No ATLAS ID — tracked as emerging techniqueEcho Chamber — steering a model toward an unsafe completion via context poisoning built from its own earlier responses04
No ATLAS ID — tracked as emerging techniqueControlled-release prompting — releasing a disallowed request to the model in deliberately staged fragments to avoid single-prompt filters04

Credential Access (AML.TA0008)

IDTechniqueChapter
AML.T0055Unsecured Credentials05, 07, 12
No ATLAS ID — tracked as emerging techniqueConfused deputy (OAuth / multi-agent) — a high-privilege component performs an action on behalf of a low-privilege caller because authorization is checked at the wrong hop05, 07, 15

Discovery (AML.TA0009)

IDTechniqueChapter
AML.T0040ML Model Inference API Access03
AML.T0056LLM Meta-Prompt Extraction04, 05
No ATLAS ID — tracked as emerging techniquePLeak — automated search for prompts that reliably extract a target system's hidden system prompt04

Collection (AML.TA0010)

IDTechniqueChapter
AML.T0035ML Artifact Collection12
AML.T0037Data from Cloud Storage12
AML.T0061Data from AI Services (Agent-side)05
AML.T0085Data from AI Services07

ML Attack Staging (AML.TA0011)

IDTechniqueChapter
AML.T0042Verify Attack10 (transfer verification), 13
AML.T0053LLM Plugin Compromise05, 07, 12
AML.T0054LLM Jailbreak04
No ATLAS ID — tracked as emerging techniquePoisonedRAG / CorruptRAG — crafting a minimal number of adversarial documents that dominate top-k retrieval for a targeted query06, 15
No ATLAS ID — tracked as emerging techniqueGASLITE / GragPoison — gradient- or embedding-guided adversarial passage generation for dense-retrieval SEO poisoning06, 15
No ATLAS ID — tracked as emerging techniqueMAS hijacking — steering a multi-agent system's routing or consensus logic away from its intended orchestrator05

Exfiltration (AML.TA0012)

IDTechniqueChapter
AML.T0024Exfiltration via ML Inference API06, 08, 13
AML.T0024.000Membership Inference06, 08, 13
AML.T0024.001Model Inversion13
AML.T0024.002Model Extraction13
AML.T0025Exfiltration via Cyber Means06, 08
AML.T0057LLM Data Leakage04, 08, 13
No ATLAS ID — tracked as emerging techniqueEchoLeak-style zero-click exfiltration — data exfiltrated via automatic rendering of attacker-controlled markdown/image references, requiring no victim click06, 07, 15
No ATLAS ID — tracked as emerging techniqueVec2Text / Zero2Text embedding inversion at scale against production vector stores08
No ATLAS ID — tracked as emerging techniqueMin-K%++ membership inference — improved thresholding over minimum-token-probability membership signals08, 13
No ATLAS ID — tracked as emerging techniqueSPV-MIA — self-calibrated probabilistic-variation membership inference against fine-tuned LLMs08, 13
No ATLAS ID — tracked as emerging techniqueDivergence attack — inducing verbatim training-data regurgitation via repetition or degenerate decoding08, 13

Impact (AML.TA0013)

IDTechniqueChapter
AML.T0034Cost Harvesting04 (LLM DoS), 14 (rate limits)
AML.T0051LLM Prompt Injection04, 05
AML.T0051.000LLM Prompt Injection: Direct04
AML.T0051.001LLM Prompt Injection: Indirect04, 06, 07
AML.T0067LLM Trusted Output Components05

Infrastructure and supply-chain CVEs (cross-cutting, not yet tactic-mapped in ATLAS)

IDTechniqueChapter
No ATLAS ID — tracked as emerging techniqueNVIDIAScape (CVE-2025-23266) — NVIDIA Container Toolkit OCI-hook misconfiguration enabling container escape12
No ATLAS ID — tracked as emerging techniqueShadowRay — unauthenticated Ray dashboard/job-submission API abuse for remote code execution on ML clusters12

Cross-cutting

Techniques that don't cleanly map to a single tactic:

ConcernChapters
Prompt-injection lifecycle (direct, indirect, obfuscated, output-abusing)04, 05, 06, 07
Multi-turn and framing-based jailbreaks (Crescendo, Policy Puppetry, Deceptive Delight, Skeleton Key, Echo Chamber, controlled-release prompting)04, 15
RAG-specific attack surface (retrieval, ingestion, embedding, inversion, PoisonedRAG/CorruptRAG/GASLITE/GragPoison poisoning)06, 08, 15
Agent-specific attack surface (tools, MCP, multi-agent, MCP line jumping/tool poisoning/rug pull, confused deputy, MAS hijacking, MINJA memory injection)05, 07, 15
Data-layer attacks (poisoning, trojans, tokenizer, adapter, LoRA sleeper agents)09, 11
Adversarial evasion (norm-bounded, sparsity, text, query-based black-box)10, 15
Privacy attacks (membership inference including Min-K%++/SPV-MIA, inversion including Vec2Text/Zero2Text, extraction, divergence attacks)13
Infrastructure (cloud, K8s, GPU, secrets, NVIDIAScape, ShadowRay)12
Supply chain (slopsquatting, model jacking, pickle/picklescan bypasses including nullifAI, mcp-remote CVE-2025-6514)11, 12
Defensive controls14
End-to-end capstones15
MITRE ATLAS — Technique to Chapter Index | PhiloCyber