MITRE ATLAS
All 101 techniques across 16 tactics in MITRE ATLAS v5.6.0, covering adversarial threats to AI systems, each mapped to how TurboPentest tests for it.
ATLAS documents real-world adversary tactics and techniques against AI and machine learning systems. Each technique page states plainly whether TurboPentest tests for it or whether it falls to IntegSec's manual engagement coverage.
Tactics
- Reconnaissance
8 techniques
- Resource Development
13 techniques
- AI Model Access
4 techniques
- Initial Access
7 techniques
- AI Attack Staging
6 techniques
- Execution
6 techniques
- Persistence
9 techniques
- Privilege Escalation
4 techniques
- Defense Evasion
15 techniques
- Credential Access
6 techniques
- Discovery
9 techniques
- Lateral Movement
2 techniques
- Collection
4 techniques
- Command and Control
3 techniques
- Exfiltration
6 techniques
- Impact
9 techniques
Browse all 101 techniques
Every technique in MITRE ATLAS v5.6.0, in id order.
- AML.T0000: Search Open Technical Databases
- AML.T0001: Search Open AI Vulnerability Analysis
- AML.T0002: Acquire Public AI Artifacts
- AML.T0003: Search Victim-Owned Websites
- AML.T0004: Search Application Repositories
- AML.T0005: Create Proxy AI Model
- AML.T0006: Active Scanning
- AML.T0007: Discover AI Artifacts
- AML.T0008: Acquire Infrastructure
- AML.T0010: AI Supply Chain Compromise
- AML.T0011: User Execution
- AML.T0012: Valid Accounts
- AML.T0013: Discover AI Model Ontology
- AML.T0014: Discover AI Model Family
- AML.T0015: Evade AI Model
- AML.T0016: Obtain Capabilities
- AML.T0017: Develop Capabilities
- AML.T0018: Manipulate AI Model
- AML.T0019: Publish Poisoned Datasets
- AML.T0020: Poison Training Data
- AML.T0021: Establish Accounts
- AML.T0024: Exfiltration via AI Inference API
- AML.T0025: Exfiltration via Cyber Means
- AML.T0029: Denial of AI Service
- AML.T0031: Erode AI Model Integrity
- AML.T0034: Cost Harvesting
- AML.T0035: AI Artifact Collection
- AML.T0036: Data from Information Repositories
- AML.T0037: Data from Local System
- AML.T0040: AI Model Inference API Access
- AML.T0041: Physical Environment Access
- AML.T0042: Verify Attack
- AML.T0043: Craft Adversarial Data
- AML.T0044: Full AI Model Access
- AML.T0046: Spamming AI System with Chaff Data
- AML.T0047: AI-Enabled Product or Service
- AML.T0048: External Harms
- AML.T0049: Exploit Public-Facing Application
- AML.T0050: Command and Scripting Interpreter
- AML.T0051: LLM Prompt Injection
- AML.T0052: Phishing
- AML.T0053: AI Agent Tool Invocation
- AML.T0054: LLM Jailbreak
- AML.T0055: Unsecured Credentials
- AML.T0056: Extract LLM System Prompt
- AML.T0057: LLM Data Leakage
- AML.T0058: Publish Poisoned Models
- AML.T0059: Erode Dataset Integrity
- AML.T0060: Publish Hallucinated Entities
- AML.T0061: LLM Prompt Self-Replication
- AML.T0062: Discover LLM Hallucinations
- AML.T0063: Discover AI Model Outputs
- AML.T0064: Gather RAG-Indexed Targets
- AML.T0065: LLM Prompt Crafting
- AML.T0066: Retrieval Content Crafting
- AML.T0067: LLM Trusted Output Components Manipulation
- AML.T0068: LLM Prompt Obfuscation
- AML.T0069: Discover LLM System Information
- AML.T0070: RAG Poisoning
- AML.T0071: False RAG Entry Injection
- AML.T0072: Reverse Shell
- AML.T0073: Impersonation
- AML.T0074: Masquerading
- AML.T0075: Cloud Service Discovery
- AML.T0076: Corrupt AI Model
- AML.T0077: LLM Response Rendering
- AML.T0078: Drive-by Compromise
- AML.T0079: Stage Capabilities
- AML.T0080: AI Agent Context Poisoning
- AML.T0081: Modify AI Agent Configuration
- AML.T0082: RAG Credential Harvesting
- AML.T0083: Credentials from AI Agent Configuration
- AML.T0084: Discover AI Agent Configuration
- AML.T0085: Data from AI Services
- AML.T0086: Exfiltration via AI Agent Tool Invocation
- AML.T0087: Gather Victim Identity Information
- AML.T0088: Generate Deepfakes
- AML.T0089: Process Discovery
- AML.T0090: OS Credential Dumping
- AML.T0091: Use Alternate Authentication Material
- AML.T0092: Manipulate User LLM Chat History
- AML.T0093: Prompt Infiltration via Public-Facing Application
- AML.T0094: Delay Execution of LLM Instructions
- AML.T0095: Search Open Websites/Domains
- AML.T0096: AI Service API
- AML.T0097: Virtualization/Sandbox Evasion
- AML.T0098: AI Agent Tool Credential Harvesting
- AML.T0099: AI Agent Tool Data Poisoning
- AML.T0100: AI Agent Clickbait
- AML.T0101: Data Destruction via AI Agent Tool Invocation
- AML.T0102: Generate Malicious Commands
- AML.T0103: Deploy AI Agent
- AML.T0104: Publish Poisoned AI Agent Tool
- AML.T0105: Escape to Host
- AML.T0106: Exploitation for Credential Access
- AML.T0107: Exploitation for Defense Evasion
- AML.T0108: AI Agent
- AML.T0109: AI Supply Chain Rug Pull
- AML.T0110: AI Agent Tool Poisoning
- AML.T0111: AI Supply Chain Reputation Inflation
- AML.T0112: Machine Compromise
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest