AML.T0017: Develop Capabilities
Adversaries may develop their own capabilities to support operations. This process encompasses identifying requirements, building solutions, and deploying capabilities. Capabilities used to support attacks on AI-enabled systems are not necessarily AI-based themselves. Examples include setting up websites with adversarial information or creating Jupyter notebooks with obfuscated exfiltration code.
Sub-techniques
AML.T0017.000: Adversarial AI Attacks
Adversaries may develop their own adversarial attacks. They may leverage existing libraries as a starting point (Adversarial AI Attack Implementations). They may implement ideas described in public research papers or develop custom made attacks for the victim model.
Standards mapping
Where this fits in a TurboPentest engagement
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Frequently asked questions
What is AML.T0017 Develop Capabilities?
Adversaries may develop their own capabilities to support operations. This process encompasses identifying requirements, building solutions, and deploying capabilities. Capabilities used to support attacks on AI-enabled systems are not necessarily AI-based themselves. Examples include setting up websites with adversarial information or creating Jupyter notebooks with obfuscated exfiltration code.
Which tactics does AML.T0017 belong to?
AML.T0017 maps to the Resource Development tactic.
Does TurboPentest test for Develop Capabilities?
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Related MITRE ATLAS techniques
- Resource DevelopmentAML.T0002: Acquire Public AI Artifacts
- Resource DevelopmentAML.T0008: Acquire Infrastructure
- Resource DevelopmentAML.T0016: Obtain Capabilities
- Resource DevelopmentAML.T0019: Publish Poisoned Datasets
- Resource Development, PersistenceAML.T0020: Poison Training Data
- Resource DevelopmentAML.T0021: Establish Accounts
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest