AML.T0078: Drive-by Compromise
Adversaries may gain access to an AI system through a user visiting a website over the normal course of browsing, or an AI agent retrieving information from the web on behalf of a user. Websites can contain an LLM Prompt Injection which, when executed, can change the behavior of the AI model.
The same approach may be used to deliver other types of malicious code that don't target AI directly (See Drive-by Compromise in ATT&CK).
Standards mapping
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Frequently asked questions
What is AML.T0078 Drive-by Compromise?
Adversaries may gain access to an AI system through a user visiting a website over the normal course of browsing, or an AI agent retrieving information from the web on behalf of a user. Websites can contain an LLM Prompt Injection which, when executed, can change the behavior of the AI model. The same approach may be used to deliver other types of malicious code that don't target AI directly (See Drive-by Compromise in ATT&CK).
Which tactics does AML.T0078 belong to?
AML.T0078 maps to the Initial Access tactic.
Does TurboPentest test for Drive-by Compromise?
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Related MITRE ATLAS techniques
- Initial AccessAML.T0010: AI Supply Chain Compromise
- Initial Access, Privilege EscalationAML.T0012: Valid Accounts
- Initial Access, Defense Evasion, ImpactAML.T0015: Evade AI Model
- Initial AccessAML.T0049: Exploit Public-Facing Application
- Initial Access, Lateral MovementAML.T0052: Phishing
- Initial Access, PersistenceAML.T0093: Prompt Infiltration via Public-Facing Application
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest