Exfiltration: MITRE ATLAS
The 6 MITRE ATLAS techniques that fall under the Exfiltration tactic, each mapped to how TurboPentest tests for it.
- AML.T0024Exfiltration via AI Inference API
Adversaries may exfiltrate private information via AI Model Inference API Access. AI Models have been shown leak private information about their training data (e.g. Infer Training Data Membership, Invert AI Model). The model itself may also be extracted (Extract AI Model) for the purposes of AI Intellectual Property Theft.
- AML.T0025Exfiltration via Cyber Means
Adversaries may exfiltrate AI artifacts or other information relevant to their goals via traditional cyber means.
- AML.T0056Extract LLM System Prompt
Adversaries may attempt to extract a large language model's (LLM) system prompt. This can be done via prompt injection to induce the model to reveal its own system prompt or may be extracted from a configuration file.
- AML.T0057LLM Data Leakage
Adversaries may craft prompts that induce the LLM to leak sensitive information. This can include private user data or proprietary information. The leaked information may come from proprietary training data, data sources the LLM is connected to, or information from other users of the LLM.
- AML.T0077LLM Response Rendering
An adversary may get a large language model (LLM) to respond with private information that is hidden from the user when the response is rendered by the user's client. The private information is then exfiltrated. This can take the form of rendered images, which automatically make a request to an adversary controlled server.
- AML.T0086Exfiltration via AI Agent Tool Invocation
AI agent tools capable of performing write operations may be invoked to exfiltrate data to an adversary. Sensitive information can be encoded into the tool's input parameters and transmitted to an adversary-controlled location (such as an inbox, document, or server) as part of a seemingly legitimate action. Variants include sending emails, creating or modifying documents, updating CRM records, or even generating media such as images or videos.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest