Summary: Wiki pages for raw/MITRE-ATLAS/ — MITRE’s ATT&CK-style threat matrix for AI systems, release 2026.06.
Sources: raw/MITRE-ATLAS/ (288 cards + source YAML + generator)
Last updated: 2026-07-28
Pages
| Page | Covers |
|---|---|
| mitre-atlas | What ATLAS is, versioning traps, how this folder was generated |
| atlas-matrix | The 16 tactics, and the two with no ATT&CK equivalent |
| atlas-mitigations | 35 mitigations — and the 56% of techniques with none |
| atlas-case-studies | 63 documented attacks, 18 of them real |
| atlas-and-pitax | How ATLAS and PITAX divide the problem |
The raw folder’s own index.md holds the full matrix and complete object listing.
The numbers
16 tactics · 173 techniques (103 top-level + 70 sub) · 35 mitigations · 63 case studies · 272 relationships
Release 2026.06, format 6.0.0, Apache 2.0.
Four findings worth carrying
- Agentic AI is the largest platform — 114 techniques, ahead of Generative AI at 92. MITRE’s own tagging says the agent is the dominant attack surface. AI Act Art 15(5) does not name a single agentic attack class.
- 56% of techniques have no mapped mitigation (97 of 173). ATLAS is a far better threat taxonomy than control catalogue; using it as a coverage checklist overstates your posture badly.
- Indirect prompt injection outranks direct in documented cases — 13 vs 12
employsrelationships across the 63 case studies. - Only 37 of 173 techniques link to ATT&CK. Roughly 79% of ATLAS describes behaviour with no conventional-security analogue.
Two traps
dist/ATLAS.yamlis deprecated but still served, stuck at release 2026.04. Resolvedist/ATLAS-latest.yamlinstead.- Format v6 restructured the data. Tactic↔technique mapping moved into
relationships; 5.x-era converters produce empty assignments silently.
Both are documented in mitre-atlas, and _gen_atlas.py in the raw folder handles them.
Cross-collection links
- AI Attack Techniques — PITAX, the payload-craft counterpart
- Data poisoning — sits in ATLAS Resource Development
- Model theft — sits in ATLAS AI Model Access
- CoSAI framework — maps ATLAS techniques per architecture component
- Root index
Gaps
- No ATLAS technique covers multi-turn attacks or reasoning-budget attacks.
- The mitigation set is thin on weight protection, where Code of Practice Appendix 4 is far stronger.
Log
See log.