⭐ Star on GitHub

Summary: Wiki pages for raw/MITRE-ATLAS/ — MITRE’s ATT&CK-style threat matrix for AI systems, release 2026.06.

Sources: raw/MITRE-ATLAS/ (288 cards + source YAML + generator)

Last updated: 2026-07-28


Pages

PageCovers
mitre-atlasWhat ATLAS is, versioning traps, how this folder was generated
atlas-matrixThe 16 tactics, and the two with no ATT&CK equivalent
atlas-mitigations35 mitigations — and the 56% of techniques with none
atlas-case-studies63 documented attacks, 18 of them real
atlas-and-pitaxHow ATLAS and PITAX divide the problem

The raw folder’s own index.md holds the full matrix and complete object listing.

The numbers

16 tactics · 173 techniques (103 top-level + 70 sub) · 35 mitigations · 63 case studies · 272 relationships

Release 2026.06, format 6.0.0, Apache 2.0.

Four findings worth carrying

  1. Agentic AI is the largest platform — 114 techniques, ahead of Generative AI at 92. MITRE’s own tagging says the agent is the dominant attack surface. AI Act Art 15(5) does not name a single agentic attack class.
  2. 56% of techniques have no mapped mitigation (97 of 173). ATLAS is a far better threat taxonomy than control catalogue; using it as a coverage checklist overstates your posture badly.
  3. Indirect prompt injection outranks direct in documented cases — 13 vs 12 employs relationships across the 63 case studies.
  4. Only 37 of 173 techniques link to ATT&CK. Roughly 79% of ATLAS describes behaviour with no conventional-security analogue.

Two traps

  • dist/ATLAS.yaml is deprecated but still served, stuck at release 2026.04. Resolve dist/ATLAS-latest.yaml instead.
  • Format v6 restructured the data. Tactic↔technique mapping moved into relationships; 5.x-era converters produce empty assignments silently.

Both are documented in mitre-atlas, and _gen_atlas.py in the raw folder handles them.

Gaps

Log

See log.

6 items under this folder.