Skip to content

Commit db56eeb

Browse files
emmanuelgjrastrogildaclaude
authored
fix(atlas): correct eleven MITRE ATLAS technique citations (#92)
Port of GenAI-Security-Project/GenAI-Data-Security-Initiative#65 (squash d0675741), which fixed these in the monorepo copy of crosswalk/ that has since been removed. Every target was re-checked against ATLAS-2026.07.yaml from mitre-atlas/atlas-data tag v2026.07, dist/v6 (sha256 0e07bb07fc6423d72cdf24ddc2038a6905bcbc00ba571064153119ee1a5888d4). Six renames, identifier right and label superseded: AML.T0020 Training Data Poisoning, AML.T0029 Denial of AI Service, AML.T0013 Discover AI Model Ontology, AML.T0018 Manipulate AI Model, AML.T0025 Exfiltration via Cyber Means, AML.T0024.000 Infer Training Data Membership. Five identifier errors, label right and identifier wrong: Data from Information Repositories AML.T0057 -> AML.T0036, Exploit Public-Facing Application AML.T0051 -> AML.T0049, Craft Adversarial Data AML.T0031 -> AML.T0043, Exfiltration via AI Inference API AML.T0016 -> AML.T0024, Valid Accounts AML.T0022 -> AML.T0012 (AML.T0022 is not in the release). The mapping files here have diverged from the monorepo copy, so the monorepo line changes were transplanted onto the current content with an assertion that each replaced line occurs here exactly as often as it did in the monorepo pre-image, and every changed line was checked to differ only by these eleven substitutions. 57 technique rows change (Agentic 5, DSGAI 51, LLM 1), plus the summary identifier lists, counter bullets and prose that cite the same identifiers. A changelog row is added to each of the three files. data/entries, backlinks and docs bundles are regenerated with scripts/generate.js. validate.js output is byte-identical to main (0 errors, 84 warnings, 312 passed); stats:check and the 50 unit tests pass; generator output is current. Claude-Session: https://claude.ai/code/session_01KJVKF6raJCNKBWjTkDSqR4 Co-authored-by: Sankalp Gilda <sankalp.gilda@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent 99620eb commit db56eeb

33 files changed

Lines changed: 522 additions & 551 deletions

‎agentic-top10/Agentic_MITREATLAS.md‎

Lines changed: 8 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -59,11 +59,11 @@ it travels through.
5959
|---|---|---|---|---|---|
6060
| ASI01 | Agent Goal Hijack | Critical | AML.T0051.000, AML.T0051.001, AML.T0054 | Autonomy turns single injection into multi-step attack chain | Foundational–Advanced |
6161
| ASI02 | Tool Misuse & Exploitation | Critical | AML.T0037, AML.T0015, AML.T0068 | Tool access converts prompt manipulation into real-world action | Foundational–Advanced |
62-
| ASI03 | Identity & Privilege Abuse | Critical | AML.T0022, AML.T0016, AML.T0024 | Cached credentials give attacker persistent access beyond session | Foundational–Advanced |
62+
| ASI03 | Identity & Privilege Abuse | Critical | AML.T0012, AML.T0024 | Cached credentials give attacker persistent access beyond session | Foundational–Advanced |
6363
| ASI04 | Agentic Supply Chain | High | AML.T0056, AML.T0048, AML.T0010 | Runtime dynamic loading means poisoned components affect all consumers | Hardening–Advanced |
6464
| ASI05 | Unexpected Code Execution | Critical | AML.T0040, AML.T0054, AML.T0037 | Code generation + execution capability creates RCE gateway | Foundational–Advanced |
6565
| ASI06 | Memory & Context Poisoning | High | AML.T0032, AML.T0063, AML.T0020 | Persistence across sessions amplifies impact of single injection | Hardening–Advanced |
66-
| ASI07 | Insecure Inter-Agent Comms | High | AML.T0043, AML.T0022, AML.T0016 | A2A spoofing misdirects entire agent clusters | Hardening–Advanced |
66+
| ASI07 | Insecure Inter-Agent Comms | High | AML.T0043, AML.T0012, AML.T0024 | A2A spoofing misdirects entire agent clusters | Hardening–Advanced |
6767
| ASI08 | Cascading Agent Failures | High | AML.T0029, AML.T0034, AML.T0057 | Single fault fans out across all downstream agents | Foundational–Advanced |
6868
| ASI09 | Human-Agent Trust Exploitation | Medium | AML.T0045, AML.T0047, AML.T0049 | Agent fluency makes manipulation invisible to audit logs | Foundational–Hardening |
6969
| ASI10 | Rogue Agents | Critical | AML.T0054, AML.T0015, AML.T0057 | Compliant surface masks persistent hidden goal pursuit | Hardening–Advanced |
@@ -246,8 +246,8 @@ the original session ends.
246246

247247
| Technique | ID | Tactic | Agentic context |
248248
|---|---|---|---|
249-
| Valid Accounts | [AML.T0022](https://atlas.mitre.org/techniques/AML.T0022) | Initial Access / Persistence | Exploiting legitimate agent credentials to access AI systems or data pipelines |
250-
| Exfiltration via AI Inference API | [AML.T0016](https://atlas.mitre.org/techniques/AML.T0016) | Exfiltration | Using compromised agent credentials to exfiltrate data through inference API |
249+
| Valid Accounts | [AML.T0012](https://atlas.mitre.org/techniques/AML.T0012) | Initial Access / Persistence | Exploiting legitimate agent credentials to access AI systems or data pipelines |
250+
| Exfiltration via AI Inference API | [AML.T0024](https://atlas.mitre.org/techniques/AML.T0024) | Exfiltration | Using compromised agent credentials to exfiltrate data through inference API |
251251
| Model Inversion | [AML.T0024](https://atlas.mitre.org/techniques/AML.T0024) | Collection | Reconstructing sensitive data accessible to the agent through credential abuse |
252252

253253
#### Mitigations by tier
@@ -521,8 +521,8 @@ cluster.
521521
| Technique | ID | Tactic | Agentic context |
522522
|---|---|---|---|
523523
| Network Service Scanning | [AML.T0043](https://atlas.mitre.org/techniques/AML.T0043) | Discovery | Identifying and mapping inter-agent communication endpoints for targeting |
524-
| Valid Accounts | [AML.T0022](https://atlas.mitre.org/techniques/AML.T0022) | Persistence | Using compromised agent credentials to impersonate trusted agents in A2A channels |
525-
| Exfiltration via AI Inference API | [AML.T0016](https://atlas.mitre.org/techniques/AML.T0016) | Exfiltration | Intercepting inter-agent messages to exfiltrate sensitive context passed between agents |
524+
| Valid Accounts | [AML.T0012](https://atlas.mitre.org/techniques/AML.T0012) | Persistence | Using compromised agent credentials to impersonate trusted agents in A2A channels |
525+
| Exfiltration via AI Inference API | [AML.T0024](https://atlas.mitre.org/techniques/AML.T0024) | Exfiltration | Intercepting inter-agent messages to exfiltrate sensitive context passed between agents |
526526

527527
#### Mitigations by tier
528528

@@ -592,7 +592,7 @@ crosswalks for OT-specific controls.
592592

593593
| Technique | ID | Tactic | Agentic context |
594594
|---|---|---|---|
595-
| Denial of ML Service | [AML.T0029](https://atlas.mitre.org/techniques/AML.T0029) | Impact | Triggering cascading failure propagation to exhaust system resources or degrade service |
595+
| Denial of AI Service | [AML.T0029](https://atlas.mitre.org/techniques/AML.T0029) | Impact | Triggering cascading failure propagation to exhaust system resources or degrade service |
596596
| Cost Harvesting | [AML.T0034](https://atlas.mitre.org/techniques/AML.T0034) | Impact | Crafting inputs that trigger runaway agent loops generating unbounded costs |
597597
| Exploit Public-Facing ML Application | [AML.T0057](https://atlas.mitre.org/techniques/AML.T0057) | Initial Access | Exploiting an exposed agent endpoint to introduce a fault that cascades internally |
598598

@@ -795,6 +795,7 @@ to visualise agentic attack coverage across your threat model.
795795
| Date | Version | Change | Author |
796796
|---|---|---|---|
797797
| 2026-03-24 | 2026-Q1 | Initial mapping — ASI01–ASI10 full entries | OWASP GenAI Data Security Initiative |
798+
| 2026-09-14 | 2026-Q3 | Corrected three ATLAS technique citations against ATLAS 2026.07 | OWASP GenAI Data Security Initiative |
798799

799800
---
800801

0 commit comments

Comments
 (0)