You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit db56eeb
Browse filesBrowse the repository at this point in the historyBrowse files
Port of GenAI-Security-Project/GenAI-Data-Security-Initiative#65
(squash d0675741), which fixed these in the monorepo copy of crosswalk/
that has since been removed. Every target was re-checked against
ATLAS-2026.07.yaml from mitre-atlas/atlas-data tag v2026.07, dist/v6
(sha256 0e07bb07fc6423d72cdf24ddc2038a6905bcbc00ba571064153119ee1a5888d4).
Six renames, identifier right and label superseded:
AML.T0020 Training Data Poisoning, AML.T0029 Denial of AI Service,
AML.T0013 Discover AI Model Ontology, AML.T0018 Manipulate AI Model,
AML.T0025 Exfiltration via Cyber Means, AML.T0024.000 Infer Training
Data Membership.
Five identifier errors, label right and identifier wrong:
Data from Information Repositories AML.T0057 -> AML.T0036,
Exploit Public-Facing Application AML.T0051 -> AML.T0049,
Craft Adversarial Data AML.T0031 -> AML.T0043,
Exfiltration via AI Inference API AML.T0016 -> AML.T0024,
Valid Accounts AML.T0022 -> AML.T0012 (AML.T0022 is not in the release).
The mapping files here have diverged from the monorepo copy, so the
monorepo line changes were transplanted onto the current content with
an assertion that each replaced line occurs here exactly as often as it
did in the monorepo pre-image, and every changed line was checked to
differ only by these eleven substitutions. 57 technique rows change
(Agentic 5, DSGAI 51, LLM 1), plus the summary identifier lists,
counter bullets and prose that cite the same identifiers. A changelog
row is added to each of the three files.
data/entries, backlinks and docs bundles are regenerated with
scripts/generate.js. validate.js output is byte-identical to main
(0 errors, 84 warnings, 312 passed); stats:check and the 50 unit tests
pass; generator output is current.
Claude-Session: https://claude.ai/code/session_01KJVKF6raJCNKBWjTkDSqR4
Co-authored-by: Sankalp Gilda <sankalp.gilda@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
| ASI08 | Cascading Agent Failures | High | AML.T0029, AML.T0034, AML.T0057 | Single fault fans out across all downstream agents | Foundational–Advanced |
68
68
| ASI09 | Human-Agent Trust Exploitation | Medium | AML.T0045, AML.T0047, AML.T0049 | Agent fluency makes manipulation invisible to audit logs | Foundational–Hardening |
| Valid Accounts |[AML.T0022](https://atlas.mitre.org/techniques/AML.T0022)| Initial Access / Persistence | Exploiting legitimate agent credentials to access AI systems or data pipelines |
250
-
| Exfiltration via AI Inference API |[AML.T0016](https://atlas.mitre.org/techniques/AML.T0016)| Exfiltration | Using compromised agent credentials to exfiltrate data through inference API |
249
+
| Valid Accounts |[AML.T0012](https://atlas.mitre.org/techniques/AML.T0012)| Initial Access / Persistence | Exploiting legitimate agent credentials to access AI systems or data pipelines |
250
+
| Exfiltration via AI Inference API |[AML.T0024](https://atlas.mitre.org/techniques/AML.T0024)| Exfiltration | Using compromised agent credentials to exfiltrate data through inference API |
251
251
| Model Inversion |[AML.T0024](https://atlas.mitre.org/techniques/AML.T0024)| Collection | Reconstructing sensitive data accessible to the agent through credential abuse |
252
252
253
253
#### Mitigations by tier
@@ -521,8 +521,8 @@ cluster.
521
521
| Technique | ID | Tactic | Agentic context |
522
522
|---|---|---|---|
523
523
| Network Service Scanning |[AML.T0043](https://atlas.mitre.org/techniques/AML.T0043)| Discovery | Identifying and mapping inter-agent communication endpoints for targeting |
524
-
| Valid Accounts |[AML.T0022](https://atlas.mitre.org/techniques/AML.T0022)| Persistence | Using compromised agent credentials to impersonate trusted agents in A2A channels |
525
-
| Exfiltration via AI Inference API |[AML.T0016](https://atlas.mitre.org/techniques/AML.T0016)| Exfiltration | Intercepting inter-agent messages to exfiltrate sensitive context passed between agents |
524
+
| Valid Accounts |[AML.T0012](https://atlas.mitre.org/techniques/AML.T0012)| Persistence | Using compromised agent credentials to impersonate trusted agents in A2A channels |
525
+
| Exfiltration via AI Inference API |[AML.T0024](https://atlas.mitre.org/techniques/AML.T0024)| Exfiltration | Intercepting inter-agent messages to exfiltrate sensitive context passed between agents |
526
526
527
527
#### Mitigations by tier
528
528
@@ -592,7 +592,7 @@ crosswalks for OT-specific controls.
592
592
593
593
| Technique | ID | Tactic | Agentic context |
594
594
|---|---|---|---|
595
-
| Denial of ML Service |[AML.T0029](https://atlas.mitre.org/techniques/AML.T0029)| Impact | Triggering cascading failure propagation to exhaust system resources or degrade service |
595
+
| Denial of AI Service |[AML.T0029](https://atlas.mitre.org/techniques/AML.T0029)| Impact | Triggering cascading failure propagation to exhaust system resources or degrade service |
| Exploit Public-Facing ML Application |[AML.T0057](https://atlas.mitre.org/techniques/AML.T0057)| Initial Access | Exploiting an exposed agent endpoint to introduce a fault that cascades internally |
598
598
@@ -795,6 +795,7 @@ to visualise agentic attack coverage across your threat model.
795
795
| Date | Version | Change | Author |
796
796
|---|---|---|---|
797
797
| 2026-03-24 | 2026-Q1 | Initial mapping — ASI01–ASI10 full entries | OWASP GenAI Data Security Initiative |
798
+
| 2026-09-14 | 2026-Q3 | Corrected three ATLAS technique citations against ATLAS 2026.07 | OWASP GenAI Data Security Initiative |
0 commit comments