MITRE ATLAS 2026.09 / technique reference
AML.T0004
Search Application Repositories
MITRE source definition
Adversaries may search open application repositories during targeting. Examples of these include Google Play, the iOS App store, the macOS App Store, and the Microsoft Store.
Adversaries may craft search queries seeking applications that contain AI-enabled components. Frequently, the next step is to [Acquire Public AI Artifacts](/techniques/AML.T0002).
Source modified 2026-05-27. Reproduced from the pinned ATLAS release; inline technique links resolve to local reference pages.
Parent, sub-techniques and ATT&CK references
No explicit relationship in this pinned source.
Source-backed defensive context
MITRE mitigations
MITRE case studies
- AML.CS0013 Backdoor Attack on Deep Learning Models in Mobile Apps · Exercise
- AML.CS0028 AI Model Tampering via Supply Chain Attack · Exercise
- AML.CS0052 LLMSmith: RCE Vulnerabilities in LLM-Integrated Applications · Exercise
These are explicit source relationships, not independently reproduced incidents or validated detection coverage.
Simulation and telemetry boundary
This is a technique reference page, not a runnable simulation. No ATLAS-specific telemetry mapping, local attack execution or detector validation is asserted. MITRE maturity describes its source evidence, not a 1200km lab result.
For broader context—not technique-specific control mappings—see AI Security, AI Security Course, and detection-validation methodology.
Provenance and attribution
Immutable MITRE ATLAS source · Import provenance · Attribution and transformation notice · Apache License 2.0
Copyright 2021-2026 MITRE. Source text and explicit relationships are retained; navigation, formatting and local links are provided by 1200km.
No explicit relationship in this pinned source.