MITRE ATLAS 2026.09 / technique reference
AML.T0006
Active Scanning
MITRE source definition
Adversaries may actively scan for publicly reachable AI systems and resources for targeting. They may identify resources or systems that are misconfigured or are known vulnerable versions. This is distinct from other reconnaissance techniques that do not involve direct interaction with the victim system.
Since AI systems are often deployed in cloud environments, adversaries can use various enumeration methods to effectively discover AI systems and uncover information about their supporting underlying platforms. For agentic and SaaS-hosted systems, the victim system can include the shared platform and provider control plane on which the victim's agents are deployed.
Adversaries may probe the victim system to gather information and metadata for targeting, or actively scan for specific open ports on a potential victim's network or accessible deployed servers, with the goal of locating different types of deployed AI services. These methods could also include directly scanning a target's assets for publicly available AI agents, or for accessible agentic chat interfaces on SaaS platforms (ex: Copilot Studio Hunter).
Information gained from Active Scanning may yield targets that provide opportunities for other forms of reconnaissance such as [Search Open Technical Databases](/techniques/AML.T0000), [Search Open Websites/Domains](/techniques/AML.T0095), [Search Open AI Vulnerability Analysis](/techniques/AML.T0001), or [Gather RAG-Indexed Targets](/techniques/AML.T0064).
Source modified 2026-09-15. Reproduced from the pinned ATLAS release; inline technique links resolve to local reference pages.
Parent, sub-techniques and ATT&CK references
Source-backed defensive context
MITRE mitigations
- AML.M0019 Control Access to AI Models and Data in Production
- AML.M0032 Segmentation of AI Agent Components
- AML.M0039 AI Honeypots
MITRE case studies
- AML.CS0023 ShadowRay: Hijacking Exposed Ray Clusters · Incident
- AML.CS0063 Prompt-Based Attacks Against Gemini via Calendar Invitations · Exercise
- AML.CS0069 GTG-1002 Claude Code Espionage Campaign · Incident
- AML.CS0070 Threat Actor Uses a DeepSeek-Powered Hermes Agent in Langflow and n8n Exploitation Attempts · Incident
- AML.CS0071 Multi-Agent Framework Compromises Taiwanese Government Systems · Incident
These are explicit source relationships, not independently reproduced incidents or validated detection coverage.
Simulation and telemetry boundary
This is a technique reference page, not a runnable simulation. No ATLAS-specific telemetry mapping, local attack execution or detector validation is asserted. MITRE maturity describes its source evidence, not a 1200km lab result.
For broader context—not technique-specific control mappings—see AI Security, AI Security Course, and detection-validation methodology.
Provenance and attribution
Immutable MITRE ATLAS source · Import provenance · Attribution and transformation notice · Apache License 2.0
Copyright 2021-2026 MITRE. Source text and explicit relationships are retained; navigation, formatting and local links are provided by 1200km.
No explicit relationship in this pinned source.