MITRE ATLAS 2026.09 / technique reference
AML.T0065
LLM Prompt Crafting
MITRE source definition
Adversaries may use their acquired knowledge of the target generative AI system to craft prompts that bypass its defenses and allow malicious instructions to be executed.
The adversary may iterate on the prompt to ensure that it works as-intended consistently.
Source modified 2026-08-31. Reproduced from the pinned ATLAS release; inline technique links resolve to local reference pages.
Parent, sub-techniques and ATT&CK references
No explicit relationship in this pinned source.
Source-backed defensive context
MITRE mitigations
No explicit relationship in this pinned source.
MITRE case studies
- AML.CS0021 ChatGPT Conversation Exfiltration · Exercise
- AML.CS0026 Financial Transaction Hijacking with M365 Copilot as an Insider · Exercise
- AML.CS0029 Google Bard Conversation Exfiltration · Exercise
- AML.CS0035 Data Exfiltration from Slack AI via Indirect Prompt Injection · Exercise
- AML.CS0037 Data Exfiltration via Agent Tools in Copilot Studio · Exercise
- AML.CS0038 Planting Instructions for Delayed Automatic AI Agent Tool Invocation · Exercise
- AML.CS0039 Living Off AI: Prompt Injection via Jira Service Management · Exercise
- AML.CS0040 Hacking ChatGPT's Memories with Prompt Injection · Exercise
- AML.CS0041 Rules File Backdoor: Supply Chain Attack on AI Coding Assistants · Exercise
- AML.CS0043 Malware Prototype with Embedded Prompt Injection · Incident
- AML.CS0045 Data Exfiltration via an MCP Server used by Cursor · Exercise
- AML.CS0046 Data Destruction via Indirect Prompt Injection Targeting Claude Computer-Use · Exercise
- AML.CS0047 Code to Deploy Destructive AI Agent Discovered in Amazon Q VS Code Extension · Incident
- AML.CS0049 Supply Chain Compromise via Poisoned ClawdBot Skill · Exercise
- AML.CS0051 OpenClaw Command & Control via Prompt Injection · Exercise
- AML.CS0052 LLMSmith: RCE Vulnerabilities in LLM-Integrated Applications · Exercise
- AML.CS0054 Data Exfiltration via Remote Poisoned MCP Tool · Exercise
- AML.CS0056 Model Distillation Campaigns Targeting Anthropic Claude · Incident
- AML.CS0059 EchoLeak: Zero-Click Prompt Injection Targeting M365 Copilot for Data Exfiltration · Exercise
- AML.CS0060 Cross-Site Scripting via Prompt Manipulation in Lenovo AI Chatbot · Exercise
- AML.CS0061 AI in the Middle: Web-Based AI Services as C2 Relays · Exercise
- AML.CS0062 RCE Vulnerability in Semantic Kernel Search Plugin · Exercise
- AML.CS0063 Prompt-Based Attacks Against Gemini via Calendar Invitations · Exercise
- AML.CS0066 ZombieAgent: Data Exfiltration Attack on ChatGPT · Exercise
- AML.CS0067 Claude Code GitHub Action Secret Exposure · Exercise
These are explicit source relationships, not independently reproduced incidents or validated detection coverage.
Simulation and telemetry boundary
This is a technique reference page, not a runnable simulation. No ATLAS-specific telemetry mapping, local attack execution or detector validation is asserted. MITRE maturity describes its source evidence, not a 1200km lab result.
For broader context—not technique-specific control mappings—see AI Security, AI Security Course, and detection-validation methodology.
Provenance and attribution
Immutable MITRE ATLAS source · Import provenance · Attribution and transformation notice · Apache License 2.0
Copyright 2021-2026 MITRE. Source text and explicit relationships are retained; navigation, formatting and local links are provided by 1200km.
No explicit relationship in this pinned source.