MITRE ATLAS 2026.09 / source relationships
ATLAS case-study relationships
Source-linked case-study IDs and their related ATLAS techniques.
← ATLAS matrix · Pinned MITRE source · Current MITRE ATLAS site
Relationship index
Names and technique relationships below come from the pinned MITRE release. This index does not reproduce full mitigation or case-study records, prove control effectiveness, or imply a live incident.
AML.CS0000 — Evasion of Deep Learning Detector for Malware C&C Traffic
Source type: Exercise.
Related ATLAS techniques:
AML.CS0001 — Botnet Domain Generation Algorithm (DGA) Detection Evasion
Source type: Exercise.
Related ATLAS techniques:
AML.CS0002 — VirusTotal Poisoning
Source type: Incident.
Related ATLAS techniques:
AML.CS0003 — Bypassing Cylance's AI Malware Detection
Source type: Exercise.
Related ATLAS techniques:
AML.CS0004 — Camera Hijack Attack on Facial Recognition System
Source type: Incident.
Related ATLAS techniques:
AML.CS0005 — Attack on Machine Translation Services
Source type: Exercise.
Related ATLAS techniques:
AML.CS0006 — ClearviewAI Misconfiguration
Source type: Incident.
Related ATLAS techniques:
AML.CS0007 — GPT-2 Model Replication
Source type: Exercise.
Related ATLAS techniques:
AML.CS0008 — ProofPoint Evasion
Source type: Exercise.
Related ATLAS techniques:
AML.CS0009 — Tay Poisoning
Source type: Incident.
Related ATLAS techniques:
AML.CS0010 — Microsoft Azure Service Disruption
Source type: Exercise.
Related ATLAS techniques:
AML.CS0011 — Microsoft Edge AI Evasion
Source type: Exercise.
Related ATLAS techniques:
AML.CS0012 — Face Identification System Evasion via Physical Countermeasures
Source type: Exercise.
Related ATLAS techniques:
- AML.T0000 Search Open Technical Databases
- AML.T0002.000 Datasets
- AML.T0005 Create Proxy AI Model
- AML.T0008.003 Physical Countermeasures
- AML.T0012 Valid Accounts
- AML.T0013 Discover AI Model Ontology
- AML.T0015 Evade AI Model
- AML.T0040 AI Model Inference API Access
- AML.T0041 Physical Environment Access
- AML.T0043.000 White-Box Optimization
AML.CS0013 — Backdoor Attack on Deep Learning Models in Mobile Apps
Source type: Exercise.
Related ATLAS techniques:
- AML.T0002.001 Models
- AML.T0004 Search Application Repositories
- AML.T0010.003 Model
- AML.T0015 Evade AI Model
- AML.T0017.000 Adversarial AI Attacks
- AML.T0018.001 Modify AI Model Architecture
- AML.T0041 Physical Environment Access
- AML.T0042 Verify Attack
- AML.T0043.004 Insert Backdoor Trigger
- AML.T0044 Full AI Model Access
AML.CS0014 — Confusing Antimalware Neural Networks
Source type: Exercise.
Related ATLAS techniques:
AML.CS0015 — Compromised PyTorch Dependency Chain
Source type: Incident.
Related ATLAS techniques:
AML.CS0016 — Achieving Code Execution in MathGPT via Prompt Injection
Source type: Exercise.
Related ATLAS techniques:
- AML.T0001 Search Open AI Vulnerability Analysis
- AML.T0029 Denial of AI Service
- AML.T0042 Verify Attack
- AML.T0047 AI-Enabled Product or Service
- AML.T0048.000 Financial Harm
- AML.T0051.000 Direct
- AML.T0053 AI Agent Tool Invocation
- AML.T0055 Unsecured Credentials
- AML.T0093 Prompt Infiltration via Public-Facing Application
AML.CS0017 — Bypassing ID.me Identity Verification
Source type: Incident.
Related ATLAS techniques:
AML.CS0018 — Arbitrary Code Execution with Google Colab
Source type: Exercise.
Related ATLAS techniques:
AML.CS0019 — PoisonGPT
Source type: Exercise.
Related ATLAS techniques:
AML.CS0020 — Indirect Prompt Injection Threats: Bing Chat Data Pirate
Source type: Exercise.
Related ATLAS techniques:
AML.CS0021 — ChatGPT Conversation Exfiltration
Source type: Exercise.
Related ATLAS techniques:
AML.CS0022 — ChatGPT Package Hallucination
Source type: Exercise.
Related ATLAS techniques:
AML.CS0023 — ShadowRay: Hijacking Exposed Ray Clusters
Source type: Incident.
Related ATLAS techniques:
AML.CS0024 — Morris II Worm: RAG-Based Attack
Source type: Exercise.
Related ATLAS techniques:
AML.CS0025 — Web-Scale Data Poisoning: Split-View Attack
Source type: Exercise.
Related ATLAS techniques:
AML.CS0026 — Financial Transaction Hijacking with M365 Copilot as an Insider
Source type: Exercise.
Related ATLAS techniques:
- AML.T0047 AI-Enabled Product or Service
- AML.T0048.000 Financial Harm
- AML.T0051.001 Indirect
- AML.T0053 AI Agent Tool Invocation
- AML.T0064 Gather RAG-Indexed Targets
- AML.T0065 LLM Prompt Crafting
- AML.T0066 Retrieval Content Crafting
- AML.T0067.000 Citations
- AML.T0068 LLM Prompt Obfuscation
- AML.T0069.000 Special Character Sets
- AML.T0069.001 System Instruction Keywords
- AML.T0070 RAG Poisoning
- AML.T0071 False RAG Entry Injection
- AML.T0093 Prompt Infiltration via Public-Facing Application
AML.CS0027 — Organization Confusion on Hugging Face
Source type: Exercise.
Related ATLAS techniques:
- AML.T0007 Discover AI Artifacts
- AML.T0010.003 Model
- AML.T0011.000 Unsafe AI Artifacts
- AML.T0016.000 Adversarial AI Attack Implementations
- AML.T0018.000 Poison AI Model
- AML.T0018.002 Embed Malware
- AML.T0021 Establish Accounts
- AML.T0025 Exfiltration via Cyber Means
- AML.T0044 Full AI Model Access
- AML.T0048 External Harms
- AML.T0048.004 AI Intellectual Property Theft
- AML.T0055 Unsecured Credentials
- AML.T0072 Cyber Communication Channel
- AML.T0073 Impersonation
- AML.T0074 Masquerading
- AML.T0115.001 Models
AML.CS0028 — AI Model Tampering via Supply Chain Attack
Source type: Exercise.
Related ATLAS techniques:
- AML.T0004 Search Application Repositories
- AML.T0007 Discover AI Artifacts
- AML.T0010.004 Container Registry
- AML.T0015 Evade AI Model
- AML.T0018.000 Poison AI Model
- AML.T0018.001 Modify AI Model Architecture
- AML.T0044 Full AI Model Access
- AML.T0048.004 AI Intellectual Property Theft
- AML.T0049 Exploit Public-Facing Application
AML.CS0029 — Google Bard Conversation Exfiltration
Source type: Exercise.
Related ATLAS techniques:
AML.CS0030 — LLM Jacking
Source type: Incident.
Related ATLAS techniques:
AML.CS0031 — Malicious Models on Hugging Face
Source type: Incident.
Related ATLAS techniques:
AML.CS0032 — Attempted Evasion of ML Phishing Webpage Detection System
Source type: Incident.
Related ATLAS techniques:
AML.CS0033 — Live Deepfake Image Injection to Evade Mobile KYC Verification
Source type: Exercise.
Related ATLAS techniques:
AML.CS0034 — ProKYC: Deepfake Tool for Account Fraud Attacks
Source type: Incident.
Related ATLAS techniques:
AML.CS0035 — Data Exfiltration from Slack AI via Indirect Prompt Injection
Source type: Exercise.
Related ATLAS techniques:
AML.CS0036 — AIKatz: Attacking LLM Desktop Applications
Source type: Exercise.
Related ATLAS techniques:
- AML.T0012 Valid Accounts
- AML.T0029 Denial of AI Service
- AML.T0047 AI-Enabled Product or Service
- AML.T0048.000 Financial Harm
- AML.T0048.003 User Harm
- AML.T0051.000 Direct
- AML.T0080.000 Memory
- AML.T0080.001 Thread
- AML.T0089 Enterprise Environment Discovery
- AML.T0090 OS Credential Dumping
- AML.T0091.000 Application Access Token
- AML.T0092 Manipulate User LLM Chat History
AML.CS0037 — Data Exfiltration via Agent Tools in Copilot Studio
Source type: Exercise.
Related ATLAS techniques:
- AML.T0006.003 Probe AI Agent Trigger Channels
- AML.T0047 AI-Enabled Product or Service
- AML.T0051 LLM Prompt Injection
- AML.T0051.002 Triggered
- AML.T0065 LLM Prompt Crafting
- AML.T0084.000 Embedded Knowledge
- AML.T0084.001 Tool Definitions
- AML.T0084.002 Activation Triggers
- AML.T0085.000 RAG Databases
- AML.T0085.001 AI Agent Tools
- AML.T0086 Exfiltration via AI Agent Tool Invocation
- AML.T0093 Prompt Infiltration via Public-Facing Application
AML.CS0038 — Planting Instructions for Delayed Automatic AI Agent Tool Invocation
Source type: Exercise.
Related ATLAS techniques:
AML.CS0039 — Living Off AI: Prompt Injection via Jira Service Management
Source type: Exercise.
Related ATLAS techniques:
AML.CS0040 — Hacking ChatGPT's Memories with Prompt Injection
Source type: Exercise.
Related ATLAS techniques:
AML.CS0041 — Rules File Backdoor: Supply Chain Attack on AI Coding Assistants
Source type: Exercise.
Related ATLAS techniques:
AML.CS0042 — SesameOp: Novel backdoor uses OpenAI Assistants API for command and control
Source type: Incident.
Related ATLAS techniques:
AML.CS0043 — Malware Prototype with Embedded Prompt Injection
Source type: Incident.
Related ATLAS techniques:
AML.CS0044 — LAMEHUG: Malware Leveraging Dynamic AI-Generated Commands
Source type: Incident.
Related ATLAS techniques:
AML.CS0045 — Data Exfiltration via an MCP Server used by Cursor
Source type: Exercise.
Related ATLAS techniques:
- AML.T0048.000 Financial Harm
- AML.T0051.001 Indirect
- AML.T0053 AI Agent Tool Invocation
- AML.T0065 LLM Prompt Crafting
- AML.T0068 LLM Prompt Obfuscation
- AML.T0078 Drive-by Compromise
- AML.T0079 Stage Capabilities
- AML.T0083 Credentials from AI Agent Configuration
- AML.T0086 Exfiltration via AI Agent Tool Invocation
AML.CS0046 — Data Destruction via Indirect Prompt Injection Targeting Claude Computer-Use
Source type: Exercise.
Related ATLAS techniques:
AML.CS0047 — Code to Deploy Destructive AI Agent Discovered in Amazon Q VS Code Extension
Source type: Incident.
Related ATLAS techniques:
AML.CS0048 — Exposed ClawdBot Control Interfaces Leads to Credential Access and Execution
Source type: Exercise.
Related ATLAS techniques:
- AML.T0000.003 Scan Databases
- AML.T0025 Exfiltration via Cyber Means
- AML.T0048.003 User Harm
- AML.T0051.001 Indirect
- AML.T0053 AI Agent Tool Invocation
- AML.T0069.002 System Prompt
- AML.T0083 Credentials from AI Agent Configuration
- AML.T0092 Manipulate User LLM Chat History
- AML.T0098 AI Agent Tool Credential Harvesting
- AML.T0132 Misconfigured or Publicly Exposed AI Services
AML.CS0049 — Supply Chain Compromise via Poisoned ClawdBot Skill
Source type: Exercise.
Related ATLAS techniques:
- AML.T0008.002 Domains
- AML.T0010.005 AI Agent Tool
- AML.T0011.002 Poisoned AI Agent Tool
- AML.T0017 Develop Capabilities
- AML.T0048 External Harms
- AML.T0051.001 Indirect
- AML.T0053 AI Agent Tool Invocation
- AML.T0065 LLM Prompt Crafting
- AML.T0074 Masquerading
- AML.T0110.000 Definition and Instructions
- AML.T0111 AI Supply Chain Reputation Inflation
- AML.T0115.002 AI Agent Tools
AML.CS0050 — OpenClaw 1-Click Remote Code Execution
Source type: Exercise.
Related ATLAS techniques:
- AML.T0011.003 Malicious Link
- AML.T0012 Valid Accounts
- AML.T0017 Develop Capabilities
- AML.T0050 Command and Scripting Interpreter
- AML.T0079 Stage Capabilities
- AML.T0081 Modify AI Agent Configuration
- AML.T0105 Escape to Host
- AML.T0106 Exploitation for Credential Access
- AML.T0107 Exploitation for Defense Evasion
AML.CS0051 — OpenClaw Command & Control via Prompt Injection
Source type: Exercise.
Related ATLAS techniques:
- AML.T0002.002 AI Agent Configuration
- AML.T0008 Acquire Infrastructure
- AML.T0051.000 Direct
- AML.T0051.001 Indirect
- AML.T0053 AI Agent Tool Invocation
- AML.T0054 LLM Jailbreak
- AML.T0065 LLM Prompt Crafting
- AML.T0069.000 Special Character Sets
- AML.T0069.001 System Instruction Keywords
- AML.T0074 Masquerading
- AML.T0078 Drive-by Compromise
- AML.T0079 Stage Capabilities
- AML.T0080.001 Thread
- AML.T0081 Modify AI Agent Configuration
- AML.T0095.000 Code Repositories
- AML.T0108 AI Agent
- AML.T0112.000 Local AI Agent
AML.CS0052 — LLMSmith: RCE Vulnerabilities in LLM-Integrated Applications
Source type: Exercise.
Related ATLAS techniques:
- AML.T0004 Search Application Repositories
- AML.T0017 Develop Capabilities
- AML.T0049 Exploit Public-Facing Application
- AML.T0050 Command and Scripting Interpreter
- AML.T0051.000 Direct
- AML.T0053 AI Agent Tool Invocation
- AML.T0054 LLM Jailbreak
- AML.T0065 LLM Prompt Crafting
- AML.T0072 Cyber Communication Channel
- AML.T0084.003 Call Chains
- AML.T0105 Escape to Host
- AML.T0112.000 Local AI Agent
AML.CS0053 — Poisoned Postmark MCP Server Email Exfiltration
Source type: Incident.
Related ATLAS techniques:
AML.CS0054 — Data Exfiltration via Remote Poisoned MCP Tool
Source type: Exercise.
Related ATLAS techniques:
- AML.T0010.005 AI Agent Tool
- AML.T0011.002 Poisoned AI Agent Tool
- AML.T0048.003 User Harm
- AML.T0051.001 Indirect
- AML.T0053 AI Agent Tool Invocation
- AML.T0055 Unsecured Credentials
- AML.T0065 LLM Prompt Crafting
- AML.T0086 Exfiltration via AI Agent Tool Invocation
- AML.T0098 AI Agent Tool Credential Harvesting
- AML.T0110.000 Definition and Instructions
- AML.T0115.002 AI Agent Tools
AML.CS0055 — AI ClickFix: Hijacking Computer-Use Agents Using ClickFix
Source type: Exercise.
Related ATLAS techniques:
AML.CS0056 — Model Distillation Campaigns Targeting Anthropic Claude
Source type: Incident.
Related ATLAS techniques:
AML.CS0057 — Storm-2139 Azure OpenAI Guardrail Bypass
Source type: Incident.
Related ATLAS techniques:
AML.CS0058 — Google Photos AI Model Extraction
Source type: Exercise.
Related ATLAS techniques:
AML.CS0059 — EchoLeak: Zero-Click Prompt Injection Targeting M365 Copilot for Data Exfiltration
Source type: Exercise.
Related ATLAS techniques:
- AML.T0025 Exfiltration via Cyber Means
- AML.T0048 External Harms
- AML.T0051.002 Triggered
- AML.T0065 LLM Prompt Crafting
- AML.T0066 Retrieval Content Crafting
- AML.T0067 LLM Trusted Output Components Manipulation
- AML.T0068 LLM Prompt Obfuscation
- AML.T0070 RAG Poisoning
- AML.T0077 LLM Response Rendering
- AML.T0079 Stage Capabilities
- AML.T0085.000 RAG Databases
- AML.T0093 Prompt Infiltration via Public-Facing Application
AML.CS0060 — Cross-Site Scripting via Prompt Manipulation in Lenovo AI Chatbot
Source type: Exercise.
Related ATLAS techniques:
- AML.T0008 Acquire Infrastructure
- AML.T0011 User Execution
- AML.T0047 AI-Enabled Product or Service
- AML.T0048 External Harms
- AML.T0050 Command and Scripting Interpreter
- AML.T0051.000 Direct
- AML.T0065 LLM Prompt Crafting
- AML.T0077 LLM Response Rendering
- AML.T0091.001 Web Session Cookie
- AML.T0093 Prompt Infiltration via Public-Facing Application
- AML.T0113 Steal Web Session Cookie
AML.CS0061 — AI in the Middle: Web-Based AI Services as C2 Relays
Source type: Exercise.
Related ATLAS techniques:
- AML.T0008.002 Domains
- AML.T0037 Data from Local System
- AML.T0047 AI-Enabled Product or Service
- AML.T0050 Command and Scripting Interpreter
- AML.T0065 LLM Prompt Crafting
- AML.T0068 LLM Prompt Obfuscation
- AML.T0079 Stage Capabilities
- AML.T0086 Exfiltration via AI Agent Tool Invocation
- AML.T0095 Search Open Websites/Domains
- AML.T0114 AI Service Web Interface
AML.CS0062 — RCE Vulnerability in Semantic Kernel Search Plugin
Source type: Exercise.
Related ATLAS techniques:
AML.CS0063 — Prompt-Based Attacks Against Gemini via Calendar Invitations
Source type: Exercise.
Related ATLAS techniques:
- AML.T0006 Active Scanning
- AML.T0025 Exfiltration via Cyber Means
- AML.T0048.003 User Harm
- AML.T0051.001 Indirect
- AML.T0051.002 Triggered
- AML.T0053 AI Agent Tool Invocation
- AML.T0054 LLM Jailbreak
- AML.T0065 LLM Prompt Crafting
- AML.T0080.001 Thread
- AML.T0084 Discover AI Agent Configuration
- AML.T0085.001 AI Agent Tools
- AML.T0086 Exfiltration via AI Agent Tool Invocation
- AML.T0093 Prompt Infiltration via Public-Facing Application
- AML.T0094 Delay Execution of LLM Instructions
- AML.T0101 Data Destruction via AI Agent Tool Invocation
AML.CS0064 — Poisoned GGUF Templates: Inference-Time Supply Chain Attack
Source type: Exercise.
Related ATLAS techniques:
- AML.T0002.001 Models
- AML.T0010.003 Model
- AML.T0011.000 Unsafe AI Artifacts
- AML.T0017.000 Adversarial AI Attacks
- AML.T0018.003 Modify Prompt Construction Logic
- AML.T0031 Erode AI Model Integrity
- AML.T0048.003 User Harm
- AML.T0051.002 Triggered
- AML.T0053 AI Agent Tool Invocation
- AML.T0067 LLM Trusted Output Components Manipulation
- AML.T0074 Masquerading
- AML.T0086 Exfiltration via AI Agent Tool Invocation
- AML.T0115.001 Models
AML.CS0065 — Model Namespace Reuse Supply Chain Attack
Source type: Exercise.
Related ATLAS techniques:
AML.CS0066 — ZombieAgent: Data Exfiltration Attack on ChatGPT
Source type: Exercise.
Related ATLAS techniques:
- AML.T0051.001 Indirect
- AML.T0053 AI Agent Tool Invocation
- AML.T0054 LLM Jailbreak
- AML.T0065 LLM Prompt Crafting
- AML.T0068 LLM Prompt Obfuscation
- AML.T0079 Stage Capabilities
- AML.T0080.000 Memory
- AML.T0085.001 AI Agent Tools
- AML.T0086 Exfiltration via AI Agent Tool Invocation
- AML.T0093 Prompt Infiltration via Public-Facing Application
AML.CS0067 — Claude Code GitHub Action Secret Exposure
Source type: Exercise.
Related ATLAS techniques:
- AML.T0051.001 Indirect
- AML.T0053 AI Agent Tool Invocation
- AML.T0054 LLM Jailbreak
- AML.T0057 LLM Data Leakage
- AML.T0065 LLM Prompt Crafting
- AML.T0084.001 Tool Definitions
- AML.T0084.002 Activation Triggers
- AML.T0086 Exfiltration via AI Agent Tool Invocation
- AML.T0093 Prompt Infiltration via Public-Facing Application
- AML.T0095.000 Code Repositories
- AML.T0098 AI Agent Tool Credential Harvesting
AML.CS0068 — Autonomous OpenAI Evaluation Agents Compromise Hugging Face Infrastructure
Source type: Incident.
Related ATLAS techniques:
- AML.T0012 Valid Accounts
- AML.T0017.001 Autonomous Exploit Development
- AML.T0025 Exfiltration via Cyber Means
- AML.T0036 Data from Information Repositories
- AML.T0037 Data from Local System
- AML.T0049 Exploit Public-Facing Application
- AML.T0050 Command and Scripting Interpreter
- AML.T0055 Unsecured Credentials
- AML.T0072 Cyber Communication Channel
- AML.T0075 Enterprise Resource Discovery
- AML.T0089 Enterprise Environment Discovery
- AML.T0091.000 Application Access Token
- AML.T0102 Generate Malicious Commands
- AML.T0105 Escape to Host
- AML.T0116 Autonomous Reconnaissance
- AML.T0117 Autonomous Attack-Path Adaptation
- AML.T0118.000 Communication via Shared Artifacts
- AML.T0119 Exploit Automated Artifact Processing Pipeline
- AML.T0120 AI Artifact Repository
- AML.T0121 AI Agent Environment Reconstruction
- AML.T0122 Exploitation of Remote Services
- AML.T0123 Obfuscated Files or Information
AML.CS0069 — GTG-1002 Claude Code Espionage Campaign
Source type: Incident.
Related ATLAS techniques:
- AML.T0006 Active Scanning
- AML.T0012 Valid Accounts
- AML.T0016.001 Software Tools
- AML.T0017.001 Autonomous Exploit Development
- AML.T0025 Exfiltration via Cyber Means
- AML.T0036 Data from Information Repositories
- AML.T0037 Data from Local System
- AML.T0040 AI Model Inference API Access
- AML.T0049 Exploit Public-Facing Application
- AML.T0051.000 Direct
- AML.T0054 LLM Jailbreak
- AML.T0055 Unsecured Credentials
- AML.T0075 Enterprise Resource Discovery
- AML.T0089 Enterprise Environment Discovery
- AML.T0103 Deploy AI Agent
- AML.T0116 Autonomous Reconnaissance
- AML.T0117 Autonomous Attack-Path Adaptation
- AML.T0125 Create Account
- AML.T0126 Automated Collection
- AML.T0127 Data Staged
- AML.T0128 Compromise Infrastructure
AML.CS0070 — Threat Actor Uses a DeepSeek-Powered Hermes Agent in Langflow and n8n Exploitation Attempts
Source type: Incident.
Related ATLAS techniques:
- AML.T0000 Search Open Technical Databases
- AML.T0000.003 Scan Databases
- AML.T0006 Active Scanning
- AML.T0016.001 Software Tools
- AML.T0016.002 Generative AI
- AML.T0016.003 Exploits
- AML.T0016.004 AI Agent Tools
- AML.T0017.002 AI Agent Tools
- AML.T0040 AI Model Inference API Access
- AML.T0049 Exploit Public-Facing Application
- AML.T0095.000 Code Repositories
- AML.T0102 Generate Malicious Commands
- AML.T0116 Autonomous Reconnaissance
- AML.T0117 Autonomous Attack-Path Adaptation
AML.CS0071 — Multi-Agent Framework Compromises Taiwanese Government Systems
Source type: Incident.
Related ATLAS techniques:
- AML.T0006 Active Scanning
- AML.T0012 Valid Accounts
- AML.T0025 Exfiltration via Cyber Means
- AML.T0036 Data from Information Repositories
- AML.T0049 Exploit Public-Facing Application
- AML.T0116 Autonomous Reconnaissance
- AML.T0117 Autonomous Attack-Path Adaptation
- AML.T0118.001 Direct Agent Communication
- AML.T0124 Autonomous Attack Orchestration
- AML.T0126 Automated Collection
AML.CS0072 — AI Recommendation Poisoning via Crafted AI Assistant Links
Source type: Incident.
Related ATLAS techniques: