TIER 1 · ADVERSARIAL THREAT KNOWLEDGE BASE

MITRE ATLAS to AITBM Mapping

Uses released ATLAS tactics and techniques to select AITBM tests while keeping system scoring deployment-specific.

How to use this crosswalk

External requirements, controls, threats, and practices identify evidence to collect or tests to run. Only measured evidence from the assessed deployment determines AITBM rubric placements, IVP, ORP, ACI, MVT findings, and ERS.

Mapping content last verified 2026-08-13. No endorsement by the external framework owner is implied.

MITRE ATLAS

Adversarial threat landscape

MITRE ATLAS data v2026.07 · MITRE Corporation

The current released basis contains 16 tactics, 101 top-level techniques plus 77 sub-techniques, 37 mitigations, and 68 case studies. This AITBM-authored crosswalk routes ATLAS elements to assessment evidence; no tactic, technique, mitigation, or case study has a deployment-independent ERS.

Released ATLAS Tactic Primary AITBM Targets Evidence Use / Boundary
AML.TA0000 AI Model AccessPr-1, Pr-2, Tr-4; AsModel-access paths select leakage, inference, lineage, and exposure tests
AML.TA0001 AI Attack StagingRo-1, Ro-4, Tr-4Selects adversarial-input, poisoning, and provenance tests
AML.TA0002 ReconnaissanceTr-3, Tr-4; AsInforms probing visibility and discoverable-origin evidence
AML.TA0003 Resource DevelopmentRo-4, Tr-4; ACI PcIdentifies malicious artifacts and provenance paths to test
AML.TA0004 Initial AccessCn-1, Cn-5, Pr-2; AsSelects trust-boundary, identity, and exposed-entry tests
AML.TA0005 ExecutionCn-1, Cn-2, Cn-3, Cn-6; AaSelects tool authority, output release, escalation, and action-gating tests
AML.TA0006 PersistenceCn-2, Cn-5, Tr-3; RfSelects persistent-state, credential, audit, eviction, and recovery tests
AML.TA0007 Defense EvasionCn-3, Cn-4, Tr-2, Tr-3; ACI C_monitorSelects bypass, detection-evasion, logging, and monitoring-health tests
AML.TA0008 DiscoveryPr-1, Pr-2, Tr-4; AsSelects model, data, service, and exposure discovery tests
AML.TA0009 CollectionPr-1, Pr-3, Pr-4; Tr-3Selects collection, minimization, re-identification, and audit tests
AML.TA0010 ExfiltrationPr-1, Pr-4, Cn-1, Cn-3; Tr-3Selects leakage, egress-boundary, release-gate, and detection tests
AML.TA0011 ImpactRo-2, Ro-3, Ro-4; Cp, RfSelects integrity, availability, behavior, cascade, and recovery tests; Cp remains graph-derived
AML.TA0012 Privilege EscalationCn-1, Cn-2, Cn-5, Cn-6Selects authority, delegated-identity, escalation, and gating tests
AML.TA0013 Credential AccessCn-5, Pr-2, Tr-3Selects token, key, workload-identity, and credential-use tests
AML.TA0014 Command and ControlCn-1, Cn-2, Tr-3; AsSelects outbound-control, session, egress, and command-channel tests
AML.TA0015 Lateral MovementCn-1, Cn-2, Cn-5; CpSelects segmentation, delegated-access, identity, and graph-reachability tests

Key findings

  • All 16 tactics in released data v2026.07 are accounted for; technique examples in the detailed mapping are illustrative, not a complete 178-technique crosswalk.
  • ATLAS provides threat and case-study context. AITBM scores only measured deployment evidence under its own rubrics and current Section 5 formula.
  • The released v2026.07 universe contains 101 top-level techniques, 77 sub-techniques, 37 mitigations, and 68 case studies.
  • AITBM does not create ATLAS-style identifiers for emerging MCP or agentic patterns and does not imply MITRE endorsement.

MITRE ATLAS v2026.07 reference →