MITRE ATLAS
Adversarial threat landscapeMITRE ATLAS data v2026.07 · MITRE Corporation
The current released basis contains 16 tactics, 101 top-level techniques plus 77 sub-techniques, 37 mitigations, and 68 case studies. This AITBM-authored crosswalk routes ATLAS elements to assessment evidence; no tactic, technique, mitigation, or case study has a deployment-independent ERS.
| Released ATLAS Tactic | Primary AITBM Targets | Evidence Use / Boundary |
|---|---|---|
| AML.TA0000 AI Model Access | Pr-1, Pr-2, Tr-4; As | Model-access paths select leakage, inference, lineage, and exposure tests |
| AML.TA0001 AI Attack Staging | Ro-1, Ro-4, Tr-4 | Selects adversarial-input, poisoning, and provenance tests |
| AML.TA0002 Reconnaissance | Tr-3, Tr-4; As | Informs probing visibility and discoverable-origin evidence |
| AML.TA0003 Resource Development | Ro-4, Tr-4; ACI Pc | Identifies malicious artifacts and provenance paths to test |
| AML.TA0004 Initial Access | Cn-1, Cn-5, Pr-2; As | Selects trust-boundary, identity, and exposed-entry tests |
| AML.TA0005 Execution | Cn-1, Cn-2, Cn-3, Cn-6; Aa | Selects tool authority, output release, escalation, and action-gating tests |
| AML.TA0006 Persistence | Cn-2, Cn-5, Tr-3; Rf | Selects persistent-state, credential, audit, eviction, and recovery tests |
| AML.TA0007 Defense Evasion | Cn-3, Cn-4, Tr-2, Tr-3; ACI C_monitor | Selects bypass, detection-evasion, logging, and monitoring-health tests |
| AML.TA0008 Discovery | Pr-1, Pr-2, Tr-4; As | Selects model, data, service, and exposure discovery tests |
| AML.TA0009 Collection | Pr-1, Pr-3, Pr-4; Tr-3 | Selects collection, minimization, re-identification, and audit tests |
| AML.TA0010 Exfiltration | Pr-1, Pr-4, Cn-1, Cn-3; Tr-3 | Selects leakage, egress-boundary, release-gate, and detection tests |
| AML.TA0011 Impact | Ro-2, Ro-3, Ro-4; Cp, Rf | Selects integrity, availability, behavior, cascade, and recovery tests; Cp remains graph-derived |
| AML.TA0012 Privilege Escalation | Cn-1, Cn-2, Cn-5, Cn-6 | Selects authority, delegated-identity, escalation, and gating tests |
| AML.TA0013 Credential Access | Cn-5, Pr-2, Tr-3 | Selects token, key, workload-identity, and credential-use tests |
| AML.TA0014 Command and Control | Cn-1, Cn-2, Tr-3; As | Selects outbound-control, session, egress, and command-channel tests |
| AML.TA0015 Lateral Movement | Cn-1, Cn-2, Cn-5; Cp | Selects segmentation, delegated-access, identity, and graph-reachability tests |
Key findings
- All 16 tactics in released data v2026.07 are accounted for; technique examples in the detailed mapping are illustrative, not a complete 178-technique crosswalk.
- ATLAS provides threat and case-study context. AITBM scores only measured deployment evidence under its own rubrics and current Section 5 formula.
- The released v2026.07 universe contains 101 top-level techniques, 77 sub-techniques, 37 mitigations, and 68 case studies.
- AITBM does not create ATLAS-style identifiers for emerging MCP or agentic patterns and does not imply MITRE endorsement.