Most organisations know about prompt injection. Far fewer understand retrieval poisoning, agent memory corruption, autonomous workflow manipulation, or AI supply chain attacks. The MITRE Threat Explorer™ makes the full MITRE ATLAS framework searchable, visual, and actionable — for everyone from red teams to compliance officers.
Searchable database of 20+ MITRE ATLAS techniques with attack paths, kill chains, sandbox simulations, and mitigation guidance. Free, no signup required.
Security teams already have threat intelligence platforms, SIEM solutions, vulnerability databases, and MITRE ATT&CK. These work well for traditional cybersecurity. But AI introduces attack categories that appear nowhere in traditional frameworks. You can't look up "retrieval poisoning" in a CVE database. You can't find "agent memory corruption" in ATT&CK. You can't query a SIEM for "autonomous workflow manipulation."
This is the gap MITRE ATLAS fills — and the gap MITRE Threat Explorer™ makes navigable.
| Dimension | MITRE ATT&CK | MITRE ATLAS |
|---|---|---|
| Primary target | Traditional IT infrastructure | AI and ML systems |
| Key techniques | Phishing, lateral movement, persistence | Prompt injection, model theft, agent abuse, RAG poisoning |
| Affected components | Servers, endpoints, networks | LLMs, agents, RAG pipelines, training data |
| Attack entry points | Vulnerabilities, credentials, phishing | Prompts, retrieved content, training data, tool integrations |
| Detection methods | Log analysis, signature detection | Semantic analysis, behaviour monitoring, output validation |
| Organisation needs | ATT&CK for infrastructure | ATLAS for all deployed AI systems |
MITRE ATLAS — Adversarial Threat Landscape for Artificial Intelligence Systems — is the leading public framework for AI-specific attack techniques. Developed by MITRE (the same organisation behind ATT&CK), ATLAS catalogues how adversaries target AI systems throughout their lifecycle: during training, at inference time, through retrieval systems, via agent tool integrations, and through supply chain compromise.
ATLAS organises techniques into tactics (the "why") and techniques (the "how"). Understanding both is essential for building AI security controls that address the actual attack surface, not just what looks familiar from traditional cybersecurity.
ATLAS is best understood as the AI-specific counterpart to MITRE ATT&CK, the long-established framework for traditional IT threats. Security teams already running ATT&CK-based threat intelligence, SIEM rules, and vulnerability management need a separate, complementary framework for AI — the two cover fundamentally different attack surfaces and don't substitute for one another.
| Dimension | MITRE ATT&CK | MITRE ATLAS |
|---|---|---|
| Domain | IT systems — networks, endpoints, cloud | AI and ML systems — models, pipelines, APIs |
| Attack type | Code exploits, network attacks | Prompt injection, data poisoning, model manipulation |
| ID format | T1xxx (e.g. T1059) | AML.Txxxx (e.g. AML.T0051) |
| Detection methods | Log analysis, signature detection | Semantic analysis, behaviour monitoring, output validation |
| Organisation needs | ATT&CK for infrastructure | ATLAS for all deployed AI systems |
You can't look up "retrieval poisoning" in a CVE database. You can't find "agent memory corruption" in ATT&CK. ATLAS exists specifically to fill that gap — and every technique ID referenced throughout HexTyx scan findings (AML.T0051, AML.T0054, AML.T0020, and others) traces back to this taxonomy, giving your findings a standardised reference point auditors and security teams already recognise.
The most common AI attack category. Adversaries craft inputs to override intended model behaviour.
Exploiting autonomous agents' tool access, memory, and workflow execution capabilities.
Manipulating RAG knowledge bases to influence AI outputs or expose sensitive data.
Extracting sensitive information through AI outputs, retrieval systems, or cross-tenant exposure.
Extracting proprietary model capabilities, weights, or training data through repeated queries.
Compromising AI components at the source — foundation models, plugins, MCP servers, dependencies.
Search 20+ MITRE ATLAS techniques by name, category, ATLAS ID, or affected system
Step-by-step attack chains showing how each technique progresses from initial access to impact
Multi-technique attack scenarios showing how real adversaries chain ATLAS techniques together
Interactive simulation showing how each attack works and how defences respond in practice
Specific, actionable controls for each technique — including vendor coverage percentages
Cross-references to OWASP LLM Top 10, NIST AI RMF, and other AI security frameworks
Red teams and penetration testers — use it to build AI attack scenarios mapped to real ATLAS techniques. The kill chains section shows how adversaries combine multiple techniques into a complete attack campaign.
Security architects — use it to design AI security controls against the actual attack surface, not just generic best practices. Each threat page links to the specific mitigations most effective against that technique.
Compliance teams — use it to map MITRE ATLAS coverage to NIST AI RMF, OWASP LLM Top 10, and EU AI Act requirements. The framework mappings on each threat page make this explicit.
CISOs and AI security leads — use it alongside the MITRE ATLAS Coverage Calculator™ to identify which techniques your organisation is currently uncovered against, and prioritise investments accordingly.
After exploring threats in the Threat Explorer, use the Coverage Calculator to score how well your organisation covers the full MITRE ATLAS framework.