The AI Learning Hub Journal

Enumerating Techniques with MITRE ATLAS

Work the matrix, column by column — coverage you can defendcomponents down the side, tactics across the top; every cell answered is a claim you can stand behindENUMERATING FROM MEMORYa biased sample dominated by whatever you read most recentlyWALKING THE PUBLISHED MATRIXforces you past the bias — a defensible answer to what you consideredYOUR COMPONENTS × ATLAS TACTICS — EACH CELL: ACHIEVABLE HERE?RECONINITIAL ACCESSEXECUTIONPERSISTENCEEXFILTRATIONRETRIEVAL CORPUS—unreviewedvendor sync—planted doc waitsin the index—TOOLS + SERVERStool listdiscoveryhostile tooldescriptionargumentsteering—query-stringegressMEMORY STORES———model-writtenentry survives—OUTPUT CONSUMERS——unvalidateddownstream parse—rendered remotefetchempty cells are findings too — record why the technique does not apply herePOPULATED CELLS BECOME THE TEST PLANordered by reach × reversibility; record control + intended testPICK THE FRAMEWORK BY TASKATLAS = techniques · OWASP LLM = app checklist · NIST RMF = programmeA CATALOGUE IS A FLOOR, NOT A CEILING — ADD THE DOMAIN-EXPERT PASSthe matrix finds what is known; people who know the domain find what would hurt most here
Cross your components against ATLAS tactics cell by cell — populated cells become the test plan, and empty cells become justified exclusions.

What ATLAS Actually Gives You

ATLAS is a knowledge base of adversary tactics and techniques against AI-enabled systems, structured like ATT&CK: tactics as columns representing adversary objectives, techniques as the methods used to achieve them, and case studies drawn from reported incidents and research. The tactic sequence spans reconnaissance and resource development, initial access, model access, execution, persistence, privilege escalation, defence evasion, discovery, collection, staging of attacks against the model, exfiltration, and impact. Its practical value to a practitioner is not conceptual education — it is coverage. Enumerating from memory produces the techniques you happen to think of, which is a biased sample dominated by whatever you read most recently. Working column by column through a published matrix forces you past that bias and produces a defensible answer to the question of what you considered.

  • Tactics are adversary objectives; techniques are the methods used to reach them
  • Case studies tie techniques to reported incidents rather than speculation
  • The value is coverage and defensibility, not novelty of ideas
  • Enumeration from memory is a biased sample — the matrix is the corrective

Using It Against Your Diagram

Do not read ATLAS as a document; use it as an axis. Build a matrix with your diagram components down one side and the tactics across the top, then for each cell ask whether any technique in that tactic is achievable against that component in your system. Most cells will be empty, and the empty ones matter — they are your justified exclusions. A retrieval corpus with reviewed writes may have no plausible initial-access technique, and saying so with a reason is a stronger position than never having asked. The populated cells become your test plan for the second and fourth modules, ordered by the reach-and-reversibility ranking you already built. Record for each populated cell the technique, the component, the current control if any, and the intended test. That table is the artefact auditors, engineers and testers can all use, which is rare.

  • Components down the side, tactics across the top, techniques inside the cells
  • Empty cells are findings too — record why the technique does not apply
  • Populated cells become the test plan, ordered by your reach and reversibility ranking
  • One table serves engineering, testing, and assurance — build it once

Complementary Frameworks, Different Jobs

Three reference sets get cited together and answer different questions, so pick by task rather than by preference. ATLAS answers what an adversary might do, technique by technique — use it for enumeration and coverage. The OWASP Top 10 for LLM Applications answers what commonly goes wrong at the application layer, in language application teams already use — use it as a review checklist and a shared vocabulary with developers. The NIST AI Risk Management Framework and similar governance frameworks answer how an organisation should organise itself to manage the risk — use them for programme structure, roles, and documentation obligations, not for technique enumeration. Mixing the layers is a common failure: a governance framework will never tell you which test to run, and a technique matrix will never tell you who owns the decision.

  • ATLAS for technique enumeration and coverage claims
  • OWASP LLM application risks for the review checklist and shared developer vocabulary
  • Governance frameworks for programme structure and documentation, not for test selection
  • Using the wrong layer for the question is why framework exercises stall

The Limits of Any Catalogue

A published matrix is a floor, not a ceiling, and treating it as complete is the failure mode to guard against. Catalogues lag practice, because they document what has been observed and written up; a system with an unusual architecture will have exposure nobody has catalogued. They are also silent on your business logic — no matrix will tell you that in your domain, a plausible but wrong answer about eligibility is more damaging than a data leak. And coverage against a catalogue is easy to overstate: marking a technique as mitigated because a related control exists is how a matrix turns into reassurance. Use the catalogue to guarantee a floor, then add a deliberate unstructured pass where people who understand the domain ask what would be worst for this specific system. The catalogue finds what is known; the domain expert finds what matters.

  • Catalogues document observed techniques and therefore lag novel architectures
  • Business-logic harm is domain knowledge and appears in no published matrix
  • A control that is related is not a control that is verified — do not mark it mitigated
  • Pair structured enumeration with an unstructured pass by people who know the domain

Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.