Discovery (9 techniques)
MITRE ATLAS tactic
The adversary is trying to figure out your AI environment. Discovery consists of techniques an adversary may use to gain knowledge about the system and internal network. These techniques help adversaries observe the environment and orient themselves before deciding how to act. They also allow adversaries to explore what they can control and what's around their entry point in order to discover how it could benefit their current objective. Native operating system tools are often used toward this post-compromise information-gathering objective.
Techniques
- AML.T0007 — Discover AI ArtifactsMaturity: demonstrated
- AML.T0013 — Discover AI Model OntologyMaturity: demonstrated
- AML.T0014 — Discover AI Model FamilyMaturity: feasible
- AML.T0062 — Discover LLM HallucinationsMaturity: demonstrated
- AML.T0063 — Discover AI Model OutputsMaturity: demonstrated
- AML.T0069 — Discover LLM System InformationMaturity: demonstrated
- AML.T0075 — Cloud Service DiscoveryMaturity: realized
- AML.T0084 — Discover AI Agent ConfigurationMaturity: demonstrated
- AML.T0089 — Process DiscoveryMaturity: demonstrated
AI red teaming training, taught by practitioners.
Hands-on courses on adversarial AI, prompt injection, and AI security operations.
View AI Security Courses