Security Data Works

Original framework · Needs validation · 3/5

The ATLAS Wall.

The D3FEND Wall asks the defensive question: what don't you cover? This is the same map drawn for the AI-attack world, so it asks the same question of MITRE ATLAS itself. Every ATLAS mitigation runs across the top, every ATLAS technique down the side, and a cell is filled where ATLAS maps that mitigation to that technique. The shape that falls out is mostly empty, and the empty part is the point.

ATLAS Wall — mitigation coverage of ATLAS techniques (v2026.06)35 ATLAS mitigations (columns) x 173 techniques (rows); 247 mapped cells (67 hi / 180 low). SCF excluded from weighting — single-license ATLAS-derived artifact.Mapping is RELEVANCE, not interdiction: across 9 recent agentic/GenAI case studies, 0 of 17 mapped mitigations survived adversarial counterfactual refutation. Read a 'hi' cell as 'mapped to a real, recent technique', never as 'would have stopped the attack'. hi: Realized target, recently exercisedlow: mapped, less mature / not recentfrontier gap: technique with 0 mitigationsM0024 AI Telemetry LoggingM0004 Restrict Number of AI Model M0005 Control Access to AI Models M0006 Use Ensemble MethodsM0019 Control Access to AI Models M0002 Passive AI Output ObfuscatioM0015 Adversarial Input DetectionM0013 Code SigningM0003 Model HardeningM0008 Validate AI ModelM0010 Input RestorationM0020 Generative AI GuardrailsM0023 AI Bill of MaterialsM0021 Generative AI GuidelinesM0022 Generative AI Model AlignmenM0026 Privileged AI Agent PermissiM0027 Single-User AI Agent PermissM0000 Limit Public Release of InfoM0014 Verify AI ArtifactsM0018 User TrainingM0017 AI Model Distribution MethodM0033 Input and Output Validation M0001 Limit Model Artifact ReleaseM0032 Segmentation of AI Agent ComM0034 Deepfake DetectionM0025 Maintain AI Dataset ProvenanM0028 AI Agent Tools Permissions CM0007 Sanitize Training DataM0012 Encrypt Sensitive InformatioM0011 Restrict Library LoadingM0016 Vulnerability ScanningM0009 Use Multi-Modal SensorsM0029 Human In-the-Loop for AI AgeM0030 Restrict AI Agent Tool InvocM0031 Memory HardeningT0047 AI-Enabled Product or ServiceT0114 AI Service Web InterfaceT0024 Exfiltration via AI Inference APIT0005.001 Train Proxy via ReplicationT0024.000 Infer Training Data MembershipT0024.001 Invert AI ModelT0024.002 Extract AI ModelT0040 AI Model Inference API AccessT0025 Exfiltration via Cyber MeansT0034 Cost HarvestingT0046 Spamming AI System with Chaff DataT0042 Verify AttackT0014 Discover AI Model FamilyT0013 Discover AI Model OntologyT0029 Denial of AI ServiceT0010.001 AI SoftwareT0043.001 Black-Box OptimizationT0043.003 Manual ModificationT0043 Craft Adversarial DataT0018 Manipulate AI ModelT0018.001 Modify AI Model ArchitectureT0031 Erode AI Model IntegrityT0043.002 Black-Box TransferT0018.002 Embed MalwareT0043.004 Insert Backdoor TriggerT0043.000 White-Box OptimizationT0010.003 ModelT0062 Discover LLM HallucinationsT0005 Create Proxy AI ModelT0051 LLM Prompt InjectionT0051.000 DirectT0051.001 IndirectT0051.002 TriggeredT0044 Full AI Model AccessT0057 LLM Data LeakageT0058 Publish Poisoned ModelsT0054 LLM JailbreakT0061 LLM Prompt Self-ReplicationT0056 Extract LLM System PromptT0085.000 RAG DatabasesT0015 Evade AI ModelT0010 AI Supply Chain CompromiseT0018.000 Poison AI ModelT0063 Discover AI Model OutputsT0007 Discover AI ArtifactsT0082 RAG Credential HarvestingT0085 Data from AI ServicesT0085.001 AI Agent ToolsT0020 Poison Training DataT0048.004 AI Intellectual Property TheftT0002 Acquire Public AI ArtifactsT0000 Search Open Technical DatabasesT0003 Search Victim-Owned WebsitesT0004 Search Application RepositoriesT0005.002 Use Pre-Trained ModelT0010.002 DataT0035 AI Artifact CollectionT0019 Publish Poisoned DatasetsT0053 AI Agent Tool InvocationT0011.000 Unsafe AI ArtifactsT0011.001 Malicious PackageT0005.000 Train Proxy via Gathered AI ArT0002.001 ModelsT0101 Data Destruction via AI Agent ToolT0086 Exfiltration via AI Agent Tool InvT0052 PhishingT0052.000 Spearphishing via Social EnginT0052.001 Deepfake-Assisted PhishingT0011 User ExecutionT0002.000 DatasetsT0098 AI Agent Tool Credential HarvestinT0059 Erode Dataset IntegrityT0088 Generate DeepfakesT0041 Physical Environment AccessT0080 AI Agent Context PoisoningT0080.000 MemoryT0065 LLM Prompt CraftingT0079 Stage CapabilitiesT0017 Develop CapabilitiesT0048.003 User HarmT0048 External HarmsT0010.005 AI Agent ToolT0012 Valid AccountsT0037 Data from Local SystemT0055 Unsecured CredentialsT0074 MasqueradingT0104 Publish Poisoned AI Agent ToolT0008 Acquire InfrastructureT0011.002 Poisoned AI Agent ToolT0048.000 Financial HarmT0049 Exploit Public-Facing ApplicationT0072 Reverse ShellT0073 ImpersonationT0006 Active ScanningT0008.005 AI Service ProxiesT0016.002 Generative AIT0048.002 Societal HarmT0076 Corrupt AI ModelT0096 AI Service APIT0097 Virtualization/Sandbox EvasionT0102 Generate Malicious CommandsT0103 Deploy AI AgentT0109 AI Supply Chain Rug PullT0110 AI Agent Tool PoisoningT0008.001 Consumer HardwareT0016 Obtain CapabilitiesT0016.000 Adversarial AI Attack ImplemenT0016.001 Software ToolsT0021 Establish AccountsT0036 Data from Information RepositoriesT0075 Cloud Service DiscoveryT0087 Gather Victim Identity InformationT0050 Command and Scripting InterpreterT0068 LLM Prompt ObfuscationT0093 Prompt Infiltration via Public-FacT0078 Drive-by CompromiseT0081 Modify AI Agent ConfigurationT0112.000 Local AI AgentT0008.002 DomainsT0067 LLM Trusted Output Components ManiT0077 LLM Response RenderingT0080.001 ThreadT0083 Credentials from AI Agent ConfigurT0092 Manipulate User LLM Chat HistoryT0095 Search Open Websites/DomainsT0105 Escape to HostT0002.002 AI Agent ConfigurationT0011.003 Malicious LinkT0066 Retrieval Content CraftingT0069.000 Special Character SetsT0069.001 System Instruction KeywordsT0069.002 System PromptT0070 RAG PoisoningT0084.000 Embedded KnowledgeT0084.001 Tool DefinitionsT0084.002 Activation TriggersT0084.003 Call ChainsT0089 Process DiscoveryT0090 OS Credential DumpingT0091.000 Application Access TokenT0091.001 Web Session CookieT0095.000 Code RepositoriesT0100 AI Agent ClickbaitT0106 Exploitation for Credential AccessT0107 Exploitation for Defense EvasionT0108 AI AgentT0111 AI Supply Chain Reputation InflatiT0112 Machine CompromiseT0113 Steal Web Session CookieT0000.001 Pre-Print RepositoriesT0001 Search Open AI Vulnerability AnalyT0008.000 AI Development WorkspacesT0008.003 Physical CountermeasuresT0010.004 Container RegistryT0017.000 Adversarial AI AttacksT0048.001 Reputational HarmT0060 Publish Hallucinated EntitiesT0064 Gather RAG-Indexed TargetsT0067.000 CitationsT0069 Discover LLM System InformationT0071 False RAG Entry InjectionT0084 Discover AI Agent ConfigurationT0091 Use Alternate Authentication MaterT0094 Delay Execution of LLM InstructionT0000.000 Journals and Conference ProceeT0000.002 Technical BlogsT0008.004 ServerlessT0010.000 HardwareT0034.000 Excessive QueriesT0034.001 Resource-Intensive QueriesT0034.002 Agentic Resource ConsumptionT0099 AI Agent Tool Data PoisoningT0112.001 AI ArtifactsFRONTIER GAP — 97 techniques with no mapped mitigation (36 Realized)
MITRE ATLAS v2026.06. 35 mitigations (columns) × 173 techniques (rows); 247 mapped cells. Seriation clusters coverage toward the top; the tinted band is the frontier gap. Reproducible from the committed ATLAS-derived layer — no SCF, no external crosswalk in the weights.

What the wall shows

ATLAS carries 247 mitigation-to-technique mappings, which sounds like coverage until you count the rows it leaves blank: 97 of the 173 techniques (56%) have no mapped mitigation at all, and 36 of those uncovered techniques are Realized — ATLAS's own label for techniques observed in real incidents, not just demonstrated in a lab. The single most-exercised recent technique, LLM Prompt Crafting, shows up in 15 recent case studies and has zero mapped ATLAS mitigations. Coverage is not just sparse; it thins out exactly where the newest attacks are landing.

How the cells are weighted

A filled cell is hi or low, and the rule is deliberately simple so you can rebuild it or disagree with it. A cell scores on two signals that ATLAS actually carries: the maturity of the target technique (Realized counts more than Demonstrated or Feasible) and whether that technique was exercised in a recent 2024–2026 case study. A cell is hi only where both hold — a mapping to a real, recently-seen technique — which is the one place the maturity read and the recency read agree. 67 of the 247 cells clear that bar; the other 180 are mapped but point at something less mature or less recent.

Mapping is relevance, not interdiction

This is the caveat the whole artifact rests on, so it rides on the front rather than in a footnote. A mapping says a mitigation is relevant to a technique; it does not say the mitigation would have stopped the attack. I tested that gap directly: across nine recent agentic and GenAI case studies, 17 mapped (mitigation, case) pairs looked like they might plausibly interdict a step, and under an adversarial refuter told to default to skepticism, zero of the 17 survived. So read a hi cell as “mapped to a real, recent technique,” never as “this would have worked.” ATLAS carries no efficacy measurement, and the wall does not invent one.

Built from MITRE ATLAS v2026.06 (Apache-2.0), reproducibly, from the committed edge, maturity, recency, and counterfactual layers. SCF is deliberately excluded from the weighting, which keeps the artifact single-licence and clean to publish. Method and every number: the ATLAS-Wall claims register.