ConsultingWorkbench-backed AI security engagements — map, attack, defend, and prove your AI systems.
Scope a Review

Labs / AI Control Crosswalk

v1.16.0

MITRE ATLAS Navigator

Interactive adversary matrix, Navigator layer overlays, case-study heatmaps, and technique exploration packaged as a Labs product.

Curated from the upstream ATLAS data repositories and surfaced here as a product-grade, public-safe Navigator experience instead of a raw signal dump.
ATLAS Navigator product surface diagram

Tactics

16

Techniques

170

Mitigations

35

Case studies

57

Navigator implementation

This surface now renders a real layer-compatible Navigator UI on top of the ATLAS matrix, frequency layer, and case-study layer exports.

Snapshot

ATLAS coverage, source metadata, and assessment summary

Matrices
1

ATLAS matrix bundles mirrored into the curated export.

Tactics
16

Adversary goals in the public ATLAS matrix.

Techniques
170

Combined technique inventory across roots and sub-techniques.

Root techniques
101

Top-level techniques in the current release.

Sub-techniques
69

Nested technique variants in the current release.

Mitigations
35

Mitigation objects mapped to technique coverage.

Case studies
57

Public case studies and incident narratives in the bundle.

technique

AI Agent Tool Invocation

Maturity demonstrated · 11 mitigations · 14 case studies

technique

Evade AI Model

Maturity realized · 6 mitigations · 17 case studies

technique

LLM Prompt Crafting

Maturity realized · 0 mitigations · 18 case studies

subtechnique

Indirect

Maturity demonstrated · 2 mitigations · 13 case studies

technique

AI-Enabled Product or Service

Maturity realized · 1 mitigations · 13 case studies

technique

Exfiltration via AI Agent Tool Invocation

Maturity realized · 8 mitigations · 5 case studies

Release v5.6.1
5.6.0
v1.16.0

Based on MITRE ATLAS public data, not proof of any organization’s internal security maturity.

Tactics

16

Case studies

57

Repository metadata

Data repoatlas-data
Navigator repoatlas-navigator-data
Release dateMay 6, 2026
Navigator releaseApr 30, 2026
Matrix version5.6.0

Top mitigations

Most linked controls

MitigationTechniquesLifecycle
AI Telemetry Logging
AML.M0024
17Deployment, Monitoring and Maintenance
Restrict Number of AI Model Queries
AML.M0004
16Business and Data Understanding, Deployment, Monitoring and Maintenance
Control Access to AI Models and Data at Rest
AML.M0005
13Business and Data Understanding, Data Preparation, ML Model Engineering, ML Model Evaluation
Passive AI Output Obfuscation
AML.M0002
11Deployment, ML Model Evaluation
Use Ensemble Methods
AML.M0006
11ML Model Engineering
Control Access to AI Models and Data in Production
AML.M0019
11Deployment, Monitoring and Maintenance

Top case studies

Most referenced public cases

Case studyTypeProceduresRefs
Bypassing ID.me Identity Verification
AML.CS0017
incident37
Code to Deploy Destructive AI Agent Discovered in Amazon Q VS Code Extension
AML.CS0047
incident75
Achieving Code Execution in MathGPT via Prompt Injection
AML.CS0016
exercise94
AI Model Tampering via Supply Chain Attack
AML.CS0028
exercise94
ShadowRay
AML.CS0023
incident74
LLM Jacking
AML.CS0030
incident74

Layer assets

Layer exports, case-study layers, and machine-readable bundles

The Navigator implementation is the real migration value here: the layer matrix, case-study frequency layer, per-case-study navigator layers, STIX bundles, and OpenCTI bundles all ship as public files.

Default layers

Matrix and frequency views

ATLAS Matrixatlas_layer_matrix
ATLAS Case Study Frequencyatlas_case_study_frequency
Default layers2
Case-study layers57
Total Navigator files69

Case-study layers

Navigator layer inventory

LayerTypeProceduresRefs
Bypassing ID.me Identity Verification
AML.CS0017
incident37
Code to Deploy Destructive AI Agent Discovered in Amazon Q VS Code Extension
AML.CS0047
incident75
Achieving Code Execution in MathGPT via Prompt Injection
AML.CS0016
exercise94
AI Model Tampering via Supply Chain Attack
AML.CS0028
exercise94
ShadowRay
AML.CS0023
incident74
LLM Jacking
AML.CS0030
incident74

STIX bundles

Matrix exports

BundleObjectsKey types
ATLAS STIX bundle
stix_atlas
538relationship 315, attack-pattern 170, course-of-action 35, x-mitre-tactic 16
ATLAS + ATT&CK Enterprise STIX bundle
stix_atlas_attack_enterprise
26381relationship 21341, x-mitre-analytic 1758, attack-pattern 1028, malware 729

OpenCTI bundles

Selected case-study packages

Case studyTypeObjects
Careful Who You Colab With: abusing google colaboratory
AMLCS0018_Report-Careful Who You Colab With_ abusing google colaboratory_full
aml.cs0018, mitre atlas source32
PoisonGPT: How We Hid a Lobotomized LLM on Hugging Face to Spread Fake News
AMLCS0019_Report-PoisonGPT_ How We Hid a Lobotomized LLM on Hugging Face to Spread Fake News_full
aml.cs0019, mitre atlas source27
ChatGPT Plugins: Data Exfiltration via Images & Cross Plugin Request Forgery
AMLCS0021_Report-ChatGPT Plugins_ Data Exfiltration via Images & Cross Plugin Request Forgery_full
aml.cs0021, mitre atlas source, ml-ready26
New Jersey Man Indicted in Fraud Scheme to Steal California Unemployment Insurance Benefits
AMLCS0017_Report-New Jersey Man Indicted in Fraud Scheme to Steal California Unemployment
aml.cs0017, mitre atlas source19
Indirect Prompt Injection Threats: Bing Chat Data Pirate
AMLCS0020_Report-Indirect Prompt Injection Threats_ Bing Chat Data Pirate_full
aml.cs0020, mitre atlas source16
MITRE ATLAS Case Study: Face Identification System Evasion via Physical Countermeasures
AMLCS0012_ Face Identification System Evasion via Physical Countermeasures_full
mitre atlas source, aml.cs001214

Explorer

Search techniques, maturity levels, and mapped signals

The technique explorer is intentionally lightweight: search by ID or label, narrow by maturity, and isolate one tactic at a time.

Charts

ATLAS signal profile

The charts are generated from the same upstream bundle as the tables above so the visual layer and the explorer stay in sync.

MITRE ATLAS Explorer

ATLAS coverage by tactic

Technique, sub-technique, and case-study coverage grouped by tactic.

public.data.external.atlas.atlas.explorer
Source: public.data.external.atlas.atlas.explorer
Based on MITRE ATLAS public data, not proof of any organization’s internal security maturity.

MITRE ATLAS Explorer

ATLAS technique maturity distribution

Current maturity labels in the upstream ATLAS technique bundle.

public.data.external.atlas.atlas.explorer
Source: public.data.external.atlas.atlas.explorer
Based on MITRE ATLAS public data, not proof of any organization’s internal security maturity.

MITRE ATLAS Explorer

ATLAS case-study type distribution

How the upstream case studies split between incidents and exercises.

public.data.external.atlas.atlas.explorer
Source: public.data.external.atlas.atlas.explorer
Based on MITRE ATLAS public data, not proof of any organization’s internal security maturity.

Assets

Mirrored validation schemas and public bundle assets

The repo keeps the useful upstream assets that help us validate, extend, and consume ATLAS without mirroring the full source tree.

Ready

Explorer JSON

Curated ATLAS matrix snapshot.

Size: 311.9 KB

Ready

Assessment JSON

Coverage scorecards and top-linked items.

Size: 15.1 KB

Ready

Navigator manifest

Layer inventory and release metadata.

Size: 35.2 KB

Ready

Layer matrix

Navigator-friendly matrix export.

Size: public JSON

Mirrored schema files

Navigator manifest35.2 KB
Case-study layers57
STIX bundles2
OpenCTI bundles8

Source

Upstream repository, release, and provenance

Repository

MITRE ATLAS data

This Labs page consumes the curated public snapshot from the upstream ATLAS repositories rather than mirroring the full source tree into the app.

Provenance

Release details

Commit
8ee2c689a7d3c65ddf2bfe4950a4f3ecffa6f48b
Tag
v5.6.1
Released
May 6, 2026
Matrix version
5.6.0
Assessment bundle
9 scorecards
Navigator files
69 files