Chronicle/Policy & standards

MITRE ATLAS 5.0 adds AI agent techniques such as context poisoning and exfiltration via tool invocation

PolicyStandardSignificance assistant-drafted

MITRE ATLAS version 5.0.0 added a set of techniques for attacks on AI agents, including agent context poisoning of memory and threads, modifying agent configuration, credential theft from agent configuration, and exfiltration via agent tool invocation, and renamed LLM Plugin Compromise to AI Agent Tool Invocation. Version 5.1.0 (November 6, 2025) added agent-specific mitigations such as tool permission configuration and human-in-the-loop for agent actions.

Why it matters

ATLAS is the ATT&CK-style reference defenders use to map detections, and these versions made agent compromise a first-class part of it.

Key facts

As stated in the sources, with where to find them.

  • 5.0.0 (2025-09-30) added AI Agent Context Poisoning (AML.T0080) with Memory and Thread sub-techniques, Modify AI Agent Configuration (T0081), Credentials from AI Agent Configuration (T0083), Discover AI Agent Configuration (T0084), and Exfiltration via AI Agent Tool Invocation (T0086); it also added a technique maturity field (feasible, demonstrated, realized).CHANGELOG, 5.0.0
  • 5.1.0 (2025-11-06) added mitigations AML.M0026-M0031, including AI Agent Tools Permissions Configuration, Human In-the-Loop for AI Agent Actions, Restrict AI Agent Tool Invocation on Untrusted Data, and Memory Hardening; that release contained 84 techniques and 42 case studies.CHANGELOG, 5.1.0

Findings that cite this record

No tracked finding cites this record yet.

Key questions this bears on

Sources

Related records