Comply · Global standards & industry frameworks
MITRE ATLAS
A living threat knowledge base for AI systems.
MITRE ATLAS is a globally accessible, living knowledge base of adversary tactics and techniques involving AI. It covers attacks on AI-enabled systems, abuse or manipulation of AI capabilities, and harmful autonomous behavior supported by observations of real attacks and realistic security demonstrations.
Primary source: MITRE ATLAS threat matrix and overview ↗
Who it applies to
Security, AI engineering, and red-team teams assessing attacks on AI-enabled, generative, and agentic systems.
How teams use ATLAS
- Map credible AI threats to the ATLAS matrix
- Review relevant tactics, techniques, mitigations, and case studies
- Test controls against observed attacks and realistic security demonstrations
- Update threat models as ATLAS and the AI system change
How Maetra maps agents to MITRE ATLAS
Maetra's Secure module scans runtime inputs, messages, tool calls, and outputs for unsafe content relevant to ATLAS. Audit preserves the system, finding, and response evidence teams need for review.
In practice, Maetra:
- Scans and fingerprints each agent. Discover reads the agent’s code — its tools, data access and sensitivity, actions, model, and environment — into an evidence-backed profile tied to the exact file and commit.
- Decides what applies. That profile determines whether MITRE ATLAS is in scope for the agent and which of its requirements apply.
- Auto-detects controls and surfaces gaps. Controls your code already satisfies are detected automatically from the scan; the rest become a clear list of gaps, each tied to the requirement and the evidence it still needs.
- Proves it and keeps it current. Close gaps with linked evidence or generated documents — reused across every framework the same control supports — and Maetra re-checks on each rescan and flags evidence that has gone stale.
Related frameworks
Use MITRE ATLAS evidence with Maetra
Map each AI system to relevant ATLAS tactics and techniques, connect runtime findings to current evidence, and keep the review history available to security teams.