Framework Explorer

MITRE ATLAS

Reviewed AuditaAI assessments connect documented offering behavior to ATLAS technique context. Related framework references do not create product coverage.

Official MITRE source

AML.T0051

LLM Prompt Injection

Manipulation of LLM execution through direct jailbreaks or indirect injected content.

18 reviewed alignments
Reviewed offering assessments+
Cranium AI, Inc. · Cranium AI Security and Governance PlatformInferred alignmentmedium confidence · 2 sources

Cranium AI platform interaction inspection is positioned to detect adversarial prompt-injection patterns in runtime workflows.

Adversarial prompt interaction detection aligns with ATLAS prompt-injection technique context.

Amazon Web Services · Amazon Bedrock GuardrailsInferred alignmenthigh confidence · 1 source

Amazon Bedrock Guardrails applies inline controls that can block prompt-injection and jailbreak-style requests before model outputs are returned.

Inline mitigation of adversarial prompt attempts aligns with ATLAS prompt-injection technique context.

F5, Inc. · F5 AI GuardrailsInferred alignmenthigh confidence · 1 source

F5 AI Guardrails applies inline policy controls that can block prompt-injection payloads before requests reach downstream models and tools.

Prompt-injection blocking behavior aligns with ATLAS prompt-injection technique context.

Cato Networks · Cato AI Security (AISEC)Inferred alignmenthigh confidence · 1 source

Cato AI Security runtime monitoring detects prompt-injection patterns and policy-violating AI prompt activity.

Prompt abuse monitoring aligns with ATLAS prompt-injection technique context.

Lakera · Lakera GuardInferred alignmentmedium confidence · 2 sources

Lakera runtime AI security positioning includes prompt attack prevention, data leakage protection, and context-aware runtime security controls.

Lakera runtime prompt-attack prevention positioning aligns with ATLAS prompt-injection technique context.

Cisco · AI Runtime ProtectionInferred alignmenthigh confidence · 1 source

AI Runtime Protection provides runtime guardrails for prompt and response threat mitigation.

Runtime prompt-threat mitigation aligns to the ATLAS prompt-injection technique context.

Google Cloud · Model ArmorInferred alignmenthigh confidence · 1 source

Model Armor scans prompts and responses for prompt injection and jailbreak content and can return a block verdict when a violation is detected.

AuditaAI assessment: inspecting and blocking prompt injection is aligned to the ATLAS prompt-injection technique context.

Wiz · Wiz AI Runtime ProtectionInferred alignmenthigh confidence · 1 source

Wiz AI Runtime Protection detects prompt injection, rogue agents, and malicious behavior targeting AI systems.

AuditaAI assessment: detecting documented prompt injection is aligned to the ATLAS prompt-injection technique context.

HiddenLayer · AI Attack SimulationInferred alignmenthigh confidence · 1 source

AI Attack Simulation tests AI systems for jailbreaks, prompt injection, data leakage, and unsafe agent tool use through automated adversarial simulation.

Testing for prompt injection aligns to the ATLAS prompt-injection technique context.

HiddenLayer · AI Runtime SecurityInferred alignmenthigh confidence · 1 source

AI Runtime Security detects and investigates prompt injection, unsafe agent behavior, sensitive data exposure, malicious tool use, and other runtime AI threats.

Detecting documented prompt injection aligns to the ATLAS prompt-injection technique context.

Mindgard · AI Runtime Threat Detection and ResponseInferred alignmentmedium confidence · 1 source

AI Runtime Threat Detection and Response monitors production AI execution to detect suspicious outputs and attack behavior.

Runtime detection of suspicious prompt-driven abuse behavior aligns with ATLAS prompt-injection technique context.

Mindgard · AI Runtime Threat Detection and ResponseInferred alignmenthigh confidence · 1 source

Runtime guardrails are applied to block prompt injection attack paths before harmful model behavior propagates.

Runtime controls for prompt-injection blocking align with the ATLAS prompt-injection technique context.

Microsoft · Azure AI Content Safety and Prompt ShieldsInferred alignmenthigh confidence · 1 source

Azure AI Content Safety and Prompt Shields identify direct and indirect prompt injection and related unsafe prompt patterns before they reach downstream model behavior.

Prompt shielding behavior aligns to the ATLAS prompt-injection technique context.

Nightfall AI · AI Agent SecurityInferred alignmentmedium confidence · 1 source

AI Agent Security uses hook-level interception and tool-call governance to constrain unsafe autonomous actions before execution.

Hook-level interception of prompt-driven agent actions aligns to ATLAS prompt-injection technique context.

Portkey · PortkeyInferred alignmentmedium confidence · 1 source

Portkey invokes Prisma AIRS guardrail checks before and after model requests and can enforce returned block verdicts.

AuditaAI assessment: pre- and post-request guardrail checks with block verdicts support the ATLAS prompt-injection context.

Prompt Security · Prompt SecurityInferred alignmenthigh confidence · 1 source

Prompt Security runtime enforcement can block prompt-injection attempts in employee and application AI interaction paths.

Prompt threat controls align with ATLAS prompt-injection technique context.

Snowflake Inc. · Cortex AI GuardrailsInferred alignmenthigh confidence · 1 source

Cortex AI Guardrails evaluate runtime prompts and responses to mitigate direct and indirect prompt-injection and jailbreak attempts.

Runtime guardrails behavior for direct and indirect prompt-injection mitigation aligns with AML.T0051 context.

SPLX · SPLX Runtime GuardrailsInferred alignmenthigh confidence · 1 source

Zscaler AI Security runtime protection blocks prompt injection, data poisoning, and malicious URLs in AI interactions.

AuditaAI assessment: runtime blocking of prompt injection is aligned to the ATLAS prompt-injection technique context.

AML.T0054

LLM Jailbreak

Bypassing LLM safety guardrails through adversarial prompting.

6 reviewed alignments
Reviewed offering assessments+
F5, Inc. · F5 AI GuardrailsInferred alignmenthigh confidence · 1 source

F5 AI Guardrails enforces policies to detect and prevent jailbreak-style attempts that seek to bypass model safety boundaries.

Guardrail policy behavior for jailbreak prevention aligns with ATLAS jailbreak technique context.

Google Cloud · Model ArmorInferred alignmenthigh confidence · 1 source

Model Armor scans prompts and responses for prompt injection and jailbreak content and can return a block verdict when a violation is detected.

AuditaAI assessment: the documented jailbreak inspection and block verdict is aligned to the ATLAS jailbreak technique context.

Mindgard · AI Red Teaming and AssessmentInferred alignmenthigh confidence · 1 source

AI Red Teaming and Assessment runs adversarial workflows to surface jailbreak and guardrail-bypass weaknesses for pre-deployment remediation.

Jailbreak and guardrail-bypass testing behavior aligns to the ATLAS jailbreak technique context.

Microsoft · Azure AI Content Safety and Prompt ShieldsInferred alignmenthigh confidence · 1 source

Azure AI Content Safety applies jailbreak detection and policy filtering to reduce unsafe prompt and response interactions at runtime.

Documented jailbreak detection and filtering align with ATLAS jailbreak technique context.

Snowflake Inc. · Cortex AI GuardrailsInferred alignmenthigh confidence · 1 source

Cortex AI Guardrails evaluate runtime prompts and responses to mitigate direct and indirect prompt-injection and jailbreak attempts.

Jailbreak-focused guardrail behavior aligns with AML.T0054 technique context.

SPLX · SPLX Runtime GuardrailsInferred alignmenthigh confidence · 1 source

Zscaler AI Security runtime protection blocks prompt injection, data poisoning, and malicious URLs in AI interactions.

AuditaAI assessment: blocking documented prompt injection is also aligned to ATLAS jailbreak technique context.

AML.T0020

Poison Training Data

Corrupting training, fine-tuning, or related data to affect model behavior.

1 reviewed alignment
Reviewed offering assessments+
SPLX · SPLX Runtime GuardrailsInferred alignmentmedium confidence · 1 source

Zscaler AI Security runtime protection blocks prompt injection, data poisoning, and malicious URLs in AI interactions.

AuditaAI assessment: blocking documented data-poisoning attempts is aligned to the ATLAS poisoning technique context.

AML.T0048

Compromise ML Software Dependencies

Compromising or exploiting third-party ML software dependencies or model artifacts.

7 reviewed alignments
Reviewed offering assessments+
Tenable Holdings, Inc. · Tenable One AI ExposureInferred alignmentmedium confidence · 2 sources

Tenable One AI Exposure analyzes AI posture and misconfiguration conditions to prioritize exposure reduction for AI workloads.

Posture analysis that includes dependency and software exposure context aligns with supply-chain risk technique context.

Chainguard · Chainguard LibrariesInferred alignmenthigh confidence · 1 source

Chainguard Libraries provides a malware-resistant dependency catalog intended to replace direct reliance on public package registries.

Malware-resistant dependency supply reduces exposure to compromised ML software dependencies.

Wiz · Wiz AI-BOMInferred alignmentmedium confidence · 1 source

Wiz AI-BOM continuously inventories AI models, datasets, frameworks, software dependencies, identities, access paths, and infrastructure.

AuditaAI assessment: inventorying frameworks and software dependencies supports the ATLAS ML-software-dependency compromise context.

HiddenLayer · AI Supply Chain SecurityInferred alignmenthigh confidence · 1 source

AI Supply Chain Security analyzes model architectures, layers, weights, and artifacts for tampering or anomalies and tracks model lineage, origin, and licensing.

Inspection for tampered model artifacts and dependencies aligns to the compromised ML dependencies technique context.

Lasso Security · AI Security Posture ManagementInferred alignmentmedium confidence · 2 sources

Lasso AI Security Posture Management evaluates misconfigurations and policy gaps, including supply-chain-oriented risk indicators before production rollout.

Supply-oriented posture assessment aligns with ATLAS AI supply-chain risk technique context.

Palo Alto Networks · Prisma AIRSInferred alignmenthigh confidence · 1 source

Prisma AIRS scans third-party models for tampering, malicious scripts, and deserialization risks.

AuditaAI assessment: scanning third-party models for tampering and malicious scripts is aligned to ML dependency and artifact compromise context.

Koi Security · Koi Agentic Endpoint SecurityInferred alignmentmedium confidence · 1 source

Koi AES evaluates code differences and behavioral shifts in real time to identify software supply-chain risk.

AuditaAI assessment: identifying software supply-chain shifts in AI-model environments supports the ATLAS dependency-compromise context.

AML.T0056

LLM Data Leakage

Exfiltrating sensitive information through an LLM application or its data paths.

11 reviewed alignments
Reviewed offering assessments+
Cranium AI, Inc. · Cranium AI Security and Governance PlatformInferred alignmenthigh confidence · 2 sources

Cranium AI platform data controls are positioned to prevent sensitive information disclosure across model and agent workflows.

Data controls preventing sensitive disclosure align with ATLAS data extraction and exfiltration risk context.

Amazon Web Services · Amazon Bedrock GuardrailsInferred alignmentmedium confidence · 1 source

Amazon Bedrock Guardrails includes sensitive-information policy controls to reduce protected-data leakage in prompt and response flows.

Controls reducing prompt and response data leakage align with ATLAS data extraction and exfiltration technique context.

F5, Inc. · F5 AI GuardrailsInferred alignmenthigh confidence · 1 source

F5 AI Guardrails inspects prompts and responses to redact or block sensitive data and reduce leakage to external AI systems.

Data leakage controls in AI interactions align with ATLAS data extraction and exfiltration risk context.

Cato Networks · Cato AI Security (AISEC)Inferred alignmenthigh confidence · 1 source

Cato AI Security applies inline controls to block sensitive data exfiltration to unauthorized AI services and channels.

Data exfiltration prevention controls align with ATLAS data extraction and exfiltration technique context.

Google Cloud · Model ArmorInferred alignmenthigh confidence · 1 source

Model Armor can inspect, transform, tokenize, and redact sensitive elements in AI prompts and responses through Sensitive Data Protection integration.

AuditaAI assessment: transforming and redacting sensitive prompt and response content addresses the ATLAS data-leakage technique context.

Microsoft · Microsoft Purview for AIInferred alignmentmedium confidence · 1 source

Microsoft Purview for AI applies DLP and sensitivity controls to reduce unauthorized sensitive data transfer in AI interactions.

Purview controls over data transfer and leakage context align to data extraction and exfiltration risk patterns.

NEO · Neo Security PlatformInferred alignmentmedium confidence · 1 source

Neo Security Platform analyzes security gaps across agentic and non-agentic software to surface exposure conditions that require remediation.

Security gap analysis for exposure conditions can contribute to identifying data leakage and extraction risk patterns.

Nightfall AI · AI Application DLPInferred alignmenthigh confidence · 1 source

AI Application DLP applies pre-submission filtering and policy controls to block sensitive prompt, upload, and clipboard data before transfer to AI providers.

Blocking sensitive data before AI submission aligns with data extraction and exfiltration risk mitigation context.

Palo Alto Networks · AI Access SecurityInferred alignmenthigh confidence · 1 source

AI Access Security classifies sensitive content inline and blocks sensitive text and file transfers to GenAI applications.

AuditaAI assessment: blocking sensitive text and file transfers to GenAI applications addresses ATLAS data-leakage context.

Portkey · PortkeyInferred alignmenthigh confidence · 1 source

Portkey automatically redacts sensitive data from requests before sending them to an LLM.

AuditaAI assessment: redacting sensitive data before LLM requests addresses ATLAS data-leakage context.

Zscaler · Zscaler Data SecurityInferred alignmenthigh confidence · 1 source

Zscaler Data Security inspects AI usage and prompts and can block risky access or enforce prompt DLP to prevent data loss.

AuditaAI assessment: prompt DLP enforcement addresses the ATLAS data-leakage technique context.

AML.T0057

LLM Agent Hijack

Exploiting overly permissive autonomous agents to take unauthorized actions.

18 reviewed alignments
Reviewed offering assessments+
Cranium AI, Inc. · Cranium AI Security and Governance PlatformInferred alignmenthigh confidence · 2 sources

Cranium AI platform is positioned with runtime policy controls to govern unsafe autonomous agent behavior and over-permissioned execution paths.

Preventing unsafe autonomous action paths aligns with ATLAS agent-hijack technique context.

Tenable Holdings, Inc. · Tenable One AI ExposureInferred alignmentmedium confidence · 2 sources

Tenable One AI Exposure surfaces identity and entitlement risk for AI workloads, including over-permissioned access paths that can increase autonomous abuse risk.

Over-permissioned identity access paths in AI workloads align with ATLAS agent-hijack risk context.

Amazon Web Services · AWS AI Security Framework and Security Hub AI-SPMInferred alignmentmedium confidence · 2 sources

AWS posture and governance workflows help identify control gaps around autonomous and agentic execution paths for prioritized remediation.

Identifying autonomous execution control gaps aligns with ATLAS agent-hijack risk context.

F5, Inc. · F5 AI GuardrailsInferred alignmenthigh confidence · 2 sources

F5 AI Guardrails applies agent-focused runtime controls to constrain unsafe autonomous actions and high-risk tool execution paths.

Constraining unsafe autonomous tool execution aligns with ATLAS agent-hijack risk context.

Cato Networks · Cato AI Security (AISEC)Inferred alignmenthigh confidence · 2 sources

Cato AI Security governance controls constrain unsafe autonomous actions and high-risk tool usage for AI agents and applications.

Constraining unsafe autonomous actions aligns with ATLAS agent-hijack technique context.

Check Point Software Technologies · AI Agent SecurityInferred alignmenthigh confidence · 1 source

AI Agent Security governs which tools and MCP servers agents can use, and evaluates agent actions in context to help block unsafe or unauthorized behavior at runtime.

Monitoring and restricting unsafe autonomous actions and tool calls aligns with agent-hijack technique context.

Glow · Glow AI-Powered Endpoint Security PlatformInferred alignmenthigh confidence · 1 source

Glow autonomous endpoint enforcement can block unsafe agentic tool execution and unauthorized actions initiated from user devices.

Blocking unsafe autonomous tool execution aligns with ATLAS agent-hijack risk context.

HiddenLayer · AI Runtime SecurityInferred alignmentmedium confidence · 1 source

AI Runtime Security can detect, block, or redact unsafe actions and sensitive information according to policy and platform capabilities.

Inline controls for unsafe agent actions and malicious tool use align to agent-hijack technique context.

HiddenLayer · Agentic and MCP SecurityInferred alignmentmedium confidence · 1 source

HiddenLayer presents Agentic and MCP Security as a use case for protecting autonomous agents and MCP-based systems from prompt injection, unsafe tool use, and harmful autonomous actions.

Protection from unsafe autonomous actions aligns to the ATLAS agent-hijack technique context.

Lasso Security · Runtime Enforcement and AI Detection and ResponseInferred alignmenthigh confidence · 2 sources

Lasso runtime enforcement can block prompt-injection attempts and prevent unsafe autonomous agent actions or unauthorized tool invocation.

Preventing unsafe autonomous actions and tool invocation aligns with ATLAS agent-hijack risk context.

Mindgard · AI Runtime Threat Detection and ResponseInferred alignmenthigh confidence · 1 source

Runtime response workflows support containment and remediation for unsafe agent behavior and unauthorized action chains.

Containment and remediation of unsafe agent actions align with ATLAS agent-hijack risk context.

Microsoft · Microsoft Defender for Cloud (AI-SPM)Inferred alignmentmedium confidence · 1 source

Defender for Cloud AI posture capabilities provide risk prioritization signals to focus remediation for high-impact AI exposure paths.

Posture analysis for over-permissioned or unsafe autonomous execution paths aligns with ATLAS agent-hijack risk context.

NEO · Neo Security PlatformInferred alignmenthigh confidence · 1 source

Neo Security Platform is positioned to prevent agentic threats by controlling unsafe runtime action paths and over-permissioned execution conditions.

Prevention of unsafe autonomous action chains aligns with ATLAS agent-hijack technique context.

Nightfall AI · AI Agent SecurityInferred alignmenthigh confidence · 1 source

AI Agent Security uses hook-level interception and tool-call governance to constrain unsafe autonomous actions before execution.

Constraining unsafe autonomous tool execution aligns with ATLAS agent-hijack risk mitigation context.

Palo Alto Networks · Prisma AIRSInferred alignmenthigh confidence · 1 source

Prisma AIRS verifies agent identity and enforces real-time security controls for agent actions.

AuditaAI assessment: verifying agent identity and controlling actions addresses the ATLAS agent-hijack technique context.

Koi Security · Koi Agentic Endpoint SecurityInferred alignmentmedium confidence · 1 source

Koi AES enforces endpoint guardrails that approve, flag, or block autonomous tools.

AuditaAI assessment: approving, flagging, and blocking autonomous tools supports the ATLAS agent-hijack context.

Prompt Security · Prompt SecurityInferred alignmenthigh confidence · 2 sources

Prompt Security agent-focused governance restricts risky autonomous tool use and unsafe execution decisions.

Restricting risky autonomous tool decisions aligns with ATLAS agent-hijack risk context.

Zenity · Runtime Boundaries and AIDRInferred alignmenthigh confidence · 2 sources

Zenity runtime boundaries can block unsafe agent actions, including risky tool usage and unauthorized task execution.

Runtime controls over risky tool and task execution align with ATLAS agent-hijack risk context.