Skip to content
MoorAI
// MoorAI · Frameworks · MITRE ATLAS

ATLAS agentic-technique coverage, vendor by vendor

What 43 AI-security vendors document in their own published material against the 76 MITRE ATLAS 2026.09 techniques tagged Agentic AI. 27 are documented by none of them and by no MoorAI rule. 10 of those are defence-side techniques, not adversary preparation. Every credit carries the URL of the vendor page it came from and a verbatim quote, and MoorAI is scored the same way. The capability-by-capability table for the same vendors is on MoorAI vs the field →

Itay Glick Published September 21, 2026 Corrected September 26, 2026 Updated September 26, 2026 Expanded September 27, 2026 Expanded October 1, 2026 Expanded again October 1, 2026 Every change to this study

The scored set, and what came back
76 techniques MITRE tags Agentic AI
43 vendors read
27 techniques no product here documents
10 of those are defence-side, not preparation

MITRE's ATLAS 2026.09 release tags 76 top-level techniques with the platform Agentic AI. That list — MITRE's tag, applied mechanically, not our own selection — is read here against what 43 AI-security vendors have published. Every credit rests on the vendor's own page and a sentence quoted from it verbatim.

The interesting result is not the ranking. It is the shape of the map: a handful of techniques draw most vendors, nine are claimed by exactly one vendor each, and 27 of the 76 are claimed by no product we read.

MITRE ATLAS agentic techniques, who documents what

One row per technique, most-documented at the top; one block per vendor along the row, so its length counts the 43 vendors. MoorAI has its own column at the left of the rows. Hover a block for the technique and the product.

Coverage collapses fast: 49 of the 76 techniques have any at all, and most of those rest on one or two products.

A dashed block is coverage documented with a limit the product states itself (220 of 548). An empty cell in the green column means MoorAI covers nothing there — 18 of 49. The same data as text is the evidence table below.

Which products document which MITRE ATLAS agentic technique One row for each of the 49 MITRE ATLAS 2026.09 agentic techniques that at least one of 44 products documents, ordered by how many products document it, most at the top. Each row carries the technique's id and name, then a MoorAI column, filled green where MoorAI's rule base maps the technique and left empty where it does not, then one coloured block per vendor documenting it, so the length of a row counts vendors. AI Agent Tool Invocation leads, documented by 36 of the 43 vendors and by MoorAI, and coverage falls away steeply. Blocks drawn hollow with a dashed outline are coverage the product documents with a limit it states itself, 220 of 548 blocks. The 27 techniques no product documents have no row. The evidence table on this page gives the same data as text. solid = documented (328) dashed = documented, with a stated limit (220 of 548 blocks) Above Security Airia Akto Aurascape Backslash Security Bifrost Edge BigID Certiv Cranium Cycode CyCraft DeepKeep dope.security Endor Labs Enkrypt AI Ent (0) Forcepoint Harmonic Security HiddenLayer Holistic AI Kitecyber Lakera Lasso Security Levo.ai MIND MoorAI Netskope NeuralTrust Noma Security Onyx Security Operant AI Permiso Pillar Security PointGuard AI Rig Security Salt Security SentinelOne Singulr AI Straiker Trustwise Vijil Virtue AI WitnessAI Zenity ATLAS 2026.09 TECHNIQUE MoorAI VENDORS DOCUMENTING IT, ONE BLOCK EACH (OF 43) 0 0 5 5 10 10 15 15 20 20 25 25 30 30 35 35 40 40 AML.T0053 AI Agent Tool Invocation AML.T0053 AI Agent Tool Invocation — MoorAI AML.T0053 AI Agent Tool Invocation — Airia (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — Akto AML.T0053 AI Agent Tool Invocation — Aurascape (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — Backslash Security AML.T0053 AI Agent Tool Invocation — Bifrost Edge (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — BigID (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — Certiv AML.T0053 AI Agent Tool Invocation — Cycode (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — CyCraft (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — DeepKeep (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — Endor Labs (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — Enkrypt AI AML.T0053 AI Agent Tool Invocation — Forcepoint (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — HiddenLayer AML.T0053 AI Agent Tool Invocation — Holistic AI (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — Lakera (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — Lasso Security AML.T0053 AI Agent Tool Invocation — Levo.ai AML.T0053 AI Agent Tool Invocation — Netskope (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — NeuralTrust AML.T0053 AI Agent Tool Invocation — Noma Security AML.T0053 AI Agent Tool Invocation — Onyx Security AML.T0053 AI Agent Tool Invocation — Operant AI AML.T0053 AI Agent Tool Invocation — Permiso (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — Pillar Security AML.T0053 AI Agent Tool Invocation — PointGuard AI AML.T0053 AI Agent Tool Invocation — Rig Security (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — Salt Security AML.T0053 AI Agent Tool Invocation — SentinelOne (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — Singulr AI AML.T0053 AI Agent Tool Invocation — Straiker (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — Trustwise AML.T0053 AI Agent Tool Invocation — Vijil (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — Virtue AI AML.T0053 AI Agent Tool Invocation — WitnessAI (documented, with a stated limit) AML.T0053 AI Agent Tool Invocation — Zenity 36 AML.T0051 LLM Prompt Injection AML.T0051 LLM Prompt Injection — MoorAI AML.T0051 LLM Prompt Injection — Airia (documented, with a stated limit) AML.T0051 LLM Prompt Injection — Akto AML.T0051 LLM Prompt Injection — Aurascape AML.T0051 LLM Prompt Injection — Backslash Security AML.T0051 LLM Prompt Injection — Bifrost Edge (documented, with a stated limit) AML.T0051 LLM Prompt Injection — BigID AML.T0051 LLM Prompt Injection — Certiv AML.T0051 LLM Prompt Injection — Cranium (documented, with a stated limit) AML.T0051 LLM Prompt Injection — Cycode AML.T0051 LLM Prompt Injection — CyCraft AML.T0051 LLM Prompt Injection — DeepKeep AML.T0051 LLM Prompt Injection — Endor Labs (documented, with a stated limit) AML.T0051 LLM Prompt Injection — Enkrypt AI (documented, with a stated limit) AML.T0051 LLM Prompt Injection — HiddenLayer AML.T0051 LLM Prompt Injection — Holistic AI (documented, with a stated limit) AML.T0051 LLM Prompt Injection — Kitecyber AML.T0051 LLM Prompt Injection — Lakera AML.T0051 LLM Prompt Injection — Lasso Security AML.T0051 LLM Prompt Injection — Levo.ai (documented, with a stated limit) AML.T0051 LLM Prompt Injection — Netskope AML.T0051 LLM Prompt Injection — NeuralTrust AML.T0051 LLM Prompt Injection — Noma Security AML.T0051 LLM Prompt Injection — Onyx Security AML.T0051 LLM Prompt Injection — Operant AI AML.T0051 LLM Prompt Injection — Pillar Security AML.T0051 LLM Prompt Injection — PointGuard AI AML.T0051 LLM Prompt Injection — Salt Security AML.T0051 LLM Prompt Injection — SentinelOne AML.T0051 LLM Prompt Injection — Singulr AI AML.T0051 LLM Prompt Injection — Straiker AML.T0051 LLM Prompt Injection — Trustwise (documented, with a stated limit) AML.T0051 LLM Prompt Injection — Vijil AML.T0051 LLM Prompt Injection — Virtue AI (documented, with a stated limit) AML.T0051 LLM Prompt Injection — WitnessAI AML.T0051 LLM Prompt Injection — Zenity 35 AML.T0057 LLM Data Leakage AML.T0057 LLM Data Leakage — MoorAI AML.T0057 LLM Data Leakage — Airia AML.T0057 LLM Data Leakage — Akto AML.T0057 LLM Data Leakage — Aurascape AML.T0057 LLM Data Leakage — Backslash Security AML.T0057 LLM Data Leakage — Bifrost Edge AML.T0057 LLM Data Leakage — BigID AML.T0057 LLM Data Leakage — Cranium (documented, with a stated limit) AML.T0057 LLM Data Leakage — Cycode (documented, with a stated limit) AML.T0057 LLM Data Leakage — CyCraft (documented, with a stated limit) AML.T0057 LLM Data Leakage — DeepKeep AML.T0057 LLM Data Leakage — Enkrypt AI AML.T0057 LLM Data Leakage — Forcepoint AML.T0057 LLM Data Leakage — HiddenLayer AML.T0057 LLM Data Leakage — Holistic AI AML.T0057 LLM Data Leakage — Lakera AML.T0057 LLM Data Leakage — Lasso Security AML.T0057 LLM Data Leakage — Levo.ai AML.T0057 LLM Data Leakage — MIND AML.T0057 LLM Data Leakage — Netskope AML.T0057 LLM Data Leakage — NeuralTrust AML.T0057 LLM Data Leakage — Noma Security AML.T0057 LLM Data Leakage — Onyx Security AML.T0057 LLM Data Leakage — Operant AI AML.T0057 LLM Data Leakage — Pillar Security AML.T0057 LLM Data Leakage — PointGuard AI AML.T0057 LLM Data Leakage — Salt Security AML.T0057 LLM Data Leakage — SentinelOne AML.T0057 LLM Data Leakage — Straiker AML.T0057 LLM Data Leakage — Trustwise AML.T0057 LLM Data Leakage — Vijil AML.T0057 LLM Data Leakage — Virtue AI (documented, with a stated limit) AML.T0057 LLM Data Leakage — WitnessAI AML.T0057 LLM Data Leakage — Zenity 33 AML.T0086 Exfiltration via AI Agent Tool Invocation AML.T0086 Exfiltration via AI Agent Tool Invocation — MoorAI (documented, with a stated limit) AML.T0086 Exfiltration via AI Agent Tool Invocation — Above Security (documented, with a stated limit) AML.T0086 Exfiltration via AI Agent Tool Invocation — Airia AML.T0086 Exfiltration via AI Agent Tool Invocation — Akto (documented, with a stated limit) AML.T0086 Exfiltration via AI Agent Tool Invocation — Aurascape AML.T0086 Exfiltration via AI Agent Tool Invocation — Backslash Security AML.T0086 Exfiltration via AI Agent Tool Invocation — BigID (documented, with a stated limit) AML.T0086 Exfiltration via AI Agent Tool Invocation — Certiv AML.T0086 Exfiltration via AI Agent Tool Invocation — Cycode (documented, with a stated limit) AML.T0086 Exfiltration via AI Agent Tool Invocation — dope.security (documented, with a stated limit) AML.T0086 Exfiltration via AI Agent Tool Invocation — Endor Labs (documented, with a stated limit) AML.T0086 Exfiltration via AI Agent Tool Invocation — Enkrypt AI AML.T0086 Exfiltration via AI Agent Tool Invocation — Forcepoint AML.T0086 Exfiltration via AI Agent Tool Invocation — Harmonic Security AML.T0086 Exfiltration via AI Agent Tool Invocation — Kitecyber AML.T0086 Exfiltration via AI Agent Tool Invocation — Lakera (documented, with a stated limit) AML.T0086 Exfiltration via AI Agent Tool Invocation — Lasso Security AML.T0086 Exfiltration via AI Agent Tool Invocation — Levo.ai (documented, with a stated limit) AML.T0086 Exfiltration via AI Agent Tool Invocation — MIND (documented, with a stated limit) AML.T0086 Exfiltration via AI Agent Tool Invocation — Netskope AML.T0086 Exfiltration via AI Agent Tool Invocation — NeuralTrust (documented, with a stated limit) AML.T0086 Exfiltration via AI Agent Tool Invocation — Noma Security AML.T0086 Exfiltration via AI Agent Tool Invocation — Onyx Security (documented, with a stated limit) AML.T0086 Exfiltration via AI Agent Tool Invocation — Operant AI (documented, with a stated limit) AML.T0086 Exfiltration via AI Agent Tool Invocation — Pillar Security AML.T0086 Exfiltration via AI Agent Tool Invocation — PointGuard AI AML.T0086 Exfiltration via AI Agent Tool Invocation — Salt Security AML.T0086 Exfiltration via AI Agent Tool Invocation — SentinelOne AML.T0086 Exfiltration via AI Agent Tool Invocation — Straiker AML.T0086 Exfiltration via AI Agent Tool Invocation — WitnessAI AML.T0086 Exfiltration via AI Agent Tool Invocation — Zenity 30 AML.T0054 LLM Jailbreak AML.T0054 LLM Jailbreak — MoorAI AML.T0054 LLM Jailbreak — Airia AML.T0054 LLM Jailbreak — Akto AML.T0054 LLM Jailbreak — Aurascape (documented, with a stated limit) AML.T0054 LLM Jailbreak — Bifrost Edge (documented, with a stated limit) AML.T0054 LLM Jailbreak — Cranium AML.T0054 LLM Jailbreak — CyCraft AML.T0054 LLM Jailbreak — DeepKeep (documented, with a stated limit) AML.T0054 LLM Jailbreak — Enkrypt AI AML.T0054 LLM Jailbreak — HiddenLayer (documented, with a stated limit) AML.T0054 LLM Jailbreak — Holistic AI AML.T0054 LLM Jailbreak — Lakera AML.T0054 LLM Jailbreak — Lasso Security AML.T0054 LLM Jailbreak — Levo.ai AML.T0054 LLM Jailbreak — Netskope AML.T0054 LLM Jailbreak — NeuralTrust (documented, with a stated limit) AML.T0054 LLM Jailbreak — Noma Security (documented, with a stated limit) AML.T0054 LLM Jailbreak — Onyx Security (documented, with a stated limit) AML.T0054 LLM Jailbreak — Operant AI AML.T0054 LLM Jailbreak — Pillar Security AML.T0054 LLM Jailbreak — PointGuard AI AML.T0054 LLM Jailbreak — Salt Security AML.T0054 LLM Jailbreak — SentinelOne AML.T0054 LLM Jailbreak — Singulr AI AML.T0054 LLM Jailbreak — Straiker AML.T0054 LLM Jailbreak — Trustwise AML.T0054 LLM Jailbreak — Vijil AML.T0054 LLM Jailbreak — Virtue AI AML.T0054 LLM Jailbreak — WitnessAI AML.T0054 LLM Jailbreak — Zenity (documented, with a stated limit) 29 AML.T0110 AI Agent Tool Poisoning AML.T0110 AI Agent Tool Poisoning — MoorAI (documented, with a stated limit) AML.T0110 AI Agent Tool Poisoning — Airia (documented, with a stated limit) AML.T0110 AI Agent Tool Poisoning — Akto AML.T0110 AI Agent Tool Poisoning — Aurascape (documented, with a stated limit) AML.T0110 AI Agent Tool Poisoning — Backslash Security AML.T0110 AI Agent Tool Poisoning — Certiv AML.T0110 AI Agent Tool Poisoning — CyCraft (documented, with a stated limit) AML.T0110 AI Agent Tool Poisoning — Endor Labs (documented, with a stated limit) AML.T0110 AI Agent Tool Poisoning — Enkrypt AI (documented, with a stated limit) AML.T0110 AI Agent Tool Poisoning — Lakera AML.T0110 AI Agent Tool Poisoning — Lasso Security AML.T0110 AI Agent Tool Poisoning — Levo.ai (documented, with a stated limit) AML.T0110 AI Agent Tool Poisoning — NeuralTrust (documented, with a stated limit) AML.T0110 AI Agent Tool Poisoning — Noma Security AML.T0110 AI Agent Tool Poisoning — Operant AI AML.T0110 AI Agent Tool Poisoning — Pillar Security AML.T0110 AI Agent Tool Poisoning — PointGuard AI AML.T0110 AI Agent Tool Poisoning — SentinelOne AML.T0110 AI Agent Tool Poisoning — Straiker AML.T0110 AI Agent Tool Poisoning — Trustwise (documented, with a stated limit) AML.T0110 AI Agent Tool Poisoning — Virtue AI (documented, with a stated limit) AML.T0110 AI Agent Tool Poisoning — WitnessAI (documented, with a stated limit) AML.T0110 AI Agent Tool Poisoning — Zenity 22 AML.T0103 Deploy AI Agent AML.T0103 Deploy AI Agent — Above Security (documented, with a stated limit) AML.T0103 Deploy AI Agent — Airia (documented, with a stated limit) AML.T0103 Deploy AI Agent — Akto (documented, with a stated limit) AML.T0103 Deploy AI Agent — Aurascape (documented, with a stated limit) AML.T0103 Deploy AI Agent — Backslash Security AML.T0103 Deploy AI Agent — Certiv AML.T0103 Deploy AI Agent — Forcepoint (documented, with a stated limit) AML.T0103 Deploy AI Agent — HiddenLayer (documented, with a stated limit) AML.T0103 Deploy AI Agent — Holistic AI (documented, with a stated limit) AML.T0103 Deploy AI Agent — Lasso Security (documented, with a stated limit) AML.T0103 Deploy AI Agent — MIND (documented, with a stated limit) AML.T0103 Deploy AI Agent — Netskope (documented, with a stated limit) AML.T0103 Deploy AI Agent — NeuralTrust (documented, with a stated limit) AML.T0103 Deploy AI Agent — Noma Security (documented, with a stated limit) AML.T0103 Deploy AI Agent — Permiso AML.T0103 Deploy AI Agent — Pillar Security (documented, with a stated limit) AML.T0103 Deploy AI Agent — PointGuard AI (documented, with a stated limit) AML.T0103 Deploy AI Agent — Rig Security (documented, with a stated limit) AML.T0103 Deploy AI Agent — SentinelOne (documented, with a stated limit) AML.T0103 Deploy AI Agent — Straiker (documented, with a stated limit) AML.T0103 Deploy AI Agent — WitnessAI (documented, with a stated limit) 21 AML.T0084 Discover AI Agent Configuration AML.T0084 Discover AI Agent Configuration — Airia (documented, with a stated limit) AML.T0084 Discover AI Agent Configuration — Akto (documented, with a stated limit) AML.T0084 Discover AI Agent Configuration — Bifrost Edge AML.T0084 Discover AI Agent Configuration — BigID AML.T0084 Discover AI Agent Configuration — Cranium (documented, with a stated limit) AML.T0084 Discover AI Agent Configuration — Cycode AML.T0084 Discover AI Agent Configuration — DeepKeep (documented, with a stated limit) AML.T0084 Discover AI Agent Configuration — Endor Labs (documented, with a stated limit) AML.T0084 Discover AI Agent Configuration — Enkrypt AI (documented, with a stated limit) AML.T0084 Discover AI Agent Configuration — Kitecyber (documented, with a stated limit) AML.T0084 Discover AI Agent Configuration — Lakera (documented, with a stated limit) AML.T0084 Discover AI Agent Configuration — Lasso Security (documented, with a stated limit) AML.T0084 Discover AI Agent Configuration — NeuralTrust (documented, with a stated limit) AML.T0084 Discover AI Agent Configuration — Noma Security (documented, with a stated limit) AML.T0084 Discover AI Agent Configuration — Operant AI (documented, with a stated limit) AML.T0084 Discover AI Agent Configuration — Permiso (documented, with a stated limit) AML.T0084 Discover AI Agent Configuration — Pillar Security (documented, with a stated limit) AML.T0084 Discover AI Agent Configuration — SentinelOne (documented, with a stated limit) AML.T0084 Discover AI Agent Configuration — Zenity 19 AML.T0010 AI Supply Chain Compromise AML.T0010 AI Supply Chain Compromise — MoorAI AML.T0010 AI Supply Chain Compromise — Akto (documented, with a stated limit) AML.T0010 AI Supply Chain Compromise — Backslash Security AML.T0010 AI Supply Chain Compromise — Endor Labs AML.T0010 AI Supply Chain Compromise — Enkrypt AI (documented, with a stated limit) AML.T0010 AI Supply Chain Compromise — Lakera AML.T0010 AI Supply Chain Compromise — Lasso Security AML.T0010 AI Supply Chain Compromise — Netskope AML.T0010 AI Supply Chain Compromise — Noma Security (documented, with a stated limit) AML.T0010 AI Supply Chain Compromise — Operant AI AML.T0010 AI Supply Chain Compromise — Pillar Security AML.T0010 AI Supply Chain Compromise — PointGuard AI (documented, with a stated limit) AML.T0010 AI Supply Chain Compromise — SentinelOne (documented, with a stated limit) AML.T0010 AI Supply Chain Compromise — Singulr AI (documented, with a stated limit) AML.T0010 AI Supply Chain Compromise — Straiker AML.T0010 AI Supply Chain Compromise — WitnessAI AML.T0010 AI Supply Chain Compromise — Zenity 16 AML.T0048 External Harms AML.T0048 External Harms — MoorAI AML.T0048 External Harms — Airia AML.T0048 External Harms — Akto (documented, with a stated limit) AML.T0048 External Harms — Aurascape AML.T0048 External Harms — Cranium AML.T0048 External Harms — CyCraft AML.T0048 External Harms — DeepKeep AML.T0048 External Harms — Enkrypt AI AML.T0048 External Harms — Holistic AI AML.T0048 External Harms — Lakera AML.T0048 External Harms — Lasso Security AML.T0048 External Harms — Netskope AML.T0048 External Harms — NeuralTrust AML.T0048 External Harms — Permiso (documented, with a stated limit) AML.T0048 External Harms — Pillar Security AML.T0048 External Harms — Straiker AML.T0048 External Harms — WitnessAI 16 AML.T0133 Discover AI Agent Runtime Capabilities AML.T0133 Discover AI Agent Runtime Capabilities — MoorAI AML.T0133 Discover AI Agent Runtime Capabilities — Akto (documented, with a stated limit) AML.T0133 Discover AI Agent Runtime Capabilities — Aurascape (documented, with a stated limit) AML.T0133 Discover AI Agent Runtime Capabilities — Backslash Security AML.T0133 Discover AI Agent Runtime Capabilities — Endor Labs AML.T0133 Discover AI Agent Runtime Capabilities — Forcepoint AML.T0133 Discover AI Agent Runtime Capabilities — Harmonic Security AML.T0133 Discover AI Agent Runtime Capabilities — Lakera (documented, with a stated limit) AML.T0133 Discover AI Agent Runtime Capabilities — Lasso Security AML.T0133 Discover AI Agent Runtime Capabilities — Netskope AML.T0133 Discover AI Agent Runtime Capabilities — Noma Security (documented, with a stated limit) AML.T0133 Discover AI Agent Runtime Capabilities — Pillar Security (documented, with a stated limit) AML.T0133 Discover AI Agent Runtime Capabilities — Salt Security AML.T0133 Discover AI Agent Runtime Capabilities — SentinelOne AML.T0133 Discover AI Agent Runtime Capabilities — Straiker AML.T0133 Discover AI Agent Runtime Capabilities — WitnessAI AML.T0133 Discover AI Agent Runtime Capabilities — Zenity 16 AML.T0132 Misconfigured or Publicly Exposed AI Services AML.T0132 Misconfigured or Publicly Exposed AI Services — Backslash Security AML.T0132 Misconfigured or Publicly Exposed AI Services — Certiv AML.T0132 Misconfigured or Publicly Exposed AI Services — Cycode AML.T0132 Misconfigured or Publicly Exposed AI Services — Endor Labs (documented, with a stated limit) AML.T0132 Misconfigured or Publicly Exposed AI Services — Lakera (documented, with a stated limit) AML.T0132 Misconfigured or Publicly Exposed AI Services — Lasso Security AML.T0132 Misconfigured or Publicly Exposed AI Services — Netskope AML.T0132 Misconfigured or Publicly Exposed AI Services — NeuralTrust (documented, with a stated limit) AML.T0132 Misconfigured or Publicly Exposed AI Services — Noma Security (documented, with a stated limit) AML.T0132 Misconfigured or Publicly Exposed AI Services — Permiso AML.T0132 Misconfigured or Publicly Exposed AI Services — Pillar Security AML.T0132 Misconfigured or Publicly Exposed AI Services — PointGuard AI (documented, with a stated limit) AML.T0132 Misconfigured or Publicly Exposed AI Services — Salt Security AML.T0132 Misconfigured or Publicly Exposed AI Services — SentinelOne AML.T0132 Misconfigured or Publicly Exposed AI Services — Straiker AML.T0132 Misconfigured or Publicly Exposed AI Services — Zenity 16 AML.T0011 User Execution AML.T0011 User Execution — MoorAI AML.T0011 User Execution — Akto AML.T0011 User Execution — Aurascape AML.T0011 User Execution — Backslash Security AML.T0011 User Execution — Certiv (documented, with a stated limit) AML.T0011 User Execution — Endor Labs AML.T0011 User Execution — Enkrypt AI (documented, with a stated limit) AML.T0011 User Execution — HiddenLayer (documented, with a stated limit) AML.T0011 User Execution — Lakera AML.T0011 User Execution — Lasso Security (documented, with a stated limit) AML.T0011 User Execution — Netskope AML.T0011 User Execution — Operant AI AML.T0011 User Execution — Permiso AML.T0011 User Execution — Pillar Security AML.T0011 User Execution — PointGuard AI AML.T0011 User Execution — Zenity 15 AML.T0101 Data Destruction via AI Agent Tool Invocation AML.T0101 Data Destruction via AI Agent Tool Invocation — MoorAI AML.T0101 Data Destruction via AI Agent Tool Invocation — Akto AML.T0101 Data Destruction via AI Agent Tool Invocation — Aurascape (documented, with a stated limit) AML.T0101 Data Destruction via AI Agent Tool Invocation — Certiv AML.T0101 Data Destruction via AI Agent Tool Invocation — DeepKeep (documented, with a stated limit) AML.T0101 Data Destruction via AI Agent Tool Invocation — Endor Labs (documented, with a stated limit) AML.T0101 Data Destruction via AI Agent Tool Invocation — Forcepoint AML.T0101 Data Destruction via AI Agent Tool Invocation — Holistic AI AML.T0101 Data Destruction via AI Agent Tool Invocation — Netskope AML.T0101 Data Destruction via AI Agent Tool Invocation — NeuralTrust AML.T0101 Data Destruction via AI Agent Tool Invocation — Noma Security AML.T0101 Data Destruction via AI Agent Tool Invocation — Onyx Security (documented, with a stated limit) AML.T0101 Data Destruction via AI Agent Tool Invocation — Operant AI AML.T0101 Data Destruction via AI Agent Tool Invocation — PointGuard AI AML.T0101 Data Destruction via AI Agent Tool Invocation — Straiker AML.T0101 Data Destruction via AI Agent Tool Invocation — Zenity 15 AML.T0083 Credentials from AI Agent Configuration AML.T0083 Credentials from AI Agent Configuration — Akto (documented, with a stated limit) AML.T0083 Credentials from AI Agent Configuration — Backslash Security (documented, with a stated limit) AML.T0083 Credentials from AI Agent Configuration — BigID AML.T0083 Credentials from AI Agent Configuration — Cycode AML.T0083 Credentials from AI Agent Configuration — dope.security (documented, with a stated limit) AML.T0083 Credentials from AI Agent Configuration — Endor Labs (documented, with a stated limit) AML.T0083 Credentials from AI Agent Configuration — Forcepoint AML.T0083 Credentials from AI Agent Configuration — Lakera (documented, with a stated limit) AML.T0083 Credentials from AI Agent Configuration — Noma Security (documented, with a stated limit) AML.T0083 Credentials from AI Agent Configuration — Onyx Security (documented, with a stated limit) AML.T0083 Credentials from AI Agent Configuration — Operant AI (documented, with a stated limit) AML.T0083 Credentials from AI Agent Configuration — Pillar Security (documented, with a stated limit) AML.T0083 Credentials from AI Agent Configuration — PointGuard AI (documented, with a stated limit) AML.T0083 Credentials from AI Agent Configuration — Salt Security (documented, with a stated limit) AML.T0083 Credentials from AI Agent Configuration — Zenity 15 AML.T0098 AI Agent Tool Credential Harvesting AML.T0098 AI Agent Tool Credential Harvesting — MoorAI (documented, with a stated limit) AML.T0098 AI Agent Tool Credential Harvesting — Akto (documented, with a stated limit) AML.T0098 AI Agent Tool Credential Harvesting — Certiv AML.T0098 AI Agent Tool Credential Harvesting — Cycode (documented, with a stated limit) AML.T0098 AI Agent Tool Credential Harvesting — DeepKeep (documented, with a stated limit) AML.T0098 AI Agent Tool Credential Harvesting — Endor Labs (documented, with a stated limit) AML.T0098 AI Agent Tool Credential Harvesting — Enkrypt AI AML.T0098 AI Agent Tool Credential Harvesting — Forcepoint (documented, with a stated limit) AML.T0098 AI Agent Tool Credential Harvesting — Holistic AI AML.T0098 AI Agent Tool Credential Harvesting — Lasso Security (documented, with a stated limit) AML.T0098 AI Agent Tool Credential Harvesting — Netskope (documented, with a stated limit) AML.T0098 AI Agent Tool Credential Harvesting — Noma Security (documented, with a stated limit) AML.T0098 AI Agent Tool Credential Harvesting — Operant AI AML.T0098 AI Agent Tool Credential Harvesting — Pillar Security (documented, with a stated limit) AML.T0098 AI Agent Tool Credential Harvesting — PointGuard AI (documented, with a stated limit) 14 AML.T0056 Extract LLM System Prompt AML.T0056 Extract LLM System Prompt — MoorAI AML.T0056 Extract LLM System Prompt — Airia (documented, with a stated limit) AML.T0056 Extract LLM System Prompt — Akto (documented, with a stated limit) AML.T0056 Extract LLM System Prompt — Cranium AML.T0056 Extract LLM System Prompt — CyCraft AML.T0056 Extract LLM System Prompt — Enkrypt AI AML.T0056 Extract LLM System Prompt — HiddenLayer (documented, with a stated limit) AML.T0056 Extract LLM System Prompt — Lakera AML.T0056 Extract LLM System Prompt — Lasso Security AML.T0056 Extract LLM System Prompt — Levo.ai AML.T0056 Extract LLM System Prompt — Netskope (documented, with a stated limit) AML.T0056 Extract LLM System Prompt — NeuralTrust (documented, with a stated limit) AML.T0056 Extract LLM System Prompt — Pillar Security AML.T0056 Extract LLM System Prompt — Straiker 13 AML.T0068 LLM Prompt Obfuscation AML.T0068 LLM Prompt Obfuscation — MoorAI (documented, with a stated limit) AML.T0068 LLM Prompt Obfuscation — Akto (documented, with a stated limit) AML.T0068 LLM Prompt Obfuscation — Certiv AML.T0068 LLM Prompt Obfuscation — Cranium (documented, with a stated limit) AML.T0068 LLM Prompt Obfuscation — CyCraft AML.T0068 LLM Prompt Obfuscation — HiddenLayer AML.T0068 LLM Prompt Obfuscation — Lakera AML.T0068 LLM Prompt Obfuscation — Lasso Security AML.T0068 LLM Prompt Obfuscation — Levo.ai AML.T0068 LLM Prompt Obfuscation — NeuralTrust (documented, with a stated limit) AML.T0068 LLM Prompt Obfuscation — Noma Security AML.T0068 LLM Prompt Obfuscation — Pillar Security AML.T0068 LLM Prompt Obfuscation — Vijil AML.T0068 LLM Prompt Obfuscation — WitnessAI 13 AML.T0081 Modify AI Agent Configuration AML.T0081 Modify AI Agent Configuration — MoorAI (documented, with a stated limit) AML.T0081 Modify AI Agent Configuration — Akto (documented, with a stated limit) AML.T0081 Modify AI Agent Configuration — Backslash Security AML.T0081 Modify AI Agent Configuration — Cranium (documented, with a stated limit) AML.T0081 Modify AI Agent Configuration — Cycode AML.T0081 Modify AI Agent Configuration — Endor Labs (documented, with a stated limit) AML.T0081 Modify AI Agent Configuration — Enkrypt AI (documented, with a stated limit) AML.T0081 Modify AI Agent Configuration — Noma Security (documented, with a stated limit) AML.T0081 Modify AI Agent Configuration — Operant AI (documented, with a stated limit) AML.T0081 Modify AI Agent Configuration — Pillar Security AML.T0081 Modify AI Agent Configuration — SentinelOne (documented, with a stated limit) AML.T0081 Modify AI Agent Configuration — Straiker AML.T0081 Modify AI Agent Configuration — Virtue AI AML.T0081 Modify AI Agent Configuration — Zenity (documented, with a stated limit) 13 AML.T0099 AI Agent Tool Data Poisoning AML.T0099 AI Agent Tool Data Poisoning — MoorAI (documented, with a stated limit) AML.T0099 AI Agent Tool Data Poisoning — Akto AML.T0099 AI Agent Tool Data Poisoning — Certiv AML.T0099 AI Agent Tool Data Poisoning — Enkrypt AI AML.T0099 AI Agent Tool Data Poisoning — HiddenLayer AML.T0099 AI Agent Tool Data Poisoning — Lakera AML.T0099 AI Agent Tool Data Poisoning — Lasso Security AML.T0099 AI Agent Tool Data Poisoning — NeuralTrust (documented, with a stated limit) AML.T0099 AI Agent Tool Data Poisoning — Noma Security AML.T0099 AI Agent Tool Data Poisoning — Operant AI AML.T0099 AI Agent Tool Data Poisoning — Pillar Security AML.T0099 AI Agent Tool Data Poisoning — PointGuard AI AML.T0099 AI Agent Tool Data Poisoning — Straiker AML.T0099 AI Agent Tool Data Poisoning — Zenity 13 AML.T0034 Cost Harvesting AML.T0034 Cost Harvesting — MoorAI AML.T0034 Cost Harvesting — Airia AML.T0034 Cost Harvesting — Bifrost Edge AML.T0034 Cost Harvesting — Certiv (documented, with a stated limit) AML.T0034 Cost Harvesting — Holistic AI (documented, with a stated limit) AML.T0034 Cost Harvesting — Lasso Security AML.T0034 Cost Harvesting — Levo.ai AML.T0034 Cost Harvesting — Netskope (documented, with a stated limit) AML.T0034 Cost Harvesting — NeuralTrust AML.T0034 Cost Harvesting — Operant AI AML.T0034 Cost Harvesting — PointGuard AI (documented, with a stated limit) AML.T0034 Cost Harvesting — Trustwise (documented, with a stated limit) AML.T0034 Cost Harvesting — WitnessAI (documented, with a stated limit) 12 AML.T0118 Autonomous AI Agent Communication AML.T0118 Autonomous AI Agent Communication — MoorAI (documented, with a stated limit) AML.T0118 Autonomous AI Agent Communication — Enkrypt AI AML.T0118 Autonomous AI Agent Communication — Holistic AI (documented, with a stated limit) AML.T0118 Autonomous AI Agent Communication — Lakera (documented, with a stated limit) AML.T0118 Autonomous AI Agent Communication — Lasso Security AML.T0118 Autonomous AI Agent Communication — NeuralTrust AML.T0118 Autonomous AI Agent Communication — Operant AI (documented, with a stated limit) AML.T0118 Autonomous AI Agent Communication — Permiso (documented, with a stated limit) AML.T0118 Autonomous AI Agent Communication — Pillar Security AML.T0118 Autonomous AI Agent Communication — PointGuard AI AML.T0118 Autonomous AI Agent Communication — Straiker AML.T0118 Autonomous AI Agent Communication — WitnessAI AML.T0118 Autonomous AI Agent Communication — Zenity 12 AML.T0007 Discover AI Artifacts AML.T0007 Discover AI Artifacts — BigID (documented, with a stated limit) AML.T0007 Discover AI Artifacts — Cranium (documented, with a stated limit) AML.T0007 Discover AI Artifacts — Cycode AML.T0007 Discover AI Artifacts — HiddenLayer (documented, with a stated limit) AML.T0007 Discover AI Artifacts — Holistic AI (documented, with a stated limit) AML.T0007 Discover AI Artifacts — Noma Security (documented, with a stated limit) AML.T0007 Discover AI Artifacts — Operant AI (documented, with a stated limit) AML.T0007 Discover AI Artifacts — Permiso (documented, with a stated limit) AML.T0007 Discover AI Artifacts — Pillar Security (documented, with a stated limit) AML.T0007 Discover AI Artifacts — PointGuard AI (documented, with a stated limit) AML.T0007 Discover AI Artifacts — SentinelOne (documented, with a stated limit) AML.T0007 Discover AI Artifacts — Zenity 12 AML.T0085 Data from AI Services AML.T0085 Data from AI Services — BigID AML.T0085 Data from AI Services — Forcepoint AML.T0085 Data from AI Services — Holistic AI AML.T0085 Data from AI Services — Kitecyber (documented, with a stated limit) AML.T0085 Data from AI Services — Lasso Security AML.T0085 Data from AI Services — MIND (documented, with a stated limit) AML.T0085 Data from AI Services — Netskope (documented, with a stated limit) AML.T0085 Data from AI Services — Operant AI AML.T0085 Data from AI Services — Permiso (documented, with a stated limit) AML.T0085 Data from AI Services — Salt Security AML.T0085 Data from AI Services — Zenity 11 AML.T0080 AI Agent Context Poisoning AML.T0080 AI Agent Context Poisoning — MoorAI (documented, with a stated limit) AML.T0080 AI Agent Context Poisoning — Akto AML.T0080 AI Agent Context Poisoning — Certiv AML.T0080 AI Agent Context Poisoning — HiddenLayer AML.T0080 AI Agent Context Poisoning — Lakera (documented, with a stated limit) AML.T0080 AI Agent Context Poisoning — Lasso Security AML.T0080 AI Agent Context Poisoning — Operant AI AML.T0080 AI Agent Context Poisoning — Pillar Security (documented, with a stated limit) AML.T0080 AI Agent Context Poisoning — Salt Security AML.T0080 AI Agent Context Poisoning — Straiker AML.T0080 AI Agent Context Poisoning — Zenity 10 AML.T0109 AI Supply Chain Rug Pull AML.T0109 AI Supply Chain Rug Pull — Airia (documented, with a stated limit) AML.T0109 AI Supply Chain Rug Pull — Backslash Security AML.T0109 AI Supply Chain Rug Pull — Endor Labs (documented, with a stated limit) AML.T0109 AI Supply Chain Rug Pull — Enkrypt AI (documented, with a stated limit) AML.T0109 AI Supply Chain Rug Pull — Noma Security AML.T0109 AI Supply Chain Rug Pull — Operant AI AML.T0109 AI Supply Chain Rug Pull — Pillar Security AML.T0109 AI Supply Chain Rug Pull — Straiker (documented, with a stated limit) AML.T0109 AI Supply Chain Rug Pull — Zenity 9 AML.T0029 Denial of AI Service AML.T0029 Denial of AI Service — Akto (documented, with a stated limit) AML.T0029 Denial of AI Service — Enkrypt AI AML.T0029 Denial of AI Service — HiddenLayer (documented, with a stated limit) AML.T0029 Denial of AI Service — Lasso Security AML.T0029 Denial of AI Service — NeuralTrust AML.T0029 Denial of AI Service — Operant AI AML.T0029 Denial of AI Service — Straiker AML.T0029 Denial of AI Service — Vijil (documented, with a stated limit) 8 AML.T0112 Machine Compromise AML.T0112 Machine Compromise — MoorAI (documented, with a stated limit) AML.T0112 Machine Compromise — Backslash Security AML.T0112 Machine Compromise — Endor Labs AML.T0112 Machine Compromise — Enkrypt AI AML.T0112 Machine Compromise — Operant AI AML.T0112 Machine Compromise — Pillar Security AML.T0112 Machine Compromise — PointGuard AI AML.T0112 Machine Compromise — Straiker 7 AML.T0070 RAG Poisoning AML.T0070 RAG Poisoning — Enkrypt AI AML.T0070 RAG Poisoning — Lakera AML.T0070 RAG Poisoning — Lasso Security AML.T0070 RAG Poisoning — Levo.ai (documented, with a stated limit) AML.T0070 RAG Poisoning — Pillar Security AML.T0070 RAG Poisoning — SentinelOne AML.T0070 RAG Poisoning — Zenity 7 AML.T0018 Manipulate AI Model AML.T0018 Manipulate AI Model — DeepKeep AML.T0018 Manipulate AI Model — Endor Labs AML.T0018 Manipulate AI Model — HiddenLayer AML.T0018 Manipulate AI Model — NeuralTrust AML.T0018 Manipulate AI Model — Noma Security AML.T0018 Manipulate AI Model — PointGuard AI 6 AML.T0129 Triggers in Multimodal Inputs AML.T0129 Triggers in Multimodal Inputs — MoorAI (documented, with a stated limit) AML.T0129 Triggers in Multimodal Inputs — Enkrypt AI (documented, with a stated limit) AML.T0129 Triggers in Multimodal Inputs — NeuralTrust AML.T0129 Triggers in Multimodal Inputs — Straiker AML.T0129 Triggers in Multimodal Inputs — WitnessAI (documented, with a stated limit) 4 AML.T0020 Training Data Poisoning AML.T0020 Training Data Poisoning — MoorAI AML.T0020 Training Data Poisoning — Netskope (documented, with a stated limit) AML.T0020 Training Data Poisoning — Salt Security (documented, with a stated limit) AML.T0020 Training Data Poisoning — SentinelOne 3 AML.T0077 LLM Response Rendering AML.T0077 LLM Response Rendering — MoorAI (documented, with a stated limit) AML.T0077 LLM Response Rendering — Bifrost Edge AML.T0077 LLM Response Rendering — HiddenLayer (documented, with a stated limit) AML.T0077 LLM Response Rendering — Zenity 3 AML.T0024 Exfiltration via AI Inference API AML.T0024 Exfiltration via AI Inference API — MoorAI AML.T0024 Exfiltration via AI Inference API — Levo.ai (documented, with a stated limit) AML.T0024 Exfiltration via AI Inference API — Operant AI 2 AML.T0093 Prompt Infiltration via Public-Facing Application AML.T0093 Prompt Infiltration via Public-Facing Application — Certiv AML.T0093 Prompt Infiltration via Public-Facing Application — Pillar Security (documented, with a stated limit) 2 AML.T0060 Publish Hallucinated Entities AML.T0060 Publish Hallucinated Entities — MoorAI (documented, with a stated limit) AML.T0060 Publish Hallucinated Entities — Endor Labs 1 AML.T0061 LLM Prompt Self-Replication AML.T0061 LLM Prompt Self-Replication — MoorAI AML.T0061 LLM Prompt Self-Replication — Cranium (documented, with a stated limit) 1 AML.T0006 Active Scanning AML.T0006 Active Scanning — Salt Security 1 AML.T0040 AI Model Inference API Access AML.T0040 AI Model Inference API Access — Harmonic Security (documented, with a stated limit) 1 AML.T0062 Discover LLM Hallucinations AML.T0062 Discover LLM Hallucinations — Lakera (documented, with a stated limit) 1 AML.T0082 RAG Credential Harvesting AML.T0082 RAG Credential Harvesting — Lakera (documented, with a stated limit) 1 AML.T0100 AI Agent Clickbait AML.T0100 AI Agent Clickbait — Straiker 1 AML.T0108 AI Agent AML.T0108 AI Agent — Zenity (documented, with a stated limit) 1 AML.T0115 Publish Poisoned AI Artifacts AML.T0115 Publish Poisoned AI Artifacts — Endor Labs 1 AML.T0035 AI Artifact Collection AML.T0035 AI Artifact Collection — MoorAI (documented, with a stated limit) 0 AML.T0067 LLM Trusted Output Components Manipulation AML.T0067 LLM Trusted Output Components Manipulation — MoorAI (documented, with a stated limit) 0 AML.T0092 Manipulate User LLM Chat History AML.T0092 Manipulate User LLM Chat History — MoorAI (documented, with a stated limit) 0 AML.T0131 Crafted AI Assistant Links AML.T0131 Crafted AI Assistant Links — MoorAI 0 AML.T0134 AI Targeted Cloaking AML.T0134 AI Targeted Cloaking — MoorAI (documented, with a stated limit) 0 MITRE ATLAS 2026.09 · platform tag “Agentic AI” · every credit with a source URL and a verbatim quote · 19 vendors read 20 Sep 2026, 4 added 27 Sep, 2 added 1 Oct, then 18; 4 cells added 26 Sep MoorAI: rule base of agent v1.1.0, released 1 Oct 2026; its ATLAS mapping is unchanged since v0.96.0, 26 Sep 2026

No row at all — 27 techniques no product here documents

None of the 43 vendors reviewed documents these, and MoorAI's rule base carries none of their ids. 10 are defence-side techniques. 6 sit in Discovery or AI Model Access; ATLAS calls Discovery post-compromise and neither tactic preparation, so they are listed apart rather than set aside. 11 are adversary preparation, by ATLAS's own definitions of Reconnaissance, Resource Development and AI Attack Adaptation.

10 defence-side

6 Discovery or AI Model Access

11 adversary preparation

* Described in MoorAI's published prose, which the prose review credits, though no shipped rule carries the id: AML.T0094, AML.T0117.

Where everyone is standing

The most-documented techniques are the ones with obvious product shape — something leaves, something gets injected, a tool gets called. Twenty-five are documented by ten or more of the 43 vendors.

TechniqueVendors documenting it
AML.T0053 AI Agent Tool Invocation36 / 43
AML.T0051 LLM Prompt Injection35 / 43
AML.T0057 LLM Data Leakage33 / 43
AML.T0086 Exfiltration via AI Agent Tool Invocation30 / 43
AML.T0054 LLM Jailbreak29 / 43
AML.T0110 AI Agent Tool Poisoning22 / 43
AML.T0103 Deploy AI Agent21 / 43
AML.T0084 Discover AI Agent Configuration19 / 43
AML.T0010 AI Supply Chain Compromise16 / 43
AML.T0048 External Harms16 / 43
AML.T0132 Misconfigured or Publicly Exposed AI Services16 / 43
AML.T0133 Discover AI Agent Runtime Capabilities16 / 43
AML.T0011 User Execution15 / 43
AML.T0083 Credentials from AI Agent Configuration15 / 43
AML.T0101 Data Destruction via AI Agent Tool Invocation15 / 43
AML.T0098 AI Agent Tool Credential Harvesting14 / 43
AML.T0056 Extract LLM System Prompt13 / 43
AML.T0068 LLM Prompt Obfuscation13 / 43
AML.T0081 Modify AI Agent Configuration13 / 43
AML.T0099 AI Agent Tool Data Poisoning13 / 43
AML.T0007 Discover AI Artifacts12 / 43
AML.T0034 Cost Harvesting12 / 43
AML.T0118 Autonomous AI Agent Communication12 / 43
AML.T0085 Data from AI Services11 / 43
AML.T0080 AI Agent Context Poisoning10 / 43

Coverage is less concentrated than the top of that table suggests. The four most-documented techniques hold 134 of the 517 vendor credits, 26%, and it takes the eleven most-documented to account for half. The other half is spread across the remaining 33 techniques that any vendor documents.

Counts in this table are out of the 43 vendors, and so is the length of every row in the chart above. MoorAI has its own column at the left of those rows — filled where our rule base maps the technique, left deliberately empty where it does not, so the column reads as a floor with holes in it rather than quietly closing up. There are 18 holes in it. If you are buying, the top of this table is the part of the market where you have genuine choice and can compare on quality rather than existence.

Coverage by product

The same 548 credits, read the other way: one row per product instead of one row per technique. No vendor documents more than 26 of the 76 techniques, 34% of the set. The median vendor documents 11, and 18 of the 43 document fewer than ten. The scale is the whole 76, not the leader, so the empty length to the right of every bar is the part of the framework where we found nothing published for that product.

MoorAI's row is counted from its rule base, as its column is in the chart above, not by the prose method the vendor rows use. It is not like-for-like with the rows around it; the note under the table gives the figures the prose method produces.

Techniques documented, per product, of 76

documenteddocumented, with a limit the product states itself

MITRE ATLAS agentic techniques documented per product, of 76 One horizontal bar per product, 44 products, longest first, on a scale of all 76 techniques. Solid is documented coverage; hollow with a dashed outline is coverage documented with a limit the product states itself. Pillar Security documents the most of the 43 vendors, 26; the median vendor documents 11; Ent documents none. MoorAI's row, 31 with 16 bounded, is counted from its rule base and is drawn in green on a tinted row. 0 20 40 60 76 MoorAI MoorAI: 31 of 76 documented, 16 with a stated limit MoorAI: 31 of 76 documented, 16 with a stated limit 31 Pillar Security Pillar Security: 26 of 76 documented, 8 with a stated limit Pillar Security: 26 of 76 documented, 8 with a stated limit 26 Zenity Zenity: 23 of 76 documented, 3 with a stated limit Zenity: 23 of 76 documented, 3 with a stated limit 23 Lasso Security Lasso Security: 23 of 76 documented, 4 with a stated limit Lasso Security: 23 of 76 documented, 4 with a stated limit 23 Operant AI Operant AI: 23 of 76 documented, 6 with a stated limit Operant AI: 23 of 76 documented, 6 with a stated limit 23 Straiker Straiker: 22 of 76 documented, 3 with a stated limit Straiker: 22 of 76 documented, 3 with a stated limit 22 Lakera Lakera: 21 of 76 documented, 10 with a stated limit Lakera: 21 of 76 documented, 10 with a stated limit 21 Akto Akto: 21 of 76 documented, 12 with a stated limit Akto: 21 of 76 documented, 12 with a stated limit 21 Enkrypt AI Enkrypt AI: 20 of 76 documented, 8 with a stated limit Enkrypt AI: 20 of 76 documented, 8 with a stated limit 20 Noma Security Noma Security: 20 of 76 documented, 10 with a stated limit Noma Security: 20 of 76 documented, 10 with a stated limit 20 PointGuard AI PointGuard AI: 19 of 76 documented, 7 with a stated limit PointGuard AI: 19 of 76 documented, 7 with a stated limit 19 NeuralTrust NeuralTrust: 19 of 76 documented, 9 with a stated limit NeuralTrust: 19 of 76 documented, 9 with a stated limit 19 Endor Labs Endor Labs: 18 of 76 documented, 11 with a stated limit Endor Labs: 18 of 76 documented, 11 with a stated limit 18 Netskope Netskope: 17 of 76 documented, 7 with a stated limit Netskope: 17 of 76 documented, 7 with a stated limit 17 SentinelOne SentinelOne: 15 of 76 documented, 6 with a stated limit SentinelOne: 15 of 76 documented, 6 with a stated limit 15 Backslash Security Backslash Security: 14 of 76 documented, 1 with a stated limit Backslash Security: 14 of 76 documented, 1 with a stated limit 14 Certiv Certiv: 14 of 76 documented, 2 with a stated limit Certiv: 14 of 76 documented, 2 with a stated limit 14 WitnessAI WitnessAI: 14 of 76 documented, 5 with a stated limit WitnessAI: 14 of 76 documented, 5 with a stated limit 14 HiddenLayer HiddenLayer: 14 of 76 documented, 7 with a stated limit HiddenLayer: 14 of 76 documented, 7 with a stated limit 14 Salt Security Salt Security: 12 of 76 documented, 2 with a stated limit Salt Security: 12 of 76 documented, 2 with a stated limit 12 Holistic AI Holistic AI: 12 of 76 documented, 6 with a stated limit Holistic AI: 12 of 76 documented, 6 with a stated limit 12 Airia Airia: 12 of 76 documented, 7 with a stated limit Airia: 12 of 76 documented, 7 with a stated limit 12 Levo.ai Levo.ai: 11 of 76 documented, 5 with a stated limit Levo.ai: 11 of 76 documented, 5 with a stated limit 11 Aurascape Aurascape: 11 of 76 documented, 6 with a stated limit Aurascape: 11 of 76 documented, 6 with a stated limit 11 Cycode Cycode: 10 of 76 documented, 4 with a stated limit Cycode: 10 of 76 documented, 4 with a stated limit 10 Cranium Cranium: 10 of 76 documented, 7 with a stated limit Cranium: 10 of 76 documented, 7 with a stated limit 10 Forcepoint Forcepoint: 9 of 76 documented, 3 with a stated limit Forcepoint: 9 of 76 documented, 3 with a stated limit 9 DeepKeep DeepKeep: 9 of 76 documented, 5 with a stated limit DeepKeep: 9 of 76 documented, 5 with a stated limit 9 Permiso Permiso: 9 of 76 documented, 6 with a stated limit Permiso: 9 of 76 documented, 6 with a stated limit 9 BigID BigID: 8 of 76 documented, 3 with a stated limit BigID: 8 of 76 documented, 3 with a stated limit 8 CyCraft CyCraft: 8 of 76 documented, 3 with a stated limit CyCraft: 8 of 76 documented, 3 with a stated limit 8 Bifrost Edge Bifrost Edge: 7 of 76 documented, 3 with a stated limit Bifrost Edge: 7 of 76 documented, 3 with a stated limit 7 Onyx Security Onyx Security: 7 of 76 documented, 4 with a stated limit Onyx Security: 7 of 76 documented, 4 with a stated limit 7 Vijil Vijil: 6 of 76 documented, 2 with a stated limit Vijil: 6 of 76 documented, 2 with a stated limit 6 Trustwise Trustwise: 6 of 76 documented, 3 with a stated limit Trustwise: 6 of 76 documented, 3 with a stated limit 6 Virtue AI Virtue AI: 6 of 76 documented, 3 with a stated limit Virtue AI: 6 of 76 documented, 3 with a stated limit 6 Singulr AI Singulr AI: 4 of 76 documented, 1 with a stated limit Singulr AI: 4 of 76 documented, 1 with a stated limit 4 Kitecyber Kitecyber: 4 of 76 documented, 2 with a stated limit Kitecyber: 4 of 76 documented, 2 with a stated limit 4 MIND MIND: 4 of 76 documented, 3 with a stated limit MIND: 4 of 76 documented, 3 with a stated limit 4 Harmonic Security Harmonic Security: 3 of 76 documented, 1 with a stated limit Harmonic Security: 3 of 76 documented, 1 with a stated limit 3 Above Security Above Security: 2 of 76 documented, 2 with a stated limit 2 dope.security dope.security: 2 of 76 documented, 2 with a stated limit 2 Rig Security Rig Security: 2 of 76 documented, 2 with a stated limit 2 Ent 0
MITRE ATLAS 2026.09 agentic techniques documented per product, of 76, longest first
ProductDocumented (of 76)Of which boundedNo other vendor documentsShare of the 76
MoorAI*rule base31165T0131 T0067 T0092 T0134 T003541%
Pillar Securityadded 27 Sep268034%
Zenity2331T010830%
Lasso Securityadded 27 Sep234030%
Operant AI236030%
Straiker2231T010029%
Lakera‡partial review21102T0062 T008228%
Aktoadded 1 Oct2112028%
Enkrypt AIadded 1 Oct208026%
Noma Securityadded 1 Oct2010026%
PointGuard AIadded 1 Oct197025%
NeuralTrustadded 1 Oct199025%
Endor Labs18112T0060† T011524%
Netskope177022%
SentinelOne‡partial review156020%
Backslash Security141018%
Certiv142018%
WitnessAIadded 27 Sep145018%
HiddenLayeradded 1 Oct147018%
Salt Security1221T000616%
Holistic AIadded 1 Oct126016%
Airiaadded 1 Oct127016%
Levo.aiadded 1 Oct115014%
Aurascapeadded 1 Oct116014%
Cycode104013%
Craniumadded 1 Oct1071T0061†13%
Forcepoint93012%
DeepKeepadded 1 Oct95012%
Permisoadded 27 Sep96012%
BigID83011%
CyCraftadded 1 Oct83011%
Bifrost Edge7309%
Onyx Securityadded 1 Oct7409%
Vijiladded 1 Oct6208%
Trustwiseadded 1 Oct6308%
Virtue AIadded 1 Oct6308%
Singulr AIadded 1 Oct4105%
Kitecyber4205%
MIND4305%
Harmonic Security311T00404%
Above Securityadded 1 Oct2203%
dope.security2203%
Rig Securityadded 1 Oct2203%
Ent0000%

* MoorAI's 31 (16 bounded) come from its rule base: a technique counts when a shipped rule carries its ATLAS id. Scored the way the vendors are, from published prose only, MoorAI documents 31; with every credit traceable to the one README bullet that names ATLAS ids removed, 26. The rule base is MoorAI agent v1.1.0’s, released on 1 October 2026. Its ATLAS mapping is unchanged since agent v0.96.0, released on 26 September, after the original vendor read of 20 September and before the four vendors added on 27 September and the twenty vendors added on 1 October were read; the rules v0.96.0 added are listed in the 26 September update. The method is in We ran the method against ourselves. Its “no other vendor” count is the techniques none of the 43 vendors documents.

† Also documented by MoorAI. That column counts the 43 vendors only, as the single-vendor table below does: 9 techniques, 2 of which MoorAI's rule base also holds.

Marked added 27 Sep: Lasso Security, Permiso, Pillar Security and WitnessAI, read on 27 September and added to the study after the original read of 20 September. They were read by the same method; the expansion notes say what changed.

Marked added 1 Oct: Above Security, Airia, Akto, Aurascape, Cranium, CyCraft, DeepKeep, Enkrypt AI, HiddenLayer, Holistic AI, Levo.ai, NeuralTrust, Noma Security, Onyx Security, PointGuard AI, Rig Security, Singulr AI, Trustwise, Vijil and Virtue AI, read on 1 October and added to the study after the original read of 20 September. They were read by the same method; the expansion notes say what changed.

‡ Partial review: this vendor's material had a shallower read than the others, so its count is a floor rather than a comparable figure. The reason is recorded with its sources.

Two in five published credits come with a limit attached

Counting cells hides something. Of the 548 credits in this review, 220 are what the data calls bounded — coverage the product documents together with a limit it states itself. In the chart those blocks are drawn hollow and dashed. Treating them as equal to a flat claim would overstate two fifths of the market.

The qualification is uneven, and it does not simply follow the crowd:

TechniqueBlocksOf which boundedShare bounded
AML.T0053 AI Agent Tool Invocation371849%
AML.T0051 LLM Prompt Injection36925%
AML.T0057 LLM Data Leakage34412%
AML.T0086 Exfiltration via AI Agent Tool Invocation311342%
AML.T0054 LLM Jailbreak30827%
AML.T0110 AI Agent Tool Poisoning231148%
AML.T0103 Deploy AI Agent211886%
AML.T0084 Discover AI Agent Configuration191579%
AML.T0010 AI Supply Chain Compromise17635%
AML.T0133 Discover AI Agent Runtime Capabilities17529%
AML.T0048 External Harms17212%
AML.T0132 Misconfigured or Publicly Exposed AI Services16531%
AML.T0011 User Execution16425%
AML.T0101 Data Destruction via AI Agent Tool Invocation16425%
AML.T0083 Credentials from AI Agent Configuration151173%
AML.T0098 AI Agent Tool Credential Harvesting151173%
AML.T0081 Modify AI Agent Configuration14964%
AML.T0056 Extract LLM System Prompt14536%
AML.T0068 LLM Prompt Obfuscation14429%
AML.T0099 AI Agent Tool Data Poisoning14214%
AML.T0034 Cost Harvesting13646%
AML.T0118 Autonomous AI Agent Communication13538%
AML.T0007 Discover AI Artifacts121083%
AML.T0085 Data from AI Services11436%
AML.T0080 AI Agent Context Poisoning11327%

Tool invocation ties with deploying an agent for the most bounded claims — eighteen of its thirty-seven arrive with a stated limit, and eighteen of deploying an agent’s twenty-one. Tool invocation is the cell most likely to be read as solved and least likely to be. But crowding is not the pattern: prompt injection and data leakage are nearly all flat claims. The highest shares sit on techniques about an agent’s configuration and credentials — deploying an agent, harvesting tool credentials, modifying agent configuration, credentials in agent configuration, discovering agent configuration — and on discovering AI artifacts, where vendors often say themselves that they find things rather than stop them.

By product, the share varies enormously: dope.security 2 of 2, MIND 3 of 4, Permiso 6 of 9, Endor Labs 11 of 18, Lakera 10 of 21, MoorAI 16 of 31. Read a high proportion as candour, not weakness. A bounded cell exists because a vendor wrote down where its coverage stops; a vendor that never qualifies anything is not necessarily covering more ground, it may simply be writing less carefully. Every product here has at least one bounded cell except Ent, which has no cells at all.

Why nobody can count their agents

Four techniques on the map are the same job from different angles: AML.T0132 exposed AI services (16 of 43), AML.T0084 discover agent configuration (19), AML.T0103 deploy AI agent (21) and AML.T0007 discover AI artifacts (12). Inventory, posture and discovery — knowing what exists before defending it.

Even the best-covered of those has only about half the vendors here publishing on it.

The underlying difficulty is that some products count agents, some map their permissions, some watch what they actually do, and buyers assume one implies the others. ATLAS agrees — it keeps those as separate techniques, and AML.T0133 is defined as learning an agent’s capabilities without access to its configuration, which is exactly what makes it a different technique from AML.T0084. Three rows in this chart, not one.

The 27 no product here documents

27 of the 76 techniques are documented by none of the 43 vendors, and no MoorAI rule carries their ids. Counting vendors alone it is 32, because five techniques are held by MoorAI’s rule base and no one else: AML.T0131 Crafted AI Assistant Links and AML.T0134 AI Targeted Cloaking, and three whose rules shipped in agent v0.96.0 after this study and because of it, AML.T0092, AML.T0067 and AML.T0035 (see the update). A fourth rule from that release, for AML.T0061 LLM Prompt Self-Replication, has company: Cranium, added on 1 October, documents a static check for it in agent configuration files. The chart lists all 27 by id and name under “No row at all”.

“Nobody” needs two qualifications. It means nobody in this sample. Forty-three vendors plus MoorAI is not the market, and products outside it publish material on some of these techniques: Microsoft on AI recommendation poisoning (AML.T0130) and on a backdoor that uses an AI service API for command and control (AML.T0096), Cisco’s open-source skill scanner on instructions deferred to a later turn (AML.T0094), and ReversingLabs on corrupted model files (AML.T0076). Those vendors were not read against the whole framework, so they are not in the chart. And MoorAI’s own prose describes two of the 27, AML.T0094 and AML.T0117, which the prose review below credits; no shipped rule is mapped to them, so the chart’s MoorAI column, which counts rules, leaves them empty.

The 27 split three ways by ATLAS’s own tactic definitions.

11 are adversary preparation, in Reconnaissance, Resource Development and AI Attack Adaptation: acquiring public AI artifacts, developing capabilities, crafting a prompt or retrieval content, verifying an attack works, reconnaissance. They are on the map because ATLAS models the attacker’s whole path, not because they are a product gap. It is not true, though, that defensive products never claim this ground: vendors document nine techniques whose tactics all sit in these three or the two below, four of them in the preparation tactics themselves, led by autonomous AI agent communication (AML.T0118, twelve vendors).

6 sit in Discovery or AI Model Access: discovering a model family, its outputs or the LLM’s system information, and three kinds of model access. ATLAS does not call these preparation; it describes Discovery as post-compromise. They are listed apart rather than set aside. Neighbouring Discovery techniques are among the most documented in the review, and system-information discovery overlaps system-prompt extraction (AML.T0056), which thirteen vendors document; under the one-mechanism rule those sentences earn the extraction cell only.

The remaining 10 are defence-side techniques that a security product could plausibly address, and nobody in this set has published that they do. By tactic, the uncovered techniques fall like this:

Tactic (first listed)TechniquesDocumented by no productShareATLAS class
AI Attack Adaptation8675%adversary preparation
AI Model Access4375%Discovery / model access
Command and Control3267%defence-side
Reconnaissance3267%adversary preparation
Resource Development5360%adversary preparation
Impact9444%defence-side
Discovery7343%Discovery / model access
Defense Evasion11436%defence-side

By count, Defense Evasion and Impact tie for the most undocumented defence-side techniques, four of Defense Evasion’s eleven and four of Impact’s nine. By share, Command and Control is emptier, two of three. Defense Evasion is not empty: jailbreaks, prompt obfuscation, supply-chain rug pulls and triggers in multimodal inputs all have vendor coverage, and AI-targeted cloaking has a MoorAI rule. Two of the four that have nothing are about an attack that has already landed and is hiding — a false entry nested in the index, instructions set to fire later. The other two are about getting past a check: a model file corrupted to slip past a scanner, reputation inflated in a supply chain. Chat history rewritten and output dressed to look trustworthy each have a bounded MoorAI rule, written after the study.

Four of Impact’s nine techniques have nothing either: eroding model integrity, eroding dataset integrity, biasing an agent’s responses, flooding a system with chaff. These are outcomes an attacker actually wants, and no vendor here documents defending against them.

Nine techniques with exactly one vendor

Nine more are documented by a single vendor. A monoculture is worth knowing about when you are building a stack.

TechniqueThe only vendor documenting it
AML.T0061 LLM Prompt Self-ReplicationCranium
AML.T0060 Publish Hallucinated EntitiesEndor Labs
AML.T0115 Publish Poisoned AI ArtifactsEndor Labs
AML.T0040 AI Model Inference API AccessHarmonic Security
AML.T0062 Discover LLM HallucinationsLakera
AML.T0082 RAG Credential HarvestingLakera
AML.T0006 Active ScanningSalt Security
AML.T0100 AI Agent ClickbaitStraiker
AML.T0108 AI AgentZenity

A low count is usually a category, not a weakness

The vendors at the bottom of this map are mostly data-loss-prevention and insider-risk platforms. That is not a verdict on them. ATLAS agentic techniques describe an adversary acting against a model or an agent; a DLP platform is built to stop sensitive data leaving regardless of which technique moved it. Most of this framework is simply not its subject.

Two vendors say so themselves, and their word is taken over their own marketing. MIND, on a post about an autonomous-agent breach:

“MIND doesn’t patch template-injection flaws or contain a sandbox escape. No data loss prevention platform does.”

And dope.security, which publicly assigns MCP security, prompt injection and model security to others. Where a vendor draws its own boundary, the boundary wins — credits were removed on the strength of those statements.

Corpus size is not the explanation either. MIND publishes 184 pages and roughly 174,000 words, a body of material comparable to vendors scoring four times higher. It writes a great deal; it writes about something else.

We ran the method against ourselves

MoorAI’s column is counted differently from every vendor’s row: from a rule base that carries explicit ATLAS ids, where a technique counts when a shipped rule is tagged with it. Every vendor row is a prose review.

To find out what that difference is worth, MoorAI was scored the way vendors are — published prose only, no access to the rule base. It came out at 31, against the 27 the rule base gave on the read date. Discarding every credit traceable to one README bullet that names ATLAS ids outright, it is still 26.

So on the read date the prose method was the more generous of the two. Eight of those 31 are techniques our own rule base does not claim — inventory, posture and visibility sentences that a reviewer credits because that is what Operant and Lakera were credited for, and that a rule base has no rule for.

The rule base now gives 31, level with the prose count, and the two are no longer like-for-like in time. MoorAI agent v0.96.0, released on 26 September, added rules for AML.T0061, AML.T0092, AML.T0067 and AML.T0035, the last three bounded to local transcript files, links, and model files moved in one command. They were written after this study, because of the gaps it found; they did not exist when the prose was read, and the prose review has not been re-run since. The current release, agent v1.1.0, carries the same ATLAS mapping, and it is the rule base the chart’s MoorAI column is drawn from.

The real asymmetry is vocabulary, not measurement

Our documentation is written in this framework's language, in units about the size of one ATLAS technique. A prose review rewards that shape. A vendor whose documentation is written for buyers gets credited only where its wording happens to coincide with a technique name, and is undercounted for it. That is the bias in this map, and it favours us. Read the whole thing as a map of what each vendor has written down, not as a measurement of what each product does.

Every technique, every vendor: the evidence

MITRE ATLAS tags every technique with the kinds of system it applies to, and one of those tags is Agentic AI. Taking that tag as the filter gives 76 techniques in the 2026.09 release — the denominator of every count on this page. The set is MITRE’s, not ours, which is the point: it was not drawn around what any product here happens to do. Technique IDs, names and definitions come from the ATLAS 2026.09 data release (Apache‑2.0), published 2026-09-15. The table below is every cell of the study, and the chart above drawn as text.

How each cell was scored — and what the score is not

Where the 76 come from
Every top-level ATLAS 2026.09 technique whose own platforms field lists Agentic AI. Sub-techniques are not separate rows — a claim about one counts toward its parent. Applying someone else’s tag mechanically is what keeps the denominator honest: it admits techniques nobody covers, and it drops two that an earlier draft of this page scored, including AML.T0012, which the MoorAI rule base maps to. The rule costs MoorAI a cell rather than buying it one.
The comparison is asymmetric, in MoorAI’s favour — discount it accordingly
MoorAI’s count is derived from a rule base whose rules carry ATLAS ids, so nothing it addresses can be missed. Every competitor’s count comes from marketing and documentation prose that mostly never mentions ATLAS, so it is credited only where the wording happens to line up with a technique. Those two methods do not produce comparable numbers, and the gap flatters MoorAI. A vendor scoring lower here has not been shown to do less; it has been shown to have written less that maps onto this framework.
When one mechanism covers several techniques
A technique is credited when the evidence describes a distinct implemented mechanism that addresses that technique’s definition. One piece of evidence may credit more than one technique only when it implements each distinctly — never when one technique restates, contains, or is a likely consequence of another. So a single vague “discover your AI” sentence still earns one cell, not five; but a documented mechanism that genuinely does several separate jobs earns each of them. This rule was applied to every row in the table, MoorAI’s included. MoorAI’s row is re-derived under it: 9 of its 77 rules map to more than one technique.
When a vendor contradicts itself, the disclaimer wins
Vendors publish boundaries as well as claims, and the boundaries are honoured here over that same vendor’s marketing. A vendor writing “we do not claim this”, assigning a capability to a named competitor’s lane, or labelling it roadmap or not-yet-enforced, removes the cell — a company disowning a capability is stronger evidence than a sentence elsewhere implying it has one. Where the two are dated, the later statement governs; where a claim is newer than the disclaimer and describes something narrower that the disclaimer does not cover, it stands, with the boundary recorded on the cell. One vendor here lost two cells this way, and the rule cost it its position rather than us ours. A stated scope limit — only some hosts, only the hosted product, fails open, tests rather than enforces — keeps the cell and adds the limit instead. That search was not equally thorough for every vendor: two of the six reviews did not report, and their vendors’ boundaries were recovered from collected material rather than a dedicated pass, so “no disclaimer found” is less firmly established for those than for the rest. One credited capability was also removed for the opposite reason — not a disclaimer but an absence: the technology it named appears nowhere on that vendor’s site, so the credit had no evidence behind it at all.
Governing usage of AI is not defending against an adversary
Shadow-AI discovery, data-loss prevention and app control applied to AI traffic are real capabilities, but they are not coverage of an ATLAS adversary technique, and they earn no cell here. Explaining an attack is not covering it either: a blog post defining prompt injection is education, a page saying the product detects or blocks it is a claim, and only the second counts.
Three states, and no “absent”
A cell is documented, documented with a stated limit, or not described. A bounded cell still counts — it is coverage with an edge, and the edge is written on the row. There is deliberately no “absent” state: a vendor whose material is silent on a technique may well handle it. Nothing on this page says a named vendor is exposed to anything.
What a stated limit means
The bounded state is open to every product here and several vendors carry one — a capability routed to a third party rather than native, enforcement on only some hosts, or wording that describes red-team testing rather than runtime enforcement. MoorAI carries the most of them, and that is a fact about the evidence rather than about the products: MoorAI is scored from its own implementation, where the boundary is known and written down, while a competitor is scored from marketing copy, which rarely says where a capability stops. So read an unqualified documented in a vendor column as “their material claims this”, never as “this is complete” — on that evidence nobody can tell, and the absence of a limit is not evidence of its absence.
This is a documentation review, not a test
Competitor cells were read from each vendor’s own published material — product pages, public documentation, vendor blogs — on 2026-09-20, except 4 cells added in a correction on 2026-09-26, each dated in its source line below. 4 vendors were added to the review later, read on 2026-09-27 by the same method: Lasso Security, Permiso, Pillar Security, WitnessAI. 2 vendors were added to the review later, read on 2026-10-01 by the same method: Above Security, Rig Security. 18 vendors were added to the review later, read on 2026-10-01 by the same method: Airia, Akto, Aurascape, Cranium, CyCraft, DeepKeep, Enkrypt AI, HiddenLayer, Holistic AI, Levo.ai, NeuralTrust, Noma Security, Onyx Security, PointGuard AI, Singulr AI, Trustwise, Vijil, Virtue AI. Nothing here was measured against a running product. A measured result on this site looks different: it names a corpus, a split and a rate, the way the benchmark does. This does not.
Only the vendor’s own words count
Every documented cell carries the URL of the page it came from and a verbatim quote, listed under Sources below, each one re-checked against the live page. Analyst notes, press coverage and third-party write-ups were not used. A claim with no URL behind it was dropped rather than scored. Research a vendor publishes about an attack is not counted either — explaining a technique is not shipping a control for it, and that rule cost the vendor who contributed several of these techniques the cells it might otherwise have earned.
What was read, and what was not
Public HTML only. Gated PDFs, datasheets behind a form and anything requiring a login were not opened, and a few sites serve little text without JavaScript. For the vendors added on 2026-09-27 the read also took in ungated first-party PDFs linked from their sites and, for one, its open-source repositories; each of the four keeps its product documentation behind a login or a password, which was not opened. The two added on 2026-10-01 were read the same way, ungated first-party PDFs included; Above Security’s customer portal is behind a login and was not opened, and Rig Security publishes no product documentation. The eighteen added later on 2026-10-01 were read from the same kinds of first-party material, plus public product documentation, press releases and GitHub repositories, and for Virtue AI, which Fortinet has acquired, Fortinet’s own release; Airia, DeepKeep and HiddenLayer keep some or all of their documentation behind a login or a password, which was not opened, and Virtue AI’s documentation, which is rendered by JavaScript, was read in a browser. So “not described” means not found in the material that was read — narrower than “not published anywhere”, and much narrower than “not built”. That is not a formality, and two measurements on this page show why. A vendor first scored from its product pages alone came out at zero; reading its blog afterwards took it to 4, and one of the deciding posts is absent from its own site’s sitemap. A second vendor went from 13 to 22 the same way. And a sitemap-driven crawl has a systematic blind spot: one vendor’s marketing sitemap lists 481 pages and none of them on its documentation subdomain, which is where nearly all of its quotable claims live. A low count here is as likely to be a gap in the reading as a gap in the product, and it is the vendors whose substance sits off the marketing domain that this method under-reads.
MoorAI’s score is derived, and the snapshot it came from is named
MoorAI is not scored from its marketing. Its row is computed during the build from threats.json — rule base 0.7.0, 77 rules — by matching each rule’s ATLAS mapping against the 76 IDs. A technique counts only when a shipped rule carries that ID or one beneath it, so the number cannot be edited upward; it moves when a rule ships. That file is a copied snapshot of the product repository, not a live feed, so the version above is printed here, and in every build log, on purpose: it has sat a release behind before, and a number whose provenance is invisible rots quietly. The rule base also maps to AML.T0012, which this denominator does not contain. The full rule base is published at the threat catalog.
A count is not a ranking
Some of these techniques describe the adversary’s own preparation — Reconnaissance, Resource Development and AI Attack Adaptation, by ATLAS’s own tactic definitions: building a proxy model, staging infrastructure, orchestrating an autonomous attack. 27 of the 76 rows are empty for every product in the table, 11 of them preparation; vendors here do document 4 other preparation techniques. Others describe attacks on hosted, internet-reachable agents. A product on a developer’s laptop, one on a SaaS control plane and one at a network egress point are not competing for the same cells. Read the rows, not the totals.
AML.M0039 AI Honeypots is excluded
A mitigation rather than an adversary technique. Asking whether a product “covers” it is a category error, so it is left out of the denominator rather than scored against every vendor.
documented documented, with a stated limit not described ← scroll the table →
ATLAS 2026.09 technique MoorAI dope.security Operant AI Lakera SentinelOne Netskope Forcepoint Salt Security BigID Harmonic Security Zenity Cycode Bifrost Edge Ent Endor Labs Certiv Backslash Security Kitecyber Straiker MIND WitnessAI Lasso Security Pillar Security Permiso Above Security Rig Security Noma Security Onyx Security Akto HiddenLayer Virtue AI NeuralTrust DeepKeep Enkrypt AI Holistic AI Airia Aurascape Cranium CyCraft Levo.ai PointGuard AI Singulr AI Trustwise Vijil
AI Model Access
AI Model Inference API Access AML.T0040 Adversaries may gain access to a model via legitimate access to the inference API.Harmonic Security: Managed endpoints only (Harmonic Endpoint Agent); visibility and per-process/per-user attribution of inference-API connections — this sentence claims detection, not blocking.
Physical Environment Access AML.T0041 In addition to the attacks that take place purely in the digital domain, adversaries may also exploit the physical environment for their attacks.
Full AI Model Access AML.T0044 Adversaries may gain full "white-box" access to an AI model.
AI-Enabled Product or Service AML.T0047 Adversaries may use a product or service that uses artificial intelligence under the hood to gain access to the underlying AI model.
AI Attack Adaptation
Create Proxy AI Model — 3 sub-techniques AML.T0005 Adversaries may obtain models to serve as proxies for the target model in use at the victim organization.
Manipulate AI Model — 4 sub-techniques AML.T0018 Adversaries may manipulate an AI model artifact or its bundled components to change AI system behavior, introduce malicious code, or establish persistent malicious functionality.
Verify Attack AML.T0042 Adversaries can verify the efficacy of their attack via an inference API or access to an offline copy of the target model.
LLM Prompt Crafting AML.T0065 Adversaries may use their acquired knowledge of the target generative AI system to craft prompts that bypass its defenses and allow malicious instructions to be executed.
Retrieval Content Crafting AML.T0066 Adversaries may write content designed to be retrieved by user queries and influence a user of the system in some way.
Autonomous Attack-Path Adaptation AML.T0117 Adversaries may use an AI agent to autonomously construct and repeatedly revise an attack path toward an adversary-defined objective.
Autonomous AI Agent Communication — 2 sub-techniques AML.T0118 Autonomous AI agents may exchange operational information with other AI agents, sub-agents, or independent agent runs.MoorAI: Requires lineage metadata on agent events.Operant AI: Agent-loop plugin, scoped to Claude Cowork in cloud mode.Lakera: Vendor states it is addressed indirectly, and only where inter-agent interactions are routed through the Guard API; cryptographic/identity controls for inter-agent channels are explicitly left to the customer.Permiso: A forensic trail of the identity and authorisation chain between agents. No detection is described, and the content agents pass to one another is not inspected.Holistic AI: Endlayer's Guardian tier, one of three device-agent tiers; the page gives no mechanism detail for agent-to-agent interception.
Autonomous Attack Orchestration AML.T0124 Adversaries may use autonomous AI systems as an operational control layer to manage multiple distinct autonomous agents or sub-agents toward a common adversary-defined objective.
Reconnaissance
Active Scanning — 4 sub-techniques AML.T0006 Adversaries may actively scan for publicly reachable AI systems and resources for targeting.
Gather RAG-Indexed Targets AML.T0064 Adversaries may identify data sources used in retrieval augmented generation (RAG) systems for targeting purposes.
Autonomous Reconnaissance AML.T0116 Adversaries may use autonomous AI agents to conduct Reconnaissance activities.
Resource Development
Acquire Public AI Artifacts — 3 sub-techniques AML.T0002 Adversaries may search public sources, including cloud storage, public-facing services, and software or data repositories, to identify AI artifacts.
Obtain Capabilities — 5 sub-techniques AML.T0016 Adversaries may search for and obtain software capabilities for use in their operations.
Develop Capabilities — 3 sub-techniques AML.T0017 Adversaries may develop their own capabilities to support operations.
Publish Hallucinated Entities AML.T0060 Adversaries may create an entity they control, such as a software package, website, or email address corresponding to a source hallucinated by an LLM.MoorAI: Package names only.
Publish Poisoned AI Artifacts — 3 sub-techniques AML.T0115 Adversaries may create or modify AI artifacts and publish them through public or shared distribution channels to facilitate compromise of downstream AI systems.
Initial Access
AI Supply Chain Compromise — 6 sub-techniques AML.T0010 Adversaries may gain initial access to a system by compromising the unique portions of the AI supply chain.SentinelOne: ClawSec is a free open-source skill suite scoped to OpenClaw agents, not the commercial platformNoma Security: A posture assessment of MCP servers (unpinned versions, permissions, low-trust packages, known vulnerabilities), not interception of a compromised package at install or run time.Akto: Stated for agent skills (SKILL.md inventory and scanning) only.Enkrypt AI: A scan with allowlist/denylist recommendations, not a runtime block.PointGuard AI: A rating of the server, weighted 50% security, 30% operational and 20% adoption maturity per PointGuard's own methodology post, not a runtime block.Singulr AI: Drift detection against an approved baseline, described in a post that maps the product onto the LiteLLM compromise after the fact; the rest of that mapping is counterfactual ('would have').
Prompt Infiltration via Public-Facing Application AML.T0093 An adversary may introduce malicious prompts into the victim's system via a public-facing application with the intention of it being ingested by an AI at some point in the future and ultimately having a downstream effect.Pillar Security: A posture finding on CI/CD workflow configuration (SAIL 5.3) that flags an agent reachable by public input. It does not detect the injected prompt when it arrives.
Crafted AI Assistant Links AML.T0131 Adversaries may craft links that open an AI assistant or agent with attacker-controlled input already supplied, so that opening the link initiates an interaction the adversary defines rather than one the target composed.
Misconfigured or Publicly Exposed AI Services AML.T0132 AI agents and LLM platforms are deployed across diverse architectures, including standalone servers, SaaS platforms, and low-code builders.Lakera: A posture finding surfaced in a risk assessment, not runtime enforcement.Endor Labs: Static, source-and-configuration only — live runtime probes are disabled, so an exposed server is inferred from published source, not observed. Transport and Network Security is one of the three dimensions that contribute findings without a per-dimension score. Blocking depends on an MCP Server Posture policy, which is a guardrail, not a security boundary; enforcement fails open.Noma Security: Posture finding, not runtime enforcement.NeuralTrust: A posture finding from a scan, not runtime enforcement.PointGuard AI: A posture finding on MLOps platforms, not runtime enforcement.
Execution
User Execution — 4 sub-techniques AML.T0011 An adversary may rely upon a user to load, execute, interpret, or otherwise use a malicious or unsafe artifact.Certiv: The gate is "the user did not explicitly ask for it", not a malware verdict — Certiv makes no claim to identify a package as malicious, and a dependency the user does request is not checked. Semantic (model-judged) check; action is tunable per enrollment.Lasso Security: Lasso's open-source MCP Gateway security scanner, which gates MCP servers on a reputation score built from marketplace (Smithery, NPM) and GitHub data plus tool-description scanning; it is a reputation threshold, not a malware verdict, and applies only to servers routed through the gateway.HiddenLayer: Credited for the dependency-install clause only; the detection mechanism for malicious packages is not described.Enkrypt AI: Skill Sentinel is a pre-execution scanner run locally or in CI.
LLM Prompt Injection — 3 sub-techniques AML.T0051 An adversary may craft malicious prompts as inputs to an LLM that cause the LLM to act in unintended ways.Bifrost Edge: Bifrost's own FAQ routes injection and jailbreak detection to third-party providers; the native checks are secret, PII and custom-regex scanning plus an LLM-as-judge.Endor Labs: Source-only: an LLM workflow reads the SKILL.md captured at session start and scores it; skills are never executed and there is no runtime prompt inspection (Endor states it frames security "around the agent's actions, not just its prompts"). Enforcement via a Skill Access policy is a guardrail, not a security boundary, and enforcement fails open.Virtue AI: Red-team testing (AgentSuite-Red), not a runtime prompt-injection control.Enkrypt AI: Enkrypt states its guardrails process inputs of up to 14,000 characters.Holistic AI: Enforced through the HAI Guardian SDK, which the customer integrates into the agent or application so its traffic routes through Holistic's monitoring pipeline.Airia: Traffic routed through the Airia AI Gateway only; Airia's Claude guide says Claude iOS, Android and unlocked Desktop chat cannot be proxied and are monitored after the fact.Cranium: From Arena red teaming, which tests for prompt injection rather than blocking it at runtime.Levo.ai: AI Firewall (inline) product for in-house AI applications; FAQ answer.Trustwise: June 2025 launch press release; the product was then in private preview.
AI Agent Tool Invocation AML.T0053 Adversaries may use their access to an AI agent to invoke tools the agent has access to.Lakera: SaaS only: the published self-hosted detector list contains neither dangerous-deviation nor the tool allow/deny list.SentinelOne: Described in the future tense as a first phase rather than as shipped behaviour.Netskope: Enforcement on one hosted model platform is documented as failing open, and stdio and SSE transports are listed as untested.Forcepoint: The agent gateway this depends on is documented as pre-general-availability.BigID: BigID documents itself as feeding context to an enforcement point rather than being the enforcement point.Cycode: Enforced at the IDE and CLI boundary via hooks, stated for two assistants, with others on the roadmap.Bifrost Edge: Enforcement is a gateway allow-list; Bifrost states it does not execute the tool call itself.Endor Labs: Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.Straiker: Blocking requires the inline deployment; other deployments are documented as detection only.WitnessAI: An approved-list control: WitnessAI describes it as denying MCP servers and tools that are off the list before they execute, not as judging what an approved tool is asked to do. WitnessAI itself scopes it to “traffic governed through the platform” and, on its home page, to “supported agent workflows”.Permiso: Anomaly detection on tool calls attributed from logs to an identity. The stated response is an identity-layer kill switch once behaviour crosses a threshold. Permiso does not claim to evaluate a call before it runs, and it argues against prevention by guardrails.Rig Security: Inline enforcement on endpoints running the Gatewatch sensor, keyed to which agent is acting and which identity or resource it reaches (Rig's examples are AWS production versus dev). Rig does not publicly describe inspecting prompts, files read or tool arguments for malicious content, and it publishes no product documentation.DeepKeep: Cursor and Claude Code only today; GitHub Copilot, OpenAI Codex, Lovable and Windsurf are planned.Holistic AI: Requires the HAI Guardian SDK in the agent's path; Holistic lists Claude Code among the supported SDKs.Airia: Airia's Claude guide states that agent constraints intercept tool calls at the gateway, and that Bash commands Claude Code runs locally never traverse it.Aurascape: Gateway-routed tool calls only; Aurascape says a call that skips the gateway is caught through the model conversation instead.CyCraft: An OpenClaw plugin only, which sends tool calls to the XecGuard cloud Scan API; no other agent integration is published.Vijil: Library-level enforcement inside agents built with supported frameworks (or wrapped tools); not an interception point for third-party agents.
AI Agent Clickbait AML.T0100 Adversaries may craft deceptive content designed to bait computer-using AI agents or AI web browsers and tools into taking unintended actions, such as clicking buttons, copying code, or navigating to specific web pages.
Deploy AI Agent AML.T0103 Adversaries may launch AI agents in the victim's environment to execute actions on their behalf.SentinelOne: framed as shadow-AI hunting, not adversary-deployed-agent detection specificallyNetskope: managed Windows/macOS endpoints only, signature-bound; inventory onlyForcepoint: shadow-AI governance framing; inventory plus console-driven responseStraiker: Discovery/inventory of unknown and shadow agent deployments; containment is a separate product (Agentic Kill Switch).MIND: Inventory and visibility only — shadow-agent discovery, not detection of an adversary launching an agent.WitnessAI: Network-level shadow-AI and shadow-agent discovery; inventory, not detection of an adversary launching an agent.Lasso Security: Shadow-AI and agent discovery with risk scoring; Lasso says a high-risk agent can be blocked, but it is not framed as detection of an adversary deploying an agent.Pillar Security: Stated as a counterfactual about one campaign. The detection is keyed to permission-bypassing launch flags found by configuration scanning, not to the launch of an agent as such.Above Security: Visibility and alerting on OAuth consent grants to third-party AI agents, routed to the security team for an allow-or-revoke decision. Not prevention, and not agents launched on a device. Above says no enforcement action is taken autonomously on an AI verdict.Rig Security: Discovery and attribution of agents on devices where the Gatewatch sensor is deployed. This is inventory, not detection of an adversary launching an agent.Noma Security: Shadow-agent governance of endpoint agents, MCP servers and skills against an approved registry; not framed as detecting an adversary-deployed agent.Akto: Shadow-AI governance against an approved list, not detection of an adversary launching an agent.HiddenLayer: Shadow-AI discovery, not detection of an adversary launching an agent.NeuralTrust: Inventory and discovery rather than enforcement against an adversary-deployed agent.Holistic AI: Inventory and discovery on managed devices rather than enforcement against an adversary-deployed agent; seventeen tools are recognised by name, others surface as unidentified AI processes.Airia: Inventory and discovery rather than detection of an adversary-deployed agent.Aurascape: Shadow-agent discovery, not detection of an adversary launching an agent.PointGuard AI: Inventory on managed endpoints rather than detection of an adversary-deployed agent.
Persistence
Training Data Poisoning AML.T0020 Adversaries may manipulate data used for training or fine-tuning an AI model to influence the resulting model's behavior.Netskope: Hedged verb (“help ensure”), stated in an April 2025 press release rather than in product documentation.Salt Security: Monitoring of API payloads directed at training endpoints only; no claim to identify poisoned samples or clean a dataset.
LLM Prompt Self-Replication AML.T0061 An adversary may use a carefully crafted LLM Prompt Injection designed to cause the LLM to replicate the prompt as part of its output.Cranium: A static scan of markdown command and rules files in named directories (.cursor/commands, .windsurf/workflows, .github instructions, agents.md, claude.md, gemini.md), not runtime detection.
RAG Poisoning AML.T0070 Adversaries may inject malicious content into data indexed by a retrieval augmented generation (RAG) system to contaminate a future thread through RAG-based search results.Levo.ai: Testing of RAG outputs for signs of poisoning, not inspection of what is ingested into the index.
AI Agent Context Poisoning — 2 sub-techniques AML.T0080 Adversaries may attempt to manipulate the context used by an AI agent's large language model (LLM) to influence the responses it generates or actions it takes.MoorAI: Guidance only — no memory read or diff; memory writes carried in a crafted assistant link only.Lakera: Runtime integration for this is documented as roadmap, and the dangerous-deviation detector as beta.Pillar Security: From red teaming (RedGraph Suite), which probes for memory poisoning rather than enforcing against it at runtime.
Modify AI Agent Configuration AML.T0081 Adversaries may modify the configuration files for AI agents on a system.MoorAI: Auto-loaded agent-config paths only; proxy and CA-trust overrides only.Operant AI: The claim is detection of writes to agent configuration, not blocking them.SentinelOne: same ClawSec scope; drift detection alerts, does not blockZenity: Configuration-scan coverage is described for Claude Enterprise scopes/hook/skill files; not stated for other agent platforms.Endor Labs: A shipped policy row: it blocks writes to the agent's own settings and hooks, while reads are allowed. Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.Noma Security: Detection of configuration change as an inventory event; Noma does not say it blocks or attributes the change.Akto: Posture scan of Claude Code, Codex CLI and Copilot CLI config files found by the Endpoint Shield; it flags weakened settings rather than blocking the write.Enkrypt AI: ClawPatrol is an OpenClaw plugin; files are re-hashed every 60 seconds and changed content is sent to the Enkrypt API for a verdict.Cranium: Scans the content of configuration files; it does not watch for or block writes to them.
AI Agent Tool Data Poisoning AML.T0099 Adversaries may manipulate data in a victim-controlled, trusted, or connected data source that is accessible through an AI agent tool.MoorAI: Detected on read, not at rest in the data source.NeuralTrust: NeuralTrust's model report evaluates its indirect-injection model on an English-only held-out split of its own training corpus, and names browser-agent page injections as the weakest slice.
AI Agent Tool Poisoning — 3 sub-techniques AML.T0110 Adversaries may poison tools used by AI agents by introducing or modifying malicious content or behavior in a tool's model-visible definition, executable implementation, or runtime responses.MoorAI: Approved-connector allow-list only; tool definition and schema only.Endor Labs: Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.WitnessAI: From pre-deployment red teaming (Witness Attack), which tests for tool poisoning rather than enforcing against it at runtime.Virtue AI: Static scan of tool descriptions (definition), plus optional code scanning for vulnerabilities; not a runtime check of tool responses.NeuralTrust: A scan of MCP server code and configuration, not runtime enforcement.Enkrypt AI: Inline only where MCP traffic is routed through the gateway.Airia: Airia states Tool Scanning is informational, not a gate: it flags suspicious tool definitions and does not block them.Aurascape: Bounded by Aurascape itself to governed deployments.CyCraft: Content scan of skill text submitted to the API; CyCraft's FAQ says XecGuard is not recommended for scanning large documents or full-length files.Levo.ai: Pre-deployment security testing of MCP servers, not runtime prevention; covers poisoned tool output (runtime response), not poisoned tool definitions.Trustwise: Given as an example of the Prompt Shield; covers instructions hidden in a tool description (definition), not compromised tool implementations or runtime responses.
Defense Evasion
LLM Jailbreak AML.T0054 Adversaries may induce a large language model (LLM) to ignore, circumvent, or override its safety/alignment behaviors and/or guardrails to elicit outputs the model is intended to withhold.Zenity: Hedged verb ("helps protect against"); stated on the Microsoft 365 Copilot page. Corroborated on the Claude Enterprise page, where AIDR's real-time coverage list names "jailbreaks".Bifrost Edge: Bifrost's own FAQ routes injection and jailbreak detection to third-party providers; the native checks are secret, PII and custom-regex scanning plus an LLM-as-judge.Noma Security: From AI Red Teaming, which tests the customer's own apps and agents for jailbreaks rather than blocking them at runtime.Onyx Security: Automated red teaming of deployed agents (testing). The runtime jailbreak claim on the platform page shares a sentence with the prompt-injection cell and is not counted twice.HiddenLayer: From AI Attack Simulation, which tests for jailbreaks rather than blocking them at runtime.NeuralTrust: Enforced where traffic reaches a NeuralTrust collector (gateway, SDK, browser, sidecar or log stream).DeepKeep: DeepKeep's own blog says you can't reliably detect every jailbreak and recommends containment over detection.Aurascape: Applied on the model-conversation channel through the AI Proxy.
LLM Trusted Output Components Manipulation — 1 sub-technique AML.T0067 Adversaries may utilize prompts to a large language model (LLM) which manipulate various components of its response in order to make it appear trustworthy to the user.MoorAI: Links only — a link whose visible address differs from where it goes. Other output components are not checked.
LLM Prompt Obfuscation AML.T0068 Adversaries may hide or otherwise obfuscate prompt injections or retrieval content to avoid detection from humans, large language model (LLM) guardrails, or other detection mechanisms.MoorAI: Text and markup only. Low-contrast text rendered inside a raster image is not detected.Akto: Stated for the Claude Code UserPromptSubmit hook, i.e. the user's prompt, not tool output.NeuralTrust: NeuralTrust's own model report names inline-encoded payloads (base64/hex/ROT13) as the toxicity model's one material robustness gap.Cranium: Static scan of the same agent configuration files for zero-width, bidi, variation-selector and tag characters.
False RAG Entry Injection AML.T0071 Adversaries may introduce false entries into a victim's retrieval augmented generation (RAG) database.
Corrupt AI Model AML.T0076 An adversary may purposefully corrupt a malicious AI model file so that it cannot be successfully deserialized in order to evade detection by a model scanner.
Manipulate User LLM Chat History AML.T0092 Adversaries may manipulate a user's large language model (LLM) chat history to cover the tracks of their malicious behavior.MoorAI: Local agent transcript files only. Chat history held on a provider's servers is not visible from an endpoint and is not claimed.
Delay Execution of LLM Instructions AML.T0094 Adversaries may include instructions to be followed by the AI system in response to a future event, such as a specific keyword or the next interaction, in order to evade detection or bypass controls placed on the AI system.
AI Supply Chain Rug Pull AML.T0109 Adversaries may publish legitimate AI components or software, gain user adoption, then push an update with a malicious variant, leading to AI Supply Chain Compromise.Endor Labs: Re-scoring on change is the defence, but the rug-pull behaviour itself is never described. Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.Straiker: From red-team testing, which probes for this rather than enforcing against it at runtime.Enkrypt AI: ClawPatrol, an OpenClaw plugin; a modified skill is re-scanned and alerted on, not blocked.Airia: Applies to tools served through an Airia MCP Gateway or Deployment.
AI Supply Chain Reputation Inflation AML.T0111 AI Supply Chain Reputation Inflation is the process of building or leveraging genuinely credible-looking trust signals to increase the perceived legitimacy of AI supply chain components, with the goal of driving adoption of malicious or…
Triggers in Multimodal Inputs AML.T0129 Adversaries may place instructions or triggers in one part of a multimodal input to influence the model while staying unnoticed by human reviewers and by defenses that do not inspect all input modalities.MoorAI: The file-metadata channel only — EXIF and equivalents. Audio and video tracks are not inspected.WitnessAI: From pre-deployment red teaming (Witness Attack), which probes with multimodal attacks rather than inspecting multimodal inputs at runtime; no runtime multimodal inspection is claimed.Enkrypt AI: From red teaming, which probes for this rather than enforcing against it at runtime.
AI Targeted Cloaking AML.T0134 Adversaries may selectively deliver malicious or manipulated content to AI systems, while presenting different benign content to human users, web crawlers, or security detection mechanisms.MoorAI: Only the artefact the cloaked response leaves behind. The server-side User-Agent branch is invisible from an endpoint and is not claimed.
Discovery
Discover AI Artifacts AML.T0007 Adversaries may search private sources to identify AI learning artifacts that exist on the system and gather information about them.Operant AI: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.SentinelOne: inventory/posture only; the /platform/ai-security-posture-management page is a live 404, so blog announcement is the only sourceBigID: Inventory-only: detects model files/binaries at rest; no claim to detect an adversary enumerating them.Pillar Security: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.Permiso: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.Noma Security: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.HiddenLayer: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.Holistic AI: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.Cranium: Inventory from repository scanning, not detection of an adversary enumerating artefacts.PointGuard AI: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.
Discover AI Model Family AML.T0014 Adversaries may discover the general family of a model.
Discover LLM Hallucinations AML.T0062 Adversaries may prompt large language models and identify hallucinated entities.Lakera: From red teaming, which probes for this rather than enforcing against it at runtime.
Discover AI Model Outputs AML.T0063 Adversaries may discover model outputs, such as class scores, whose presence is not required for the system to function and are not intended for use by the end user.
Discover LLM System Information — 3 sub-techniques AML.T0069 The adversary is trying to discover something about the large language model's (LLM) system information.
Discover AI Agent Configuration — 4 sub-techniques AML.T0084 Adversaries may attempt to discover configuration information for AI agents present on the victim's system.Operant AI: Inventory and discovery rather than enforcement against an adversary enumerating agent configuration.Lakera: Inventory and discovery rather than enforcement against an adversary enumerating agent configuration.SentinelOne: OneClaw is a standalone discovery/observability tool; inventory only, no enforcementEndor Labs: Inventory/visibility only. The system policy that guards agent configuration blocks writes, edits and deletes but explicitly allows reads, so discovery of the configuration itself is not blocked. Guardrails, not a security boundary; enforcement fails open.Kitecyber: Inventory of agent configuration and loaded skills; not runtime enforcement.Lasso Security: Inventory of the defender's own agents (read-only CI and cloud-platform integrations), not detection of an adversary enumerating agent configuration.Pillar Security: An inventory of each agent's configuration. It does not detect an adversary who is enumerating that configuration.Permiso: An inventory of which tools and data each agent can reach. It does not detect an adversary who is enumerating agent configuration.Noma Security: Inventory built from EDR or MDM telemetry; it does not detect an adversary enumerating agent configuration.Akto: Inventory and discovery rather than enforcement against an adversary enumerating agent configuration.NeuralTrust: Inventory and discovery rather than enforcement against an adversary enumerating agent configuration.DeepKeep: A design-time assessment of the customer's own agent, not runtime enforcement.Enkrypt AI: A pre-deployment and periodic scan of MCP servers, not runtime enforcement.Airia: Observe mode of the airiad endpoint agent; Airia's guide lists macOS Apple Silicon as the packaged platform today.Cranium: Repository scan of six agent frameworks (Strands, CrewAI, smolagents, AutoGen-AgentChat, LangGraph, OpenAI Agents); inventory only.
Discover AI Agent Runtime Capabilities AML.T0133 Adversaries may interact with an AI agent at runtime to reveal the capabilities available to it, without requiring access to its underlying configuration.Lakera: From red teaming, which probes for this rather than enforcing against it at runtime.Pillar Security: From red teaming, which performs the capability discovery itself rather than enforcing against it at runtime.Noma Security: Inventory of the defender's own MCP servers and tools, not detection of an agent being probed for its capabilities.Akto: Inventory of the defender's own agents' reach, not detection of capability probing.Aurascape: Inventory of the defender's MCP servers and tools.
Collection
AI Artifact Collection AML.T0035 Adversaries may collect AI artifacts for Exfiltration or for use in AI Attack Staging.MoorAI: Model files and caches moved by a single command. Collection spread across several steps is not claimed.
Data from AI Services — 2 sub-techniques AML.T0085 Adversaries may use their access to a victim organization's AI-enabled services to collect proprietary or otherwise sensitive information.Netskope: the collection-side claim rests on 'tool call results' and 'resource content'; the trailing clause is egress-framedKitecyber: Endpoint-local detection/alerting on agent access to sensitive data; no RAG-database coverage.MIND: Visibility of what data agents reach, from the data side (endpoint agent, browser extension, SaaS connectors); no claim to inspect RAG retrievals or agent tool results.Permiso: Keyed to first-time data access against the agent's own baseline, and answered at the identity layer. Permiso does not inspect what is retrieved.
Exfiltration
Exfiltration via AI Inference API — 3 sub-techniques AML.T0024 Adversaries may exfiltrate private information via AI Model Inference API Access.Levo.ai: Names model extraction only (AML.T0024.002); no claim for membership inference or model inversion.
Extract LLM System Prompt AML.T0056 Adversaries may attempt to extract a large language model's (LLM) system prompt.Netskope: AI Red Teaming probe set - pre-deployment testing, not runtime enforcementAkto: A listed catch of the PromptInjection guardrail rather than a separate detector.HiddenLayer: System prompt hardening in attack simulation; a test, not runtime prevention.NeuralTrust: A detection rate on NeuralTrust's own benchmark, which the report says was built to its own taxonomies and carries a home-field advantage.Airia: From red teaming, which probes for this rather than enforcing against it at runtime.
LLM Data Leakage AML.T0057 Adversaries may craft prompts that induce the LLM to leak sensitive information.Cycode: Enforced at the IDE and CLI boundary via hooks, stated for two assistants, with others on the roadmap.Virtue AI: Fortinet's description of Virtue AI's real-time guardrails in its acquisition release; the jailbreak claim in this sentence is not counted again.Cranium: From Arena red teaming, which simulates data leakage rather than preventing it at runtime.CyCraft: CyCraft's FAQ says the PII Policy detects personal-information attributes broadly at a low risk level and 'is not designed as a malicious activity detection alert'.
LLM Response Rendering AML.T0077 Adversaries may induce a large language model (LLM) to respond with private information structured in a reference to external content that, when rendered by the user's client, makes a request to an adversary-controlled server, exfiltrati…MoorAI: The rendered-URL channel. There is no OCR on egress, so an image-borne payload is not read.HiddenLayer: A URL detection outcome in Agentic Runtime Security; HiddenLayer does not say it checks whether the link carries conversation data.
Exfiltration via AI Agent Tool Invocation AML.T0086 AI agent tools capable of performing write operations may be invoked to exfiltrate data to an adversary.MoorAI: Send-message tool families only; known local secret values only.dope.security: Egress data-loss control over what an agent uploads or pastes, not interception of the tool call itself. dope states it does not claim MCP security.Operant AI: Response enforcement is documented as detect-and-log for this path rather than blocking.Lakera: Dangerous Deviation detector is in beta, ships in a conservative configuration, and is recommended in Detect mode before Enforce.BigID: BigID documents itself as feeding context to an enforcement point rather than being the enforcement point.Cycode: Enforced at the IDE and CLI boundary via hooks, stated for two assistants, with others on the roadmap.Endor Labs: The name of a shipped system policy rather than a described capability. Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.MIND: Egress data-loss control at the endpoint, browser and SaaS layer; MIND nowhere claims to intercept or evaluate an agent tool call itself.Above Security: After-the-fact investigation and attribution of data that an OAuth-scoped third-party agent has already reproduced off-site. Above does not claim to intercept or evaluate the agent's tool calls.Onyx Security: An anonymised scenario the post says is composited from POV work with several customers (a coding agent posting an AWS key to an external webhook after an injected README instruction).Akto: A host and path blocklist with wildcards; it does not inspect what the request carries.NeuralTrust: Stated as identification within agent tracing; the sentence does not say the exfiltrating call is blocked.Levo.ai: General agent-enforcement claim; does not name a specific tool-invocation exfiltration mechanism.
Impact
Denial of AI Service AML.T0029 Adversaries may target AI-enabled systems with a flood of requests for the purpose of degrading or shutting down the service.Akto: A use case of the Behavioural Anomaly guardrail (request-rate and repetition baselines), not a dedicated denial-of-service control.HiddenLayer: A per-requester token threshold (default 4096 tokens).Vijil: A Diamond evaluation probe (pre-deployment testing), not a runtime control.
Erode AI Model Integrity AML.T0031 Adversaries may degrade the target model's performance with adversarial data inputs to erode confidence in the system over time.
Cost Harvesting — 3 sub-techniques AML.T0034 Adversaries may deliberately drive a victim's AI services beyond normal operating capacity with the intent of increasing the cost of services.Netskope: framed as spend/budget control, not abuse or attack detection; release-note summary lineCertiv: Certiv states this capability is in public preview.WitnessAI: Framed as AI FinOps spend control — blocking or rerouting prompts classified as non-productive — rather than detection of deliberate cost harvesting.Holistic AI: Framed as cost control; Holistic states its cost figures are estimates from observed token counts against published pricing.PointGuard AI: Framed as runaway-loop and drift detection, not as an adversary driving up cost.Trustwise: Framed as cost optimisation of runaway agent loops rather than defence against an adversary inflating cost.
Spamming AI System with Chaff Data AML.T0046 Adversaries may spam the AI system with chaff data that causes increase in the number of detections.
External Harms — 5 sub-techniques AML.T0048 Adversaries may abuse their access to a victim system and use its resources or capabilities to further their goals by causing harms external to that system.Permiso: Covers LLMjacking only, meaning unauthorised use of the customer's own hosted LLM instances. ATLAS's LLM Jacking case study (AML.CS0030) maps that to the financial-harm sub-technique. Harmful-content output is not addressed.Akto: Framed as protecting the customer's LLM licence standing rather than as stopping misuse by an adversary.
Erode Dataset Integrity AML.T0059 Adversaries may poison or manipulate portions of a dataset to reduce its usefulness, reduce trust, and cause users to waste resources correcting errors.
Data Destruction via AI Agent Tool Invocation AML.T0101 Adversaries may invoke an AI agent's tool capable of performing mutative operations to perform Data Destruction.Endor Labs: Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.Onyx Security: Policy-based blocking of destructive tool calls, framed by Onyx around agent mistakes rather than adversary-driven destruction.DeepKeep: Sends the command for developer approval rather than blocking it outright; Cursor and Claude Code only today.Aurascape: Caught in the tool call the model streams back over the network, before the client executes it, so it depends on traffic being steered through Aurascape.
Machine Compromise — 2 sub-techniques AML.T0112 Adversaries may compromise a machine by exploiting or manipulating AI-enabled components on the system.MoorAI: Reverse-shell / remote-exec payloads only.
AI Agent Response Biasing AML.T0130 Adversaries may manipulate an AI assistant so that it favors adversary-chosen sources, or content in its responses.
Credential Access
RAG Credential Harvesting AML.T0082 Adversaries may attempt to use their access to a large language model (LLM) on the victim's system to collect credentials.Lakera: From red teaming, which probes rather than enforces, and names credentials in system prompts and configuration rather than a retrieval corpus.
Credentials from AI Agent Configuration AML.T0083 Adversaries may access the credentials of other tools or services on a system from the configuration of an AI agent.dope.security: Visibility of the MCP server domains a device reaches, which dope itself calls a first step toward an inventory rather than a control. dope states elsewhere that it does not claim MCP security; this cell is credited because the claim is egress visibility and its source post post-dates that statement.Operant AI: An inventory of which credentials each integration uses, rather than prevention of credential retrieval.Lakera: A posture finding surfaced in a risk assessment, not runtime prevention of credential retrieval.Salt Security: Posture-scan detection of exposed credentials across agentic components (the section's own bullets name "Hardcoded tokens and credentials" and "Risky MCP configurations"); inventory/flagging, not runtime prevention of credential read.Endor Labs: A scoring dimension rather than an enforced block. Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.Backslash Security: Free standalone Claw-Hunter script for OpenClaw only; read-only scan of the agent install/config, not platform-wide enforcement.Pillar Security: A configuration-posture finding about credentials stored in MCP configuration. It does not prevent an adversary reading them at runtime.Noma Security: A posture finding about secrets stored in agent instructions; it does not describe preventing an agent from reading them.Onyx Security: Posture scanning of agent configuration files for stored credentials, from a list of what Onyx's configuration reviews look for; it reduces what an adversary could harvest rather than detecting the harvesting.Akto: A risk-scoring finding about credentials stored in skill files, not prevention of an agent reading them.PointGuard AI: Removes standing credentials from agent configuration rather than detecting their theft.
AI Agent Tool Credential Harvesting AML.T0098 Adversaries may attempt to use their access to an AI agent on the victim's system to retrieve data from available agent tools to collect credentials.MoorAI: Local credential files and keychain only.Netskope: wording is 'manipulating' (create/rotate/export/delete), broader than harvestingForcepoint: AI Agent Gateway is stated on the same page as 'currently in early access ahead of general availability'; inline app support only 'spans core enterprise SaaS platforms at launch'Cycode: IDE-boundary control framed as data-leak prevention rather than adversary detection; enforced where Cycode AI Guardrails hooks are installed.Endor Labs: Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.Lasso Security: The open-source gateway's basic plugin masks the token types it lists (cloud, GitHub, GitLab, Hugging Face, JWT, Slack and similar) in MCP tool responses routed through the gateway; pattern masking, not detection of harvesting intent.Pillar Security: A behavioural-baseline alert on rapid, sequential reads of credential files, which Pillar describes as a deviation that triggers an alert. A single credential read by an agent is not claimed.Noma Security: Stated in a December 2025 launch post about Cursor hooks; the Claude Code coverage page does not repeat the file-access claim.Akto: Output-side scan of what a tool returns; the documented example is an API key in a file-reader response.DeepKeep: AI Lens for Developers supports Cursor and Claude Code today; other coding agents are planned.PointGuard AI: Managed macOS, Windows and Linux endpoints running PointGuard's endpoint client.
Command and Control
AI Service API AML.T0096 Adversaries may communicate using the API of an AI service on the victim's system.
AI Agent AML.T0108 Adversaries may abuse AI agents present on the victim's system for command and control.Zenity: Named as an AIDR detection class on the Claude Enterprise page only; no mechanism detail beyond the named detection.
AI Artifact Repository AML.T0120 Adversaries may repurpose AI artifact repositories as asynchronous command-and-control channels.
Covered, of 76 31 2 23 21 15 17 9 12 8 3 23 10 7 0 18 14 14 4 22 4 14 23 26 9 2 2 20 7 21 14 6 19 9 20 12 12 11 10 8 11 19 4 6 6

Sources — every documented cell, with the words behind it

MoorAI derived from rule base 0.7.0

MoorAI’s row is not a reading of MoorAI’s own marketing. It is computed during the site build from src/_data/threats.json — rule base 0.7.0, 77 rules, carrying 33 distinct ATLAS ids — by matching each rule’s mapping against the 76 IDs above. That file is a copied snapshot of the product repository rather than a live feed, so the version is named here and printed in every build log. 16 of the cells below are bounded: real coverage with an edge, and the edge is written out. The same rule base is published in full at the threat catalog.

  • AML.T0118 — Sub-agent / A2A delegation
    Limit: Requires lineage metadata on agent events.
  • AML.T0060 — Hallucinated or typosquatted dependency
    Limit: Package names only.
  • AML.T0010 — Shadow AI; Unsanctioned or malicious package install
  • AML.T0131 — Crafted AI assistant link
  • AML.T0011 — Dangerous links, files, or scripts from AI output; AI-Assisted Malware - dangerous code, macros, and scripts; Insecure code generation; Unsafe AI model loading
  • AML.T0051 — Direct Prompt Injection; Indirect Prompt Injection; Second-Order Prompt Injection; Model-escalated risk (on-device second opinion); AI rules/config file poisoning
  • AML.T0053 — Downloading malicious Skills, Plugins, or Extensions; Plugins with excessive permissions; Information exposure due to excessive permissions; Automatic action taken on the employee's behalf; Excessive Agency; Tool Misuse; AI browser extensions with browser access; Agent entitlement drift (out-of-scope action); Sub-agent / A2A delegation
  • AML.T0020 — Knowledge-base poisoning / RAG Poisoning
  • AML.T0061 — Self-replicating prompt
  • AML.T0080 — Memory Poisoning; Crafted AI assistant link
    Limit: Guidance only — no memory read or diff; memory writes carried in a crafted assistant link only.
  • AML.T0081 — AI rules/config file poisoning; Transit interception (proxy / CA environment injection)
    Limit: Auto-loaded agent-config paths only; proxy and CA-trust overrides only.
  • AML.T0099 — Second-Order Prompt Injection
    Limit: Detected on read, not at rest in the data source.
  • AML.T0110 — MCP / Connector Tool Poisoning; AI rules/config file poisoning
    Limit: Approved-connector allow-list only; tool definition and schema only.
  • AML.T0054 — Direct Prompt Injection; Indirect Prompt Injection
  • AML.T0067 — Deceptive link in AI output
    Limit: Links only — a link whose visible address differs from where it goes. Other output components are not checked.
  • AML.T0068 — Indirect Prompt Injection; Invisible or obfuscated text in content
    Limit: Text and markup only. Low-contrast text rendered inside a raster image is not detected.
  • AML.T0092 — Agent chat-history tampering
    Limit: Local agent transcript files only. Chat history held on a provider's servers is not visible from an endpoint and is not claimed.
  • AML.T0129 — Instructions in file metadata
    Limit: The file-metadata channel only — EXIF and equivalents. Audio and video tracks are not inspected.
  • AML.T0134 — Content aimed only at the AI client
    Limit: Only the artefact the cloaked response leaves behind. The server-side User-Agent branch is invisible from an endpoint and is not claimed.
  • AML.T0133 — Agent capability enumeration
  • AML.T0035 — AI model or dataset collection
    Limit: Model files and caches moved by a single command. Collection spread across several steps is not claimed.
  • AML.T0024 — Unapproved model endpoint (rogue LLM egress); Transit interception (proxy / CA environment injection); Local secret value egress
  • AML.T0056 — System-prompt extraction attempt; System-prompt or instruction leakage in output
  • AML.T0057 — Sensitive data leak; Intellectual-property exposure; Employee or customer privacy violation; Sensitive data retained in an AI conversation; AI Meeting Assistants and transcription of sensitive meetings; Leakage via email and Teams/Slack thread summaries; Leakage via conversation history and uploaded files; Data Residency - processing in an unapproved country; Cross-Context Leakage; Unauthorized AI Sharing - sharing output with excess information; Secret / credential exposure; Protected health information (HIPAA / PHI); Lethal trifecta exposure
  • AML.T0077 — Exfiltration through rendered output
    Limit: The rendered-URL channel. There is no OCR on egress, so an image-borne payload is not read.
  • AML.T0086 — Sending external email or notifications; Local secret value egress
    Limit: Send-message tool families only; known local secret values only.
  • AML.T0034 — AI Cost Abuse; Oversized or runaway input
  • AML.T0048 — Reliance on incorrect answers or hallucinations; AI-enhanced phishing; BEC, Business Email Compromise; Deepfake voice or video; AI-based Vishing and Smishing; Bias and discrimination in outputs; Fake links and sources generated by AI; AI-Generated Invoices; Synthetic Identity of suppliers or candidates; Misleading Translation; Overconfidence in an AI answer; Legal / contract language; Employee relations / PIP; Copyright / license contamination; Changing security settings, IAM, or firewall; Sending external email or notifications; Creating users, tokens, or API keys; Deploying to a production environment
  • AML.T0101 — Destructive command execution; Destructive tool / MCP call
  • AML.T0112 — Reverse shell / remote code execution
    Limit: Reverse-shell / remote-exec payloads only.
  • AML.T0098 — Credential / secret-file access
    Limit: Local credential files and keychain only.
dope.security 2 of 76

dope publishes explicit boundaries and they are honoured here over its own earlier marketing. On 31 August 2026 it wrote that it does not govern agent runtimes on Bedrock or Vertex and “does not claim MCP security”, assigning MCP server governance to a named competitor, and it separately assigns prompt injection and model security to others. Two cells credited from earlier posts were removed on the strength of that. The two that remain are egress visibility and egress data-loss control — what dope still claims — and one of them comes from a post published after the disclaimer.

  • AML.T0086 — If an agent uploads a file or pastes content containing PII, PCI, PHI, or source code, dope.security can block, warn, or log based on your policy
    https://dope.security/post/ai-browser-governance-2026 (read 2026-09-20)
    Limit: Egress data-loss control over what an agent uploads or pastes, not interception of the tool call itself. dope states it does not claim MCP security.
  • AML.T0083 — dope.security surfaces every MCP server domain a device connects to, which is the first step to inventorying those identities.
    https://dope.security/post/non-human-identity-security-2026 (read 2026-09-20)
    Limit: Visibility of the MCP server domains a device reaches, which dope itself calls a first step toward an inventory rather than a control. dope states elsewhere that it does not claim MCP security; this cell is credited because the claim is egress visibility and its source post post-dates that statement.
Operant AI 23 of 76

Most of these cells come from Operant's engineering blog rather than its product pages. Operant also asserts coverage on an OWASP comparison page using Detects and Defends badges beside OWASP's own copied risk definitions — real assertions by the vendor, but with no sentence to quote, so this method cannot count them. Searched for and not found anywhere in its material: system-prompt extraction, RAG poisoning and hallucinated-package publication. Its documentation site requires a login and was not read.

Lakera 21 of 76 · partial review

This vendor had a shallower read than the others here, for a reason recorded below. Its count is a floor rather than a comparable figure, and on this page a shallower read has repeatedly meant a lower count rather than a weaker product. It is marked rather than quietly counted.

Lakera Guard is now published under Check Point, and nearly all of its quotable claims sit on its documentation site rather than its marketing site. Its blog and security guides were deliberately not read, which is the largest unread surface of any vendor here, so this count is a floor. Two candidate cells were dropped because the wording described how the attack works rather than what the product does. Lakera's own ATLAS mapping exists inside the product but is not published, so nothing was scored from it.

  • AML.T0118 — Inter-agent communication (ASI07) is addressed indirectly: by inspecting the content agents pass between each other when those interactions are screened through the Guard API.
    https://docs.lakera.ai/docs/agent-security/framework-mapping (read 2026-09-20)
    Limit: Vendor states it is addressed indirectly, and only where inter-agent interactions are routed through the Guard API; cryptographic/identity controls for inter-agent channels are explicitly left to the customer.
  • AML.T0010 — Examples: unofficial or unverified MCP servers, MCP servers whose public code shows vulnerabilities or suspicious indicators, and components of unknown origin.
    https://docs.lakera.ai/docs/agent-security/risk-assessment (read 2026-09-20)
  • AML.T0132 — Examples: an agent owned by a non-organizational identity, and weak or missing authentication configuration on platforms that expose it.
    https://docs.lakera.ai/docs/agent-security/risk-assessment (read 2026-09-20)
    Limit: A posture finding surfaced in a risk assessment, not runtime enforcement.
  • AML.T0011 — Prevent attackers manipulating the LLM into displaying malicious or phishing links to your users by detecting unknown links.
    https://docs.lakera.ai/docs/defenses (read 2026-09-20)
  • AML.T0051 — Check Point AI Guardrails provides prompt defenses through detecting prompt attacks in real-time
    https://docs.lakera.ai/docs/prompt-defense (read 2026-09-20)
  • AML.T0053 — The Tool Allow/Deny List enforces which tools an agent may call at runtime, at the moment of tool invocation
    https://docs.lakera.ai/docs/agent-behavior-defense (read 2026-09-20)
    Limit: SaaS only: the published self-hosted detector list contains neither dangerous-deviation nor the tool allow/deny list.
  • AML.T0070 — For static document sets like knowledge bases, screen documents for prompt attack poisoning off-line
    https://docs.lakera.ai/docs/api/guard (read 2026-09-20)
  • AML.T0080 — Tool messages are screened as untrusted content, so Prompt Defense and Data Leakage detection run on them according to your policy.
    https://docs.lakera.ai/docs/agent-behavior-defense (read 2026-09-20)
    Limit: Runtime integration for this is documented as roadmap, and the dangerous-deviation detector as beta.
  • AML.T0099 — Screens the content a tool returns before the agent consumes it.
    https://docs.lakera.ai/docs/api/screening-roles (read 2026-09-20)
  • AML.T0110 — screen tool descriptions as content when a new tool or MCP server is added
    https://docs.lakera.ai/docs/prompt-defense (read 2026-09-20)
  • AML.T0054 — This includes jailbreaks, prompt injections and any attempts to manipulate and exploit AI models through malicious or unintentionally troublesome instructions
    https://docs.lakera.ai/docs/defenses (read 2026-09-20)
  • AML.T0068 — Catch instruction overrides, jailbreaks, indirect injections, and obfuscated prompts as they happen, before they reach your model.
    https://www.lakera.ai/risk/prompt-injection-attacks (read 2026-09-20)
  • AML.T0062 — Inducing the model to fabricate facts, citations, entities, or statistics presented as real
    https://docs.lakera.ai/docs/red/attack-coverage (read 2026-09-20)
    Limit: From red teaming, which probes for this rather than enforcing against it at runtime.
  • AML.T0084 — Discovery connects to the platforms where agents run and builds an inventory.
    https://docs.lakera.ai/docs/agent-security/discovery (read 2026-09-20)
    Limit: Inventory and discovery rather than enforcement against an adversary enumerating agent configuration.
  • AML.T0133 — Extraction of information about available tools, functions, APIs, or capabilities that the system has access to
    https://docs.lakera.ai/docs/red/attack-coverage (read 2026-09-20)
    Limit: From red teaming, which probes for this rather than enforcing against it at runtime.
  • AML.T0056 — In order to prevent extraction of system prompts, particular for further exploitation by attackers, custom data leakage guardrails can be setup within AI Guardrails
    https://docs.lakera.ai/docs/data-leakage-prevention (read 2026-09-20)
  • AML.T0057 — Check Point AI Guardrails can prevent data leakage by screening LLM inputs and outputs for personally identifiable information
    https://docs.lakera.ai/docs/data-leakage-prevention (read 2026-09-20)
  • AML.T0086 — A tool_call for export_customer_records with an external destination address is ungrounded in the request and leaks customer data — it is detected.
    https://docs.lakera.ai/docs/agent-behavior-defense (read 2026-09-20)
    Limit: Dangerous Deviation detector is in beta, ships in a conservative configuration, and is recommended in Detect mode before Enforce.
  • AML.T0048 — Ensure your GenAI applications do not violate your organization's policies by detecting and stopping harmful and unwanted content.
    https://docs.lakera.ai/docs/defenses (read 2026-09-20)
  • AML.T0082 — Attempts to extract hidden system prompts, credentials, or sensitive configurations
    https://docs.lakera.ai/red (read 2026-09-20)
    Limit: From red teaming, which probes rather than enforces, and names credentials in system prompts and configuration rather than a retrieval corpus.
  • AML.T0083 — Examples: write-capable tools; static credentials in toolset configuration; OAuth available but not used.
    https://docs.lakera.ai/docs/agent-security/risk-assessment (read 2026-09-20)
    Limit: A posture finding surfaced in a risk assessment, not runtime prevention of credential retrieval.
SentinelOne 15 of 76 · partial review

This vendor had a shallower read than the others here, for a reason recorded below. Its count is a floor rather than a comparable figure, and on this page a shallower read has repeatedly meant a lower count rather than a weaker product. It is marked rather than quietly counted.

SentinelOne's AI-security material spans the acquired Prompt Security line, AI-SPM and several dedicated agentic products. Its site publishes no usable sitemap, so pages are found by following links rather than enumerated. A second pass found four agentic products the first had missed and raised its count by six, which is evidence that this method under-reads this vendor rather than evidence that it no longer does — the floor marking stands.

Netskope 17 of 76

Netskope's AI Guardrails documentation states that it maps classified prompts and responses to MITRE ATLAS, making it the one vendor here whose own material references the framework this score is built on.

Forcepoint 9 of 76

Forcepoint's AI material describes no prompt-injection or jailbreak capability at all; its AI story is data classification, DLP and an agent gateway. Its AI Data Security datasheet is a password-encrypted PDF and was not read.

Salt Security 12 of 76

Salt publishes no public product documentation — every cell here comes from marketing pages and its product blog.

BigID 8 of 76

BigID's product documentation is behind a login and was not read. Much of what BigID markets — shadow-AI discovery, account governance — has no adversary-technique row in this set at all.

  • AML.T0051 — The BigID AI Security Platform (AISP) helps protect against prompt injection, model abuse, and vector-store risk.
    https://bigid.com/blog/what-is-aegis/ (read 2026-09-20)
  • AML.T0053 — BigID mediates agentic tool calls, embeds runtime checks, and flags suspicious behavior
    https://bigid.com/blog/what-is-aegis/ (read 2026-09-20)
    Limit: BigID documents itself as feeding context to an enforcement point rather than being the enforcement point.
  • AML.T0007 — BigID automatically scans your data repositories —including S3 buckets, file stores, and databases—to detect files and binaries associated with AI models (e.g., PyTorch, TensorFlow).
    https://bigid.com/blog/detecting-shadow-ai-with-bigid/ (read 2026-09-20)
    Limit: Inventory-only: detects model files/binaries at rest; no claim to detect an adversary enumerating them.
  • AML.T0084 — Find .md files across cloud storage, code repositories, collaboration platforms, and developer workstations.
    https://bigid.com/ai-instruction-file-security/ (read 2026-09-20)
  • AML.T0085 — During RAG or vector retrievals, BigID uses sensitivity metadata and entitlements to surface only what’s allowed
    https://bigid.com/blog/what-is-aegis/ (read 2026-09-20)
  • AML.T0057 — Monitor generated responses for sensitive data exposure, policy violations, unauthorized disclosure, and risky output.
    https://bigid.com/ai-prompt-security/ (read 2026-09-20)
  • AML.T0086 — determine which agents can reach sensitive data, where that information can move, and what to fix before an agent becomes the path out
    https://bigid.com/blog/ai-agent-data-exfiltration/ (read 2026-09-20)
    Limit: BigID documents itself as feeding context to an enforcement point rather than being the enforcement point.
  • AML.T0083 — BigID identifies PII, credentials, API keys, proprietary IP, and other sensitive data types within unstructured Markdown content
    https://bigid.com/ai-instruction-file-security/ (read 2026-09-20)
Harmonic Security 3 of 76

Harmonic states on its own comparison pages that agent inventory, posture management, agent identities, secrets management and pre-deployment red-teaming are not its product and it is not building them, and answers “No” when asked whether it secures customer-built agents. Those disclaimers are honoured here over its marketing. Most of what it does market — workforce AI usage governance — has no adversary-technique row in this set, so a low count reflects the framework's scope rather than product thinness. Its one inference-endpoint cell is visibility and attribution on managed endpoints, not blocking.

Zenity 23 of 76

Zenity Labs contributed several of these techniques to ATLAS; that research is not a product claim and nothing here was scored from it. Zenity's product pages state the capability in a section heading and the attack behaviour in the card beneath, so several quotes below read as a description of the attack rather than as the assertion — the assertion is the line above them on the same page. Its solution briefs are gated PDFs and were not read.

Cycode 10 of 76

Cycode's product documentation is behind a login, so every cell here comes from marketing pages and the official blog. It is the vendor in this table most likely to be under-counted for that reason.

  • AML.T0132 — Prevent excessive permissions and misconfigurations of AI agents and technologies in the ADLC.
    https://cycode.com/adlc-security/ (read 2026-09-20)
  • AML.T0051 — LLM injection risks, exposed AI API keys, vulnerable AI dependencies, and unsafe AI integrations
    https://cycode.com/ai/ (read 2026-09-20)
  • AML.T0053 — Block or warn on MCP tool calls that contain secrets or violate your security policies.
    https://cycode.com/ai/ (read 2026-09-20)
    Limit: Enforced at the IDE and CLI boundary via hooks, stated for two assistants, with others on the roadmap.
  • AML.T0081 — Inspect what each rule file contains and understand how it influences AI-generated code in your environment.
    https://cycode.com/ai/ (read 2026-09-20)
  • AML.T0007 — Discover AI code assistants, models, infrastructure, MCP servers, AI secrets, and AI packages across your software factory.
    https://cycode.com/ai/ (read 2026-09-20)
  • AML.T0084 — Cycode detects the AI signals traditional security tools miss: commit metadata, AI bot users, rule files, skill files, MCP configurations
    https://cycode.com/ai/ (read 2026-09-20)
  • AML.T0057 — Scan outbound prompts for secrets, sensitive data patterns, and policy violations in real time.
    https://cycode.com/ai/ (read 2026-09-20)
    Limit: Enforced at the IDE and CLI boundary via hooks, stated for two assistants, with others on the roadmap.
  • AML.T0086 — Tool execution is blocked before anything leaves the IDE
    https://cycode.com/blog/ai-guardrails-real-time-ide-security/ (read 2026-09-20)
    Limit: Enforced at the IDE and CLI boundary via hooks, stated for two assistants, with others on the roadmap.
  • AML.T0083 — Model Context Protocol server connections and AI API keys embedded across repos.
    https://cycode.com/ai/ (read 2026-09-20)
  • AML.T0098 — Intercept file reads that would expose credentials, PII, or confidential configuration to external AI services.
    https://cycode.com/ai/ (read 2026-09-20)
    Limit: IDE-boundary control framed as data-leak prevention rather than adversary detection; enforced where Cycode AI Guardrails hooks are installed.
Bifrost Edge 7 of 76

Bifrost is published under Maxim AI; getbifrost.ai redirects there. Its own FAQ routes injection and jailbreak detection to third-party guardrail providers rather than a native detector, so read those two cells as an integration surface. Its image cell rests on content-safety filtering rather than on detecting instructions hidden in an image.

  • AML.T0051 — Catch indirect attacks hidden inside tool results or retrieved content
    https://www.getmaxim.ai/ai-guardrails (read 2026-09-20)
    Limit: Bifrost's own FAQ routes injection and jailbreak detection to third-party providers; the native checks are secret, PII and custom-regex scanning plus an LLM-as-judge.
  • AML.T0053 — you can create a strict allow-list of MCP clients and tools, ensuring that only approved tools can be executed
    https://docs.getbifrost.ai/features/governance/mcp-tools (read 2026-09-20)
    Limit: Enforcement is a gateway allow-list; Bifrost states it does not execute the tool call itself.
  • AML.T0054 — Stop injection and jailbreak attempts before they reach your model
    https://www.getmaxim.ai/ai-guardrails (read 2026-09-20)
    Limit: Bifrost's own FAQ routes injection and jailbreak detection to third-party providers; the native checks are secret, PII and custom-regex scanning plus an LLM-as-judge.
  • AML.T0084 — Edge reads the MCP configuration of supported AI apps on each machine and builds a live inventory
    https://docs.getbifrost.ai/edge/mcp-governance (read 2026-09-20)
  • AML.T0057 — Redact emails, SSNs, financial, and medical data before they leave your gateway
    https://www.getmaxim.ai/ai-guardrails (read 2026-09-20)
  • AML.T0077 — Each prompt is inspected before it reaches a model, and each response before it reaches a user
    https://www.getmaxim.ai/ai-guardrails (read 2026-09-20)
  • AML.T0034 — Bifrost’s budget management system provides comprehensive cost control and financial governance for enterprise AI deployments.
    https://docs.getbifrost.ai/features/governance/budget-and-limits (read 2026-09-20)
Ent 0 of 76

Ent's public material contains no occurrence of prompt injection, jailbreak, system prompt, MCP, tool call, poisoning, hallucination or rug pull. It sells insider risk, endpoint data protection and shadow-AI usage control. A zero here is the honest reading of that material against this framework, not an incomplete review.

Nothing in the material read on 2026-09-20 describes coverage for any of these 76 techniques, so every cell is not described. That is a statement about the documentation, not about the product.

Endor Labs 18 of 76

Endor Labs states in its own documentation that these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open. Several cells rest on documentation tables that render client-side.

  • AML.T0018 — Catch unsafe file formats like pickle and unverified PyTorch that can execute code when a model loads.
    https://www.endorlabs.com/use-case/ai-model-governance (read 2026-09-20)
  • AML.T0060 — Catch hallucinated, typosquatted, and known-malicious packages before the agent runs npm install.
    https://www.endorlabs.com/solutions/ai-code-security (read 2026-09-20)
  • AML.T0115 — Models that could be impersonating popular models receive lower scores
    https://docs.endorlabs.com/secure-ai-coding/ai-model-scores (read 2026-09-20)
  • AML.T0010 — Endor Labs combines visibility into coding agents and their AI supply chain with runtime policy enforcement through native hooks.
    https://www.endorlabs.com/use-case/coding-agent-governance (read 2026-09-20)
  • AML.T0132 — Examples of what is checked: TLS enforcement, certificate validation, public network binding.
    https://docs.endorlabs.com/agent-governance/endor-score/index.md (read 2026-09-20)
    Limit: Static, source-and-configuration only — live runtime probes are disabled, so an exposed server is inferred from published source, not observed. Transport and Network Security is one of the three dimensions that contribute findings without a per-dimension score. Blocking depends on an MCP Server Posture policy, which is a guardrail, not a security boundary; enforcement fails open.
  • AML.T0011 — Package Firewall blocks malicious packages before a developer or AI agent ever runs the install.
    https://www.endorlabs.com/use-case/malicious-package-detection (read 2026-09-20)
  • AML.T0051 — Examples of what is checked: Prompt injection, boundary violations, behavioral manipulation in the skill body.
    https://docs.endorlabs.com/agent-governance/endor-score/index.md (read 2026-09-20)
    Limit: Source-only: an LLM workflow reads the SKILL.md captured at session start and scores it; skills are never executed and there is no runtime prompt inspection (Endor states it frames security "around the agent's actions, not just its prompts"). Enforcement via a Skill Access policy is a guardrail, not a security boundary, and enforcement fails open.
  • AML.T0053 — Use this template to govern which MCP servers and tools your agents can call.
    https://docs.endorlabs.com/agent-governance/policies (read 2026-09-20)
    Limit: Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.
  • AML.T0081 — Stops the agent loosening its own guardrails
    https://docs.endorlabs.com/agent-governance/policies.md (read 2026-09-20)
    Limit: A shipped policy row: it blocks writes to the agent's own settings and hooks, while reads are allowed. Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.
  • AML.T0110 — Tool descriptions or inputs that allow instruction override.
    https://docs.endorlabs.com/agent-governance/endor-score.md (read 2026-09-20)
    Limit: Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.
  • AML.T0109 — Endor Labs re-scores a server when its configuration changes, for example a new command, endpoint, transport, or environment variable name.
    https://docs.endorlabs.com/agent-governance/endor-score (read 2026-09-20)
    Limit: Re-scoring on change is the defence, but the rug-pull behaviour itself is never described. Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.
  • AML.T0084 — Review the details section: the source, server type, host, transport, launch command, available tools, and environment variable names.
    https://docs.endorlabs.com/agent-governance/inventory (read 2026-09-20)
    Limit: Inventory/visibility only. The system policy that guards agent configuration blocks writes, edits and deletes but explicitly allows reads, so discovery of the configuration itself is not blocked. Guardrails, not a security boundary; enforcement fails open.
  • AML.T0133 — See every agent, model, MCP server, and skill running across developer workstations and cloud.
    https://www.endorlabs.com/solutions/ai-code-security (read 2026-09-20)
  • AML.T0086 — CmdLine: block network exfiltration tools
    https://docs.endorlabs.com/agent-governance/policies.md (read 2026-09-20)
    Limit: The name of a shipped system policy rather than a described capability. Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.
  • AML.T0101 — Block destructive shell commands and risky MCP tool calls
    https://www.endorlabs.com/use-case/coding-agent-governance (read 2026-09-20)
    Limit: Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.
  • AML.T0112 — catches malware before it appears in public databases, protecting developer machines and CI pipelines
    https://www.endorlabs.com/use-case/malware-detection (read 2026-09-20)
  • AML.T0083 — Missing or weak authentication, secrets exposed in environment variables or source.
    https://docs.endorlabs.com/agent-governance/endor-score.md (read 2026-09-20)
    Limit: A scoring dimension rather than an enforced block. Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.
  • AML.T0098 — Block destructive shell commands, credential reads, and risky tool calls at the hook layer
    https://www.endorlabs.com/solutions/ai-code-security (read 2026-09-20)
    Limit: Endor states these agent-governance controls are guardrails for accidental agent behaviour rather than a hard security boundary, and that enforcement fails open.
Certiv 14 of 76

Certiv is unusually explicit about what has not shipped. Its context-aware decision engine, divergence detection, pre-load MCP inventory and session-start config scanning are all labelled roadmap or not enforced today, and none of them is counted here — which is why Certiv scores nothing for discovering or protecting agent configuration.

  • AML.T0093 — Flag prompt injection in emails, docs, shell output
    https://certiv.ai/openclaw/ (read 2026-09-26)
  • AML.T0132 — Certiv Scout finds AI agents and local model runtimes on every endpoint, including Ollama, LM Studio, llama.cpp servers, and other local services.
    https://certiv.ai/local-models/ (read 2026-09-20)
  • AML.T0011 — Blocks adding a new external dependency (npm install, pip install, go get, cargo add, or a manifest edit) that the user did not explicitly ask for.
    https://certiv.ai/ai-agent-security-policies/ (read 2026-09-20)
    Limit: The gate is "the user did not explicitly ask for it", not a malware verdict — Certiv makes no claim to identify a package as malicious, and a dependency the user does request is not checked. Semantic (model-judged) check; action is tunable per enrollment.
  • AML.T0051 — Detect agents acting on injected instructions that override intended behavior.
    https://certiv.ai/product/ (read 2026-09-20)
  • AML.T0053 — Certiv intercepts the agent's proposed tool call and evaluates it before it executes.
    https://certiv.ai/ai-agent-security-policies/ (read 2026-09-20)
  • AML.T0103 — Blocks running a known AI agent CLI, including bare-name, path-qualified, npx, and detached-wrapper forms like nohup, tmux, screen, and setsid.
    https://certiv.ai/ai-agent-security-policies/ (read 2026-09-20)
  • AML.T0080 — Memory segmentation + context integrity checks + session isolation + drift detection on stored state
    https://certiv.ai/security-teams/ (read 2026-09-20)
  • AML.T0099 — Treat tool output and repo text as untrusted
    https://certiv.ai/openclaw/ (read 2026-09-20)
  • AML.T0110 — Certiv authorizes each MCP tool call against policy on the endpoint today
    https://certiv.ai/coding-agents/ (read 2026-09-20)
  • AML.T0068 — Catches obfuscated attacks and hidden-text injection that regex misses.
    https://certiv.ai/coding-agents/ (read 2026-09-20)
  • AML.T0086 — Blocks a tool call only when it actually transmits sensitive data (secrets, keys, .env contents, proprietary source) outbound to a remote host.
    https://certiv.ai/ai-agent-security-policies/ (read 2026-09-20)
  • AML.T0034 — See abnormal token usage, set budgets, and protect against runaway sessions.
    https://certiv.ai/blog/token-spend-signal-rogue-agent/ (read 2026-09-20)
    Limit: Certiv states this capability is in public preview.
  • AML.T0101 — Blocks irreversible destruction in any phrasing: rm -rf, git push --force, DROP TABLE, TRUNCATE, unbacked overwrites, and volume purges.
    https://certiv.ai/ai-agent-security-policies/ (read 2026-09-20)
  • AML.T0098 — Blocks reads of credentials from environment variables, tool calls that read or modify .env, ~/.ssh, ~/.aws, ~/.kube, ~/.gnupg, or ~/.docker
    https://certiv.ai/ai-agent-security-policies/ (read 2026-09-20)
Backslash Security 14 of 76

No public documentation site exists; every cell comes from Backslash's own marketing pages plus one official GitHub README.

Kitecyber 4 of 76

Kitecyber's blog is largely third-party-sourced and its FAQ hedges several claims; only unhedged first-person product copy was scored. One cell was removed because neither “MCP” nor “Model Context Protocol” appears anywhere on its site, so the credit had no supporting evidence. Its case study and comparison datasheets are behind a form.

  • AML.T0051 — Allow approved actions while automatically blocking unauthorized data access, risky transfers, and prompt injection attempts.
    https://www.kitecyber.com/ai-security/ (read 2026-09-20)
  • AML.T0084 — The endpoint agent inventories every AI agent and the skills it loads.
    https://www.kitecyber.com/ai-security/ (read 2026-09-20)
    Limit: Inventory of agent configuration and loaded skills; not runtime enforcement.
  • AML.T0085 — Know the moment an agent touches sensitive data on the endpoint — PII, source code, secrets, financial or regulated records.
    https://www.kitecyber.com/ai-security/ (read 2026-09-20)
    Limit: Endpoint-local detection/alerting on agent access to sensitive data; no RAG-database coverage.
  • AML.T0086 — Stop sensitive data from being exfiltrated off the device by an agent in real time
    https://www.kitecyber.com/ai-security/ (read 2026-09-20)
Straiker 22 of 76

Straiker's product documentation sits behind a login and was not read. Its published attack-coverage matrix lists further techniques as single-cell labels with no prose, so they carry no quotable claim and are not counted here — real coverage that the evidence rule cannot admit.

  • AML.T0118 — Straiker secures multi-agent systems by monitoring agent-to-agent communication and tool-delegation chains.
    https://www.straiker.ai/solution/custom-built-agents (read 2026-09-20)
  • AML.T0010 — Defend AI identifies malicious, poisoned, or vulnerable MCP servers in real time using Straiker's MCP Threat Database, helping prevent supply chain attacks and unauthorized data access.
    https://www.straiker.ai/products/defend-ai (read 2026-09-20)
  • AML.T0132 — Detect over-permissioned agents, risky MCP connections, and misconfigured integrations across your full agentic ecosystem.
    https://www.straiker.ai/products/discover-ai (read 2026-09-20)
  • AML.T0051 — it inspects every prompt, reasoning step, and tool call to stop prompt injection, data exfiltration, and agent manipulation in real time
    https://www.straiker.ai/products/defend-ai (read 2026-09-20)
  • AML.T0053 — Defend AI enforces runtime guardrails on every tool call, blocking unauthorized actions and data exfiltration at 98%+ accuracy and low latency.
    https://www.straiker.ai/solution/mcp-security (read 2026-09-20)
    Limit: Blocking requires the inline deployment; other deployments are documented as detection only.
  • AML.T0100 — Keep agents on approved domains and workflows, intercepting redirects, shortlinks, and iframe handoffs that could steer sessions toward untrusted or malicious destinations.
    https://www.straiker.ai/solution/runtime-guardrails-for-agentic-web-browsers (read 2026-09-20)
  • AML.T0103 — Straiker's Discover AI maps every agent, tool connection, and MCP integration so security teams can detect unknown agents, shadow deployments, and unauthorized access paths.
    https://www.straiker.ai/products/discover-ai (read 2026-09-20)
    Limit: Discovery/inventory of unknown and shadow agent deployments; containment is a separate product (Agentic Kill Switch).
  • AML.T0080 — It detects and blocks identity abuse, memory poisoning, data exfiltration, and resource exploitation at runtime, without slowing down the agents your business depends on.
    https://www.straiker.ai (read 2026-09-20)
  • AML.T0081 — It can detect and block actions such as file deletion and configuration changes while protecting proprietary code and secrets in development environments.
    https://www.straiker.ai/products/defend-ai (read 2026-09-20)
  • AML.T0099 — Defend AI detects data exfiltration across SaaS applications, blocks prompt injection delivered through enterprise content like emails and documents, and surfaces unapproved agent usage.
    https://www.straiker.ai/products/defend-ai (read 2026-09-20)
  • AML.T0110 — enforces runtime policy to stop tool poisoning, malicious skills, rug pulls, output injection, and unauthorized actions
    https://www.straiker.ai/solution/mcp-security (read 2026-09-20)
  • AML.T0054 — Straiker monitors every step at runtime by catching jailbreaks, enforcing safe tool use, and flagging compliance gaps.
    https://www.straiker.ai/products/defend-ai (read 2026-09-20)
  • AML.T0109 — Ascend AI continuously red-teams your MCP connections, testing for tool poisoning, rug pulls, and privilege escalation.
    https://www.straiker.ai/solution/mcp-security (read 2026-09-20)
    Limit: From red-team testing, which probes for this rather than enforcing against it at runtime.
  • AML.T0129 — Detect threats hidden in text, code, images, audio, and file uploads that single-mode tools miss.
    https://www.straiker.ai/products/defend-ai (read 2026-09-20)
  • AML.T0133 — Uncover MCP servers & Claude Skills connected to your agents and map how they extend agent capabilities
    https://www.straiker.ai/products/discover-ai (read 2026-09-20)
  • AML.T0056 — Runtime AI guardrails address both non-agentic risks like prompt injection, system prompt leaks, harmful or toxic content, and data exfiltration
    https://www.straiker.ai/solution/guardrails (read 2026-09-20)
  • AML.T0057 — Defend AI uses semantic detection to identify data exfiltration attempts across all agent types.
    https://www.straiker.ai/products/defend-ai (read 2026-09-20)
  • AML.T0086 — Straiker blocks destructive actions, data exfiltration of company secrets, and malicious MCP connections at runtime.
    https://www.straiker.ai/products/defend-ai (read 2026-09-20)
  • AML.T0029 — Denial-of-service patterns including excessive API calls, infinite loops, and compute abuse that drain system resources.
    https://www.straiker.ai/solution/genai-and-agentic-ai-threat-detection (read 2026-09-20)
  • AML.T0048 — Detect and suppress application drift, toxic output, and policy violations before they reach users or downstream systems.
    https://www.straiker.ai/products/defend-ai (read 2026-09-20)
  • AML.T0101 — Straiker detects and blocks data exfiltration, remote code execution, destructive infrastructure actions, tool misuse, and resource exhaustion in real time.
    https://www.straiker.ai/solution/coding-agents (read 2026-09-20)
  • AML.T0112 — Straiker detects the injection path and blocks the action at runtime, before code runs.
    https://www.straiker.ai/anthropic-claude (read 2026-09-20)
MIND 4 of 76

MIND publishes its own scope boundary and it is honoured here over its adjacent marketing: “Instead of securing models or reacting to outputs, MIND ensures sensitive data is understood, governed and protected before any AI agent can access or act on it”, and, on an autonomous-agent breach post, “MIND doesn’t patch template-injection flaws or contain a sandbox escape. No data loss prevention platform does.” It is a data loss prevention and insider-risk platform, so most of this framework is not its subject: on /solutions/secure-agentic-ai, its most agentic page, “prompt injection”, “jailbreak”, “MCP” and “tool call” each occur zero times against 93 occurrences of “agent”. The low count is not a thin-corpus artefact — 184 pages and roughly 174,000 words were read, a corpus comparable to vendors scoring four times higher. A strongly worded agentic sentence on its newsroom page was left uncredited because it is Frost & Sullivan’s prose republished by MIND, not MIND’s own claim.

  • AML.T0103 — Continuously discover which AI agents are running across your environment, including embedded SaaS capabilities, custom-built agents and third-party tools.
    https://mind.io/solutions/secure-agentic-ai (read 2026-09-20)
    Limit: Inventory and visibility only — shadow-agent discovery, not detection of an adversary launching an agent.
  • AML.T0085 — See what data AI agents interact with and how it’s used, so sensitive information stays protected and aligned with policy.
    https://mind.io/solutions/secure-agentic-ai (read 2026-09-20)
    Limit: Visibility of what data agents reach, from the data side (endpoint agent, browser extension, SaaS connectors); no claim to inspect RAG retrievals or agent tool results.
  • AML.T0057 — With the lightweight endpoint agent and browser extension, MIND can protect sensitive data across GenAI tools, from prompt to response.
    https://mind.io/solutions/data-source-genai (read 2026-09-20)
  • AML.T0086 — When sensitive data starts moving somewhere it shouldn’t, whether at rest or in motion, MIND blocks the exfiltration in real time instead of filing an alert for the morning queue.
    https://mind.io/blog/hugging-face-breach-autonomous-ai-agent-dlp (read 2026-09-20)
    Limit: Egress data-loss control at the endpoint, browser and SaaS layer; MIND nowhere claims to intercept or evaluate an agent tool call itself.
WitnessAI 14 of 76

WitnessAI is first a network-layer governance product for employee and agent AI use: discovery against a catalogue of 4,000+ apps, intent-based policy, tokenisation, model routing and AI FinOps. Most of that has no adversary-technique row in this set, so a large share of its marketing earns nothing here. Its cells come from Witness Protect, an AI firewall for prompts and responses; Agentic Control, an approved-list of MCP servers and tools that it says is enforced before a call executes, launched 17 June 2026; and Witness Attack, pre-deployment red teaming, whose cells are bounded. WitnessAI scopes its own agent protection to “supported agent workflows” and to “traffic governed through the platform”, and that limit is carried on the tool-invocation cell. Its product documentation at docs.witness.ai is password-protected. All 191 pages in its sitemap returned a password form, so nothing was scored from them. The page titles alone suggest that Witness Anywhere installs a binary through Intune, Jamf, GPO or EDR, while the marketing says “no endpoint clients”. That is unverified. Several recurring claims were not credited. Tokenising credentials in prompts is usage DLP, not an agent harvesting credentials. “Hallucinated outputs” is output quality, not an adversary. A sentence about indirect injection in emails and documents describes no mechanism beyond the prompt-injection detection already counted. Read 2026-09-27: the full marketing sitemap (about 310 pages, mostly blog posts) plus 10 first-party PDFs.

  • AML.T0118 — It sits between users and AI applications to observe, classify, and enforce policy on prompts, responses, tool calls, and inter-agent activity in real time.
    https://witness.ai/blog/multi-agent-security/ (read 2026-09-27)
  • AML.T0010 — Once those tools are visible, the new MCP Catalog scores each against OWASP and CVE risk classes, so the team weighs a server’s exposure and approves it on evidence rather than a name.
    https://witness.ai/blog/introducing-witnessai-agentic-control-one-control-plane-for-every-agent-tool-and-mcp-server/ (read 2026-09-27)
  • AML.T0051 — Detect and mitigate prompt injections, jailbreaks, and other AI-specific threats before they compromise your business.
    https://witness.ai/protect/ (read 2026-09-27)
  • AML.T0053 — Govern every form of agent deployment, from custom cloud agents to agentic IDEs, with enforcement at the tool call and MCP server level.
    https://witness.ai/control/ (read 2026-09-27)
    Limit: An approved-list control: WitnessAI describes it as denying MCP servers and tools that are off the list before they execute, not as judging what an approved tool is asked to do. WitnessAI itself scopes it to “traffic governed through the platform” and, on its home page, to “supported agent workflows”.
  • AML.T0103 — Scan your entire network for third-party AI applications and agents for complete visibility into AI adoption and risk exposure across your human and digital workforce.
    https://witness.ai/observe/ (read 2026-09-27)
    Limit: Network-level shadow-AI and shadow-agent discovery; inventory, not detection of an adversary launching an agent.
  • AML.T0110 — Witness Attack —proactive testing before deployment, which validates that MCP server integrations don’t introduce tool poisoning, injection, or over-privilege risks before they reach production.
    https://witness.ai/blog/mcp-server-security/ (read 2026-09-27)
    Limit: From pre-deployment red teaming (Witness Attack), which tests for tool poisoning rather than enforcing against it at runtime.
  • AML.T0054 — WitnessAI’s Model Protection Guardrail directly addresses this challenge by detecting jailbreak attempts at every stage of the adversarial process
    https://witness.ai/blog/closing-the-loop-how-witnessai-stops-reasoning-leakage-jailbreaks-at-every-phase/ (read 2026-09-27)
  • AML.T0068 — By analyzing the intent behind the prompt, WitnessAI ensures that even obfuscated or indirect attacks are detected.
    https://witness.ai/wp-content/uploads/2024/12/WIT-24-010_Model-Protection-Guardrail-Solutions-Brief.pdf (read 2026-09-27)
  • AML.T0129 — Using multimodal attack vectors, multi-step jailbreaks, and reinforcement-learning techniques, our AI red teaming stress-tests your model defenses and provides actionable insights for hardening.
    https://witness.ai/protect/ (read 2026-09-27)
    Limit: From pre-deployment red teaming (Witness Attack), which probes with multimodal attacks rather than inspecting multimodal inputs at runtime; no runtime multimodal inspection is claimed.
  • AML.T0133 — Discover which agents are running and what external MCP servers and tools they connect to
    https://witness.ai/ (read 2026-09-27)
  • AML.T0057 — Response protection inspects what comes back, catching harmful content and leaked secrets on the way out.
    https://witness.ai/blog/prompt-injection-mitigation-strategies/ (read 2026-09-27)
  • AML.T0086 — Prevent coding agents from exposing proprietary code when calling external tools.
    https://witness.ai/for-developers/ (read 2026-09-27)
  • AML.T0034 — Stop consumer abuse of B2C AI apps for non-profitable prompts.
    https://witness.ai/for-finops/ (read 2026-09-27)
    Limit: Framed as AI FinOps spend control — blocking or rerouting prompts classified as non-productive — rather than detection of deliberate cost harvesting.
  • AML.T0048 — Filter harmful responses before end users see them
    https://witness.ai/ (read 2026-09-27)
Lasso Security 23 of 76

Lasso's product documentation, a GitBook, redirects to a login and was not read. Everything here comes from its marketing site, blog, three first-party PDFs and its open-source GitHub repositories. Two cells come from the open-source MCP Gateway rather than the commercial platform and carry that scope as a limit. Lasso's open-source Claude Code hook states that it “warns but does not block”. That is honoured as the scope of that tool and is not assumed of the enterprise hook deployment, which Lasso says flags or blocks. Lasso publishes its own OWASP and MITRE ATLAS mapping of its policies in a PDF titled Compliance and Threats Mapping. As with badge-style mappings elsewhere, the technique IDs there carry no product prose. No cell was scored from the mapping itself, only from one policy description that has a sentence of its own. Red-team reconnaissance that “extracts the system prompt” and identifies the underlying model was not counted, because it is attack targeting, not a finding or a defence. A 2025 blog attributes memory isolation to an MCP Gateway plugin that the gateway's own README does not list, so that claim was not used. Read 2026-09-27: the full sitemap (282 pages, 4 of them 404), 3 PDFs and 3 GitHub READMEs.

Pillar Security 26 of 76

Pillar documents more of this framework in its own words than any vendor reviewed so far, and most of it sits in first-party blog announcements rather than on its product pages. Its documentation site is behind a login and was not read, so the mechanics behind these claims (how the endpoint sensor intercepts a tool call, what reaches Pillar's cloud) are stated only at marketing depth. About 350 pages were read on 27 September 2026: product and solution pages, all 135 blog posts and the research pages. The 92 SAIL framework pages and 73 risk-glossary pages are Pillar's open framework, not product claims, and nothing was scored from them; neither was its vulnerability research, the Frost & Sullivan and Latio analyst prose it quotes, or single-cell labels. Red-team findings are credited only as bounded cells, and inventory as bounded cells. A homepage alert about an agent pulling 2,300 customer emails from Agentforce was not scored as data collection, because Pillar itself labels it exfiltration, which is already credited.

Permiso 9 of 76

Permiso sells identity threat detection and response and now carries an Okta banner. It treats AI agents as another class of identity, and it says so plainly: it argues against prevention by guardrails and calls for runtime visibility and containment. It also describes model-layer concerns such as prompt injection as not where most enterprise AI incidents will start. Its coverage is therefore identity-layer and log-based. It attributes agent runs and tool calls to identities, detects anomalies, revokes access with a kill switch, and sandboxes skills in SandyClaw. It makes no claim to inspect prompts or tool arguments before they execute. About 190 pages were read on 27 September 2026: product and solution pages, 107 blog posts and the resource library. The documentation site is password-protected and was not read. Nothing was scored from P0 Labs research, including its LLMjacking, Copilot cross-prompt-injection and malicious-skill work. Its sentence that detections are built on prompt injection observed in the wild names where its detections come from, not a capability, so it earns no cell. The 35-plus exposure table mapped to OWASP (entries such as agent self-modification and agent can disable logs) is single-cell labels with no prose, so it is not counted.

  • AML.T0118 — Session-level evidence and runtime data provide forensic trails for understanding how identities interact across agent networks.
    https://permiso.io/blog/8-critical-ai-security-challenges (read 2026-09-27)
    Limit: A forensic trail of the identity and authorisation chain between agents. No detection is described, and the content agents pass to one another is not inspected.
  • AML.T0132 — Permiso analyzes your AI infrastructure and agents for key security issues, including over-permissioning, weak authentication controls, and configuration vulnerabilities.
    https://permiso.io/blog/permiso-delivers-complete-ai-security-through-unified-identity-platform (read 2026-09-27)
  • AML.T0011 — SandyClaw runs every skill in a controlled sandbox before it touches your environment, recording every action, every tool call, every downstream request.
    https://permiso.io/ai-security (read 2026-09-27)
  • AML.T0053 — Permiso detects over-privileged access, unused permissions, anomalous tool usage, policy violations, and high blast radius behavior in real time.
    https://permiso.io/blog/ai-agent-runtime-security (read 2026-09-27)
    Limit: Anomaly detection on tool calls attributed from logs to an identity. The stated response is an identity-layer kill switch once behaviour crosses a threshold. Permiso does not claim to evaluate a call before it runs, and it argues against prevention by guardrails.
  • AML.T0103 — If a developer's account that normally works on a specific project suddenly attempts privilege escalation or spawns unexpected sub-agents, the system flags the behavior immediately.
    https://permiso.io/blog/8-critical-ai-security-challenges (read 2026-09-27)
  • AML.T0007 — Permiso inventories every AI agent, sub-agent, builder, model, and user across cloud, SaaS, IdPs, and code environments, including agents running in Lambdas, containers, and VMs that traditional identity tools cannot see.
    https://permiso.io/blog/ai-agent-runtime-security (read 2026-09-27)
    Limit: Inventory and discovery rather than enforcement against an adversary enumerating these artefacts.
  • AML.T0084 — Permiso models AI identities explicitly: tracking which agents have access to which tools and data
    https://permiso.io/resources/why-siem-isnt-enough-for-identity-security (read 2026-09-27)
    Limit: An inventory of which tools and data each agent can reach. It does not detect an adversary who is enumerating agent configuration.
  • AML.T0085 — When an agent starts accessing production data it has never touched before, or connects to an MCP server outside its normal pattern, the kill switch stops the session before the blast radius expands.
    https://permiso.io/blog/ai-agent-runtime-security (read 2026-09-27)
    Limit: Keyed to first-time data access against the agent's own baseline, and answered at the identity layer. Permiso does not inspect what is retrieved.
  • AML.T0048 — We also detect suspicious and malicious activity in your LLM instances by monitoring your prompt logs to detect LLM hijacking quickly.
    https://permiso.io/llm-hijacking-monitoring (read 2026-09-27)
    Limit: Covers LLMjacking only, meaning unauthorised use of the customer's own hosted LLM instances. ATLAS's LLM Jacking case study (AML.CS0030) maps that to the financial-harm sub-technique. Harmful-content output is not addressed.
Above Security 2 of 76

Above Security sells an AI-native insider-risk platform: AI investigative agents that build cases for security, HR and legal teams from identity, SaaS, endpoint, cloud and AI-tool connectors, plus real-time coaching of employees. Its research group, Above Theory, co-authored the Synthetic Insider Threat Matrix with Forscie. It works after the fact and through APIs: its Claude integration reads Claude activity, including Claude Code session transcripts, hourly and read-only from Anthropic's Compliance API, and Above states that no enforcement action is taken autonomously on an AI verdict. A joint brief with CrowdStrike assigns stopping a hijacked agent at runtime to the endpoint product, not to Above. About 70 pages were read on 1 October 2026: the whole sitemap, with about 30 read in full, plus three first-party PDFs and its GitHub plugin. The customer portal and trust center are behind a login and were not read. Not credited: the Claude integration's tool-call records (AML.T0053), because recording every tool call is not detecting or stopping one; the prompt-injection screen in the same guide, which protects Above's own analysis rather than the customer's agents; the personal-AI, custom-GPT and credential-leak pages, which govern how employees use AI rather than an adversary's technique; and research write-ups, including the matrix itself.

  • AML.T0103 — Above's investigative agents observe the consent screen, the scopes requested, and the vendor on the other end — so a grant to a vendor outside your approved list reaches the security team in minutes, not next quarter's access review.
    https://www.above.security/agentic-ai (read 2026-10-01)
    Limit: Visibility and alerting on OAuth consent grants to third-party AI agents, routed to the security team for an allow-or-revoke decision. Not prevention, and not agents launched on a device. Above says no enforcement action is taken autonomously on an AI verdict.
  • AML.T0086 — When an autonomous agent reproduces a confidential file on its vendor's servers, the investigation ties the reproduction back to the consent that enabled it — so the exfiltration is attributable to the employee, the agent, the consent, and the file, not to “an AI tool somewhere.”
    https://www.above.security/agentic-ai (read 2026-10-01)
    Limit: After-the-fact investigation and attribution of data that an OAuth-scoped third-party agent has already reproduced off-site. Above does not claim to intercept or evaluate the agent's tool calls.
Rig Security 2 of 76

Rig Security sells an identity security platform for people, non-human identities and AI agents: agentless connectors build one identity graph across systems such as Okta, GitHub, Snowflake, Google Cloud and Kubernetes, and a lightweight endpoint sensor, Gatewatch, enforces policy on devices before an agent's action runs. It came out of stealth on 29 September 2026. Its decisions are keyed to identity and resource, which agent is acting through whose session and what it may reach, and it publishes no claim to inspect prompts, files or tool arguments for content. The material is thin: two product pages, about a dozen blog posts and no public product documentation. 28 pages were read on 1 October 2026, plus its GitHub organisation. Not credited: the animated Gatewatch demo strings and labels marked illustrative, which are interface, not claims; an Entra ID screenshot caption about application access, which is identity posture; and its blog's prompt-injection scenario, which explains the attack rather than claiming to detect it.

  • AML.T0053 — It can block a risky agent action before it reaches the cloud without disrupting the person whose identity the agent borrowed.
    https://www.rig.security/blog-events/why-we-started-rig-end-to-end-identity-security-platform/ (read 2026-10-01)
    Limit: Inline enforcement on endpoints running the Gatewatch sensor, keyed to which agent is acting and which identity or resource it reaches (Rig's examples are AWS production versus dev). Rig does not publicly describe inspecting prompts, files read or tool arguments for malicious content, and it publishes no product documentation.
  • AML.T0103 — It discovers agents running on devices, distinguishes their sessions from the user’s own activity, and enforces policy inline.
    https://www.rig.security/blog-events/why-we-started-rig-end-to-end-identity-security-platform/ (read 2026-10-01)
    Limit: Discovery and attribution of agents on devices where the Gatewatch sensor is deployed. This is inventory, not detection of an adversary launching an agent.
Noma Security 20 of 76

Noma Security sells an agent security platform across SaaS, homegrown and endpoint agents, including plugins that send coding-agent hook events (Claude Code, Codex, Cursor, Copilot) to its backend for evaluation. Read 2026-10-01 from noma.security product, solution and blog pages (server-rendered, read with curl). Noma documents the same native-hook path for Claude Code and Cursor that MoorAI uses, plus EDR/MDM-based endpoint discovery, so most coding-agent cells are first-party claims rather than inference. Several cells are posture or inventory findings and carry a limit. Not credited: the red-teaming list's denial-of-wallet (one sentence, one cell: it is credited to jailbreak only), 'agents drifting from their intent' (no matching technique), and research posts (ContextCrush, Cursor triple-backtick) that explain attacks. Noma states what it does not do in one place: 'Noma's job is not to scan your code for vulnerabilities.' Where hook-time content is evaluated (Noma SaaS or the customer's on-prem deployment) is not stated for the coding-agent path; the platform offers on-prem and SaaS. Product documentation is not public and was not read.

Onyx Security 7 of 76

Onyx Security sells a secure AI control plane for agents across SaaS, cloud, endpoint and code, enforcing at coding-agent hooks, an MCP proxy and AI gateway, and Anthropic's inference hooks, and recording session content for investigation. Onyx Security (onyx.security, Tel Aviv / New York; $40M launch and a $113M Series B led by Bessemer per its own blog) - not Onyx the open-source enterprise-search product (onyx.app). Read 2026-10-01. Four solution pages linked from its navigation (MCP Security, Runtime and Prompt Injection Defense, AI Discovery and Shadow AI, Agent Identity and Access Governance) returned 404 and were not read. Several cells come from customer-success and POV blog posts describing what AI Guard did in deployments, including anonymised composite cases; these are bounded. Onyx states that it maps policy to MITRE ATLAS automatically, but publishes no per-technique mapping, so that statement earns nothing here. Its MCP post lists install-time posture inspection and toolset drift as things an MCP programme 'needs' without saying in that sentence that Onyx does it; not credited. Approval routing for newly discovered tools and MCP servers is read as governance and not credited. A post built around a third-party report was skipped, as third-party content. Unlike MoorAI, Onyx records prompt, response and tool-call content (session capture with arguments and results), and ingests Claude Enterprise conversation content through the Compliance API.

Akto 21 of 76

Akto sells an agentic AI and API security platform whose endpoint connectors and hooks for coding agents such as Claude Code report to its dashboard. Read 2026-10-01: akto.io product pages (Framer; blog posts needed the browser), the public GitBook docs at ai-security-docs.akto.io (Atlas for employee endpoints, Agent Guard scanner reference, guardrail concepts), and pricing. Akto Atlas ships hooks for Claude Code, Cursor, Codex, Gemini, Copilot and others plus an MDM-deployed AI Endpoint Shield, so it competes directly on coding agents. Its Atlas Guardrails page says policies 'are evaluated locally on each device', but its Claude CLI hook docs send prompts and MCP tool calls to an Akto ingestion URL (SaaS by default, on-prem optional), and its pricing page offers a module that 'Logs every prompt, response, violation and skill call as a forensic audit trail'. Stated limits: in the Claude Code hooks, ingestion of non-MCP tool calls (Bash, Read, Edit) is off by default; the Personal Account guardrail works only through the browser extension, with Endpoint Shield support 'coming soon'; Agentic Shield for local LLM calls is 'coming soon'. A blanket pricing-page claim of 'Full coverage of OWASP Top 10 & MITRE ATLAS threats' was not credited because it names no technique. Red-team probe lists were not scored beyond the runtime cells.

HiddenLayer 14 of 76

HiddenLayer sells an AI security platform for models, supply chain, red teaming and runtime, including Agent Harness Security, a hook plug-in for coding agents such as Claude Code, Cursor and GitHub Copilot that calls its detection API. Read 2026-10-01: hiddenlayer.com platform and solution pages, the Agent Harness Security launch release (3 August 2026) and Series B release (2 September 2026), and the public docs at docs.hiddenlayer.ai (Agent Harness architecture, deployment and policy; Agentic Runtime Security; data handling). Agent Harness Security is a direct competitor on coding agents: a plug-in installs hooks for Claude Code, Cursor and Copilot CLI that call HiddenLayer's detection API (/detection/v2/claude-code/ and siblings). Its data-handling doc says Enterprise SaaS sends 'Detection data, including prompts and responses' through the API, while Hybrid can keep prompts and responses local and Self-Hosted sends nothing out. Stated limits: 'Not every gate point can enforce every action'; post-action gates are visibility only; Copilot CLI prompt submission is visibility only; Agentic Runtime Security 'may not be enabled for your tenant yet'. Not credited: model genealogy and 'detect corruption across layers and tensors' (integrity checking, not clearly AML.T0076), and 'Model Exfiltration & Data Leakage Testing', whose sentence describes probing for PII extraction rather than model theft.

Virtue AI 6 of 76

Virtue AI sells a multimodal agent-security suite whose AgentSuite-Blue reaches desktop agents such as Claude Code and GitHub Copilot through hooks or its gateway. Virtue AI was acquired by Fortinet (Fortinet press release, 17 August 2026; terms not disclosed, 'immaterial to Fortinet's business'). Read 2026-10-01 from virtueai.com, docs.virtueai.com (JavaScript-rendered; read in a browser) and Fortinet's release. The AgentSuite-Blue docs state that it protects desktop agents 'e.g., Claude Code, GitHub Copilot, AMP agents' via hooks or its gateway. One cell (prompt injection) comes from the AgentSuite-Red red-teaming page and describes testing only; the runtime Prompt Guard is described in the docs only as detecting 'potentially malicious prompts', which does not name the technique. The sensitive-data cell is from Fortinet's own release describing the acquired guardrails. The release also credits FortiAIGate (a separate, pre-existing Fortinet product) with prompt-injection, data-leakage, model-poisoning and resource-consumption defences; those are not credited to Virtue. Shadow AI (endpoint discovery and session trajectory reconstruction, EDR integration) was read as governance and not credited. Third-party report content quoted on the Virtue site and in the Fortinet release was not used.

  • AML.T0051 — An adversarial red-teaming agent equipped with diverse red teaming algorithms probes your agents under both direct and indirect prompt-injection threat models, drawing on a library of reusable attack skills.
    https://www.virtueai.com/agentsuite-red (read 2026-10-01)
    Limit: Red-team testing (AgentSuite-Red), not a runtime prompt-injection control.
  • AML.T0053 — It can detect potentially malicious tool calls based on the agent execution history and block the malicious tool calls before they are executed.
    https://docs.virtueai.com/virtueagent/ (read 2026-10-01)
  • AML.T0081 — Skill Guard statically scans agent skills, analyzing their contents to detect malicious instructions and injected prompts before the skill is loaded by an agent.
    https://docs.virtueai.com/virtueagent/ (read 2026-10-01)
  • AML.T0110 — For connected MCPs and APIs, MCP Guard statically scans the tool descriptions of all the tools and detects the tools with injected prompts.
    https://docs.virtueai.com/virtueagent/ (read 2026-10-01)
    Limit: Static scan of tool descriptions (definition), plus optional code scanning for vulnerabilities; not a runtime check of tool responses.
  • AML.T0054 — Fast text guardrail covering violence, hate, PII exposure, jailbreaks, and 12+ harm categories in 100+ languages.
    https://www.virtueai.com/virtueguard (read 2026-10-01)
  • AML.T0057 — Enforces customizable policies across text, images, video, audio, and AI-generated code to prevent harmful content, sensitive data, jailbreaks, and vulnerable code from reaching users or downstream systems.
    https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2026/fortinet-advances-continuous-ai-protection-with-the-acquisition-of-virtue-ai (read 2026-10-01)
    Limit: Fortinet's description of Virtue AI's real-time guardrails in its acquisition release; the jailbreak claim in this sentence is not counted again.
NeuralTrust 19 of 76

NeuralTrust sells a gateway-first agent security platform with hook plugins for coding agents that send each event to its TrustGuard evaluator. Read 1 October 2026: about 310 English pages of neuraltrust.ai (product pages, 239 blog posts, news, guides, llms.txt and llms-full.txt) plus the README of the NeuralTrust GitHub plugins for Claude Code and Gemini CLI. The Spanish mirror and the 100+ glossary entries were not scored. docs.neuraltrust.ai was not read. Attack-family names listed on the threat-detection and red-teaming pages without a sentence (Obfuscation & Token Smuggling, PDF Metadata Injection and so on) were not scored as cells. The model performance report states its own limits: the benchmark was built to NeuralTrust's taxonomies (a home-field advantage it acknowledges), the indirect-injection model was scored only on an English held-out split of its own corpus, and browser-agent page injections are its weakest slice. NeuralTrust's comparison post states that it needs no endpoint agent and enforces at the traffic layer, although its GitHub publishes hook plugins for Claude Code, Codex, Cursor and Gemini CLI that send each event to a TrustGuard evaluate endpoint. Echo Chamber and Semantic Chaining are NeuralTrust attack research; the research itself was not scored. Its model scanner earns one cell, AML.T0018; the same page's supply-chain sentence describes the same scanner and is not counted again under AML.T0010.

  • AML.T0018 — Detect corrupted models, poisoned tensors, and unsafe serialization artifacts that signal hidden threats.
    https://neuraltrust.ai/model-scanner (read 2026-10-01)
  • AML.T0118 — Secure collaboration between multiple AI agents with identity verification and trust medication.
    https://neuraltrust.ai/guardian-agent (read 2026-10-01)
  • AML.T0132 — Review MCP manifests and access definitions for insecure defaults, missing authentication, or overly broad permissions that violate least-privilege principles.
    https://neuraltrust.ai/mcp-scanner (read 2026-10-01)
    Limit: A posture finding from a scan, not runtime enforcement.
  • AML.T0051 — Prompt Guard detects and blocks injection attacks in real time, using multi-layered analysis and the industry’s most extensive jailbreak database.
    https://neuraltrust.ai/prompt-guard (read 2026-10-01)
  • AML.T0053 — Prevent unauthorized tool invocation and protect sensitive resources.
    https://neuraltrust.ai/mcp-gateway (read 2026-10-01)
  • AML.T0103 — TrustLens surfaces every agent your employees interact with
    https://neuraltrust.ai/agent-posture-management (read 2026-10-01)
    Limit: Inventory and discovery rather than enforcement against an adversary-deployed agent.
  • AML.T0099 — Prompt injection, poisoned tool results, and rogue agent calls arrive as plain language. TrustGuard enforces before they reach your system.
    https://neuraltrust.ai/ai-agent-security (read 2026-10-01)
    Limit: NeuralTrust's model report evaluates its indirect-injection model on an English-only held-out split of its own training corpus, and names browser-agent page injections as the weakest slice.
  • AML.T0110 — Detect poisoned or redefined tools, insecure MCP servers, and unsafe endpoint exposures that could compromise trust boundaries.
    https://neuraltrust.ai/mcp-scanner (read 2026-10-01)
    Limit: A scan of MCP server code and configuration, not runtime enforcement.
  • AML.T0054 — TrustGuard tracks conversation context across turns — catching multi-turn attacks where a jailbreak fails once and succeeds on the third attempt.
    https://neuraltrust.ai/ai-agent-security (read 2026-10-01)
    Limit: Enforced where traffic reaches a NeuralTrust collector (gateway, SDK, browser, sidecar or log stream).
  • AML.T0068 — Protect your LLM applications from jailbreaks, obfuscations, and malicious inputs
    https://neuraltrust.ai/prompt-guard (read 2026-10-01)
    Limit: NeuralTrust's own model report names inline-encoded payloads (base64/hex/ROT13) as the toxicity model's one material robustness gap.
  • AML.T0129 — Detect and block hidden jailbreaks embedded in images, audio, or non-text inputs before they execute.
    https://neuraltrust.ai/prompt-guard (read 2026-10-01)
  • AML.T0084 — TrustLens discovers every agent in your enterprise, tracks what they're configured to do, and records what they actually do
    https://neuraltrust.ai/agent-posture-management (read 2026-10-01)
    Limit: Inventory and discovery rather than enforcement against an adversary enumerating agent configuration.
  • AML.T0056 — The most common attack families (instruction overrides and system-prompt extraction) are detected at 99%.
    https://neuraltrust.ai/blog/neuraltrust-ai-security-model-performance-report-2026 (read 2026-10-01)
    Limit: A detection rate on NeuralTrust's own benchmark, which the report says was built to its own taxonomies and carries a home-field advantage.
  • AML.T0057 — Automatically detect and redact PII, credentials, and financial information in LLM prompts and responses
    https://neuraltrust.ai/data-masking (read 2026-10-01)
  • AML.T0086 — Identify jailbreaks, prompt injections, and data exfiltration instantly.
    https://neuraltrust.ai/guardian-agent (read 2026-10-01)
    Limit: Stated as identification within agent tracing; the sentence does not say the exfiltrating call is blocked.
  • AML.T0029 — Block L3/L4 and L7 DDoS attacks in real time across your LLM applications.
    https://neuraltrust.ai/bot-detection (read 2026-10-01)
  • AML.T0034 — Prevent unexpected expenses by limiting misuse, optimizing usage, and tracking spend.
    https://neuraltrust.ai/bot-detection (read 2026-10-01)
  • AML.T0048 — Define and apply custom moderation rules to your LLM applications filtering unsafe, off-topic, or policy-violating content.
    https://neuraltrust.ai/moderation (read 2026-10-01)
  • AML.T0101 — inspects prompts, tool calls and responses in real time to block injection, data leakage and destructive commands before they run.
    https://neuraltrust.ai/blog/claude-code-vs-cursor-benchmark (read 2026-10-01)
DeepKeep 9 of 76

DeepKeep sells an AI security suite (firewall, model scanning, red teaming) whose AI Lens for Developers hooks Cursor and Claude Code and routes events to DeepKeep for a decision. Read 1 October 2026: all 64 pages in deepkeep.ai's sitemap (capability and use-case pages, 25 blog posts, press). DeepKeep's own blog argues that jailbreaks cannot be reliably detected and recommends containment, so its jailbreak cell carries that limit. Its InkJect research shows visual prompt injection defeating text guardrails on four models and closes by saying the gap remains open until defenses work at the visual layer; it does not claim DeepKeep blocks it, so no multimodal-trigger cell was credited. AI Lens for Developers hooks into Cursor and Claude Code only today, sends each event to DeepKeep for a decision, and records an audit log that includes prompt content. Red-teaming categories listed on the red-teaming page were not scored separately from the runtime cells.

  • AML.T0018 — Detect embedded malware, known vulnerabilities in model dependencies, signs of tampering, and unexpected behavior triggered by edge-case inputs.
    https://www.deepkeep.ai/capabilities/model-scanning (read 2026-10-01)
  • AML.T0051 — It protects against AI-specific risks including prompt injection, jailbreak attempts, personal and sensitive data exposure, misuse of tools, and generation of harmful, biased, hallucinated, off-topic or non-compliant outputs.
    https://www.deepkeep.ai/capabilities/ai-firewall (read 2026-10-01)
  • AML.T0053 — These hooks provide checkpoints around prompts, shell commands, file reads, and MCP tool calls, routing activity to DeepKeep for an allow, block, or audit decision.
    https://www.deepkeep.ai/blog/you-hired-a-brilliant-coding-agent-who-supervises-it (read 2026-10-01)
    Limit: Cursor and Claude Code only today; GitHub Copilot, OpenAI Codex, Lovable and Windsurf are planned.
  • AML.T0054 — It monitors and controls prompts and responses to prevent risks such as data leakage, prompt injection, jailbreaks, and unsafe outputs.
    https://www.deepkeep.ai/capabilities/ai-firewall (read 2026-10-01)
    Limit: DeepKeep's own blog says you can't reliably detect every jailbreak and recommends containment over detection.
  • AML.T0084 — AI Agent Scanner maps your agent's attack surface - tools, permissions, and orchestration paths - to reveal exploitable weaknesses
    https://www.deepkeep.ai/capabilities/ai-agent-scanner (read 2026-10-01)
    Limit: A design-time assessment of the customer's own agent, not runtime enforcement.
  • AML.T0057 — The AI Firewall prevents both external leakage and internal exposure between teams, ensuring that personal data is not shared across unintended boundaries.
    https://www.deepkeep.ai/capabilities/ai-firewall (read 2026-10-01)
  • AML.T0048 — Detects and removes toxic, offensive, harmful, unfair, unethical, or discriminatory language
    https://www.deepkeep.ai/llm (read 2026-10-01)
  • AML.T0101 — It can also flag destructive shell commands and send them to the developer for approval before they run.
    https://www.deepkeep.ai/blog/you-hired-a-brilliant-coding-agent-who-supervises-it (read 2026-10-01)
    Limit: Sends the command for developer approval rather than blocking it outright; Cursor and Claude Code only today.
  • AML.T0098 — Detect credentials, tokens, and passwords in the information an agent receives and sends, including content the developer never typed into a prompt.
    https://www.deepkeep.ai/capabilities/ai-lens (read 2026-10-01)
    Limit: AI Lens for Developers supports Cursor and Claude Code today; other coding agents are planned.
Enkrypt AI 20 of 76

Enkrypt AI, now part of Anaconda, sells red teaming and runtime guardrails, with an open-source MCP gateway, a skill scanner and an OpenClaw plugin. Read 1 October 2026: about 330 pages of enkryptai.com (product and solution pages, 148 blog posts, newsroom, ClawPatrol), Anaconda's acquisition press release and blog (Anaconda acquired Enkrypt AI on 4 August 2026 and states existing products, plans and support are unchanged), and the enkryptai GitHub repositories skill-sentinel and secure-mcp-gateway, which are listed but whose code was not reviewed. The 180 glossary entries were not scored. Blog explainers of MCP attack classes (rug pulls, tool shadowing, schema poisoning) list defenses in general terms and were not scored as product claims. Bounds Enkrypt states: guardrails process inputs of up to 14,000 characters; ClawPatrol is an OpenClaw plugin; the MCP Scanner is pre-deployment and periodic, and the Gateway enforces only where MCP traffic is routed through it.

Holistic AI 12 of 76

Holistic AI sells an AI governance platform (inventory, testing, compliance) with an SDK and a device agent, Endlayer, for runtime control. Read 1 October 2026: about 440 pages of holisticai.com (product, solution, blog, news, press, learn) plus the open-source holistic-ai/surface README. Several product pages (protect, identify, ai-red-teaming, testing-suite) render their copy from embedded Webflow code-island props rather than server HTML; that text was read from the props. Most of the site is AI governance (inventory, bias testing, EU AI Act/NIST/ISO workflows); per the method, governance of AI usage is not counted as adversary coverage, and red-teaming of third-party models (Grok, DeepSeek, Claude jailbreak audits) is research, not a product claim. The agent-runtime cells come from one product announcement (Runtime Agentic Enforcement via the HAI Guardian SDK, which must be integrated into the agent) and from the Endlayer device-agent page. Endlayer states its device tiers run no language model and that decrypted text never leaves the device. Holistic's own comparison page carries the line 'Rows marked ⚠ require internal confirmation before publishing', so nothing was scored from it. No claims were found for MCP tool poisoning, rug pulls, system-prompt extraction, RAG poisoning or hallucinated packages.

Airia 12 of 76

Airia sells an AI orchestration and governance platform whose control point is a cloud AI and MCP gateway, with browser and endpoint helpers. Read 1 October 2026: the 24 airia.com/ai-platform pages, about 390 blog and news posts, llms.txt, and the public pages of the airia.ai/docs site (Securing Claude, AI Gateway, MCP Gateway, Tool Scanning, Radar, Skills over MCP, discovery connectors). Ten docs pages redirected to a login (Claude Inference Hooks, Filters, Agent Constraints, Red Teaming, Gateway Rules, Gateway Traffic Anomaly Detection, Endpoint Agent overview, SASE Integration, Copilot Studio threat detection, MCP Monitoring) and were not read. Airia's docs state limits plainly and they are recorded here: MCP Tool Scanning is informational, not a gate; the browser extension is domain-scoped and not pre-submit keystroke DLP; agent constraints apply at the gateway and Bash commands that Claude Code runs locally never traverse it; native and mobile Claude apps are monitored after the fact, which it calls observation, not prevention. Most of Airia's site is orchestration, model routing and governance workflow, which was not scored. The 444 integration pages were not read. Its prompt-injection cell rests on the guardrails sentence that also earns the jailbreak cell, a list naming both; the Claude guide's statement that every prompt, completion and tool call passes through Airia describes routing, not detection, and earns nothing on its own.

Aurascape 11 of 76

Aurascape sells an inline AI traffic proxy and MCP gateway, steered alongside an existing SASE stack, that covers coding assistants from the network side. Read 2026-10-01 from aurascape.ai solution pages, product page, FAQs, two blog posts, a case study and the MCP gateway data-sheet summary (the PDFs behind 'Solution Brief PDF' and the data sheet were not downloaded). Aurascape inspects AI traffic inline as a proxy steered alongside an existing SASE stack, decoding SSE, WebSockets, gRPC, Protobuf and MCP, plus a 'Zero-Bypass' MCP gateway; coding-agent coverage is network-side, not a hook on the device. Its own pages bound MCP enforcement to 'supported paths' and 'gateway-routed' tool calls, and tool-poisoning blocking to 'governed deployments'. It keeps full conversation logs for security operations. Aura Labs research posts (ChatGPT Agent Mode, SilentBridge, DNS tunnelling, LLM search poisoning) explain attacks and were not credited. Not credited: secret redaction for prompts as a credential-harvesting cell (it is credited once, as data leakage). Not credited: a sentence on blocking a typosquatted package returned to a coding assistant, considered for AML.T0060 Publish Hallucinated Entities; a typosquatted name is not a hallucinated one, and the sentence does not name hallucination.

  • AML.T0011 — Detect embedded threats in real time across generated responses, including links, attachments, or agent-initiated actions.
    https://aurascape.ai/product/ (read 2026-10-01)
  • AML.T0051 — A hijacked instruction hidden in a README or a connected document, telling the agent to post secrets to an external site, is detected and neutralized.
    https://aurascape.ai/coding-assistant-guardrails/ (read 2026-10-01)
  • AML.T0053 — Allow marked, approved tools, and block unsanctioned tool calls routed through the gateway.
    https://aurascape.ai/secure-agentic-ai/ (read 2026-10-01)
    Limit: Gateway-routed tool calls only; Aurascape says a call that skips the gateway is caught through the model conversation instead.
  • AML.T0103 — Find employee-used agents, agents embedded in SaaS, internally built agents, and shadow MCP servers connected without IT oversight.
    https://aurascape.ai/secure-agentic-ai/ (read 2026-10-01)
    Limit: Shadow-agent discovery, not detection of an adversary launching an agent.
  • AML.T0110 — In governed deployments, Aurascape inspects that exchange and blocks the poisoned tool and the resulting connection before data leaves.
    https://aurascape.ai/secure-agentic-ai/ (read 2026-10-01)
    Limit: Bounded by Aurascape itself to governed deployments.
  • AML.T0054 — Runtime guardrails provide prompt-injection and jailbreak detection, PII filtering, credential guard, code-injection checks, and output sanitization.
    https://aurascape.ai/secure-agentic-ai/ (read 2026-10-01)
    Limit: Applied on the model-conversation channel through the AI Proxy.
  • AML.T0133 — It maintains a catalog of registered servers with their tools, a risk score, and a security scan, and it flags tools it finds operating outside the gateway.
    https://aurascape.ai/secure-agentic-ai/ (read 2026-10-01)
    Limit: Inventory of the defender's MCP servers and tools.
  • AML.T0057 — Redact keys, tokens, and credentials in flight before an assistant or an unapproved model ever receives them.
    https://aurascape.ai/coding-assistant-guardrails/ (read 2026-10-01)
  • AML.T0086 — Follow data across chained tool calls and flag when it crosses a trust boundary.
    https://aurascape.ai/secure-agentic-ai/ (read 2026-10-01)
  • AML.T0048 — Analyze every AI prompt and response to detect risks like phishing, social engineering, and malicious code generation—before they reach the user.
    https://aurascape.ai/product/ (read 2026-10-01)
  • AML.T0101 — Stop destructive or exploitative commands and runtimes before they reach the shell, caught by policy rather than left to a developer to notice in time.
    https://aurascape.ai/coding-assistant-guardrails/ (read 2026-10-01)
    Limit: Caught in the tool call the model streams back over the network, before the client executes it, so it depends on traffic being steered through Aurascape.
Cranium 10 of 76

Cranium sells an AI governance and assurance platform: AI inventory from code and cloud, red teaming, and a static scanner for agent configuration files. Read 2026-10-01: cranium.ai platform and solution pages, Cranium press releases (Series A, Arena launch, Aiceberg acquisition, coding-assistant vulnerability) and the public knowledge base at docs.cranium.ai. Cranium is a governance-first platform (discovery, AI-BOM, compliance, AI Cards) with red teaming (Arena) and, since acquiring Aiceberg in May 2026, an inline or listen-mode guardrail engine (Guardian) that sits between an AI tool and its LLM. The coding-agent cells come from the Adversarial Inputs Detector, a static scanner of rules and command files that Cranium released as free IDE plugins after its February 2026 coding-assistant research; the download link in that press release now redirects to /platform/secure/ and no repository was found, so the plugin itself was not read. Cranium states one boundary in its FAQ: asked whether it prevents users sending sensitive data to ChatGPT, it answers 'No, our tooling focuses on the internal systems of organizations and their vendors.' Arena attack categories (harmful responses, misinformation, hallucinations, encoding attacks, cyberattacks) were not credited beyond the cells below.

CyCraft 8 of 76

CyCraft sells XecGuard, a cloud guardrail API that classifies prompts and responses for teams building chatbots and agents. Read 2026-10-01: cycraft.com XecGuard and XecART pages, two CyCraft press releases, the public XecGuard docs at community.cycraft.ai, and the xecclaw-plugin README on CyCraft's GitHub. XecGuard is a cloud guardrail API for prompts and responses (an LLM firewall built from fine-tuned small models), not an endpoint product; the only agent-side integration published is an OpenClaw plugin. XecART red-teaming claims (prompt injection, indirect injection, prompt disclosure, sensitive data leak) duplicate runtime cells and earn nothing extra. Not credited: Content Bias Protection (stereotypes, not AML.T0130 response biasing) and Context Grounding Validation (hallucination against RAG context, not RAG poisoning). CyCraft states limits plainly in its FAQ: 'XecGuard does not replace an organization's overall security governance mechanisms', it 'does not automatically rewrite user input', on-premise deployment 'is not part of our standard offering' (the 2025 launch release described an on-premises embedded firewall), and it is 'not recommended for scanning large documents or full-length files'. The PII Policy 'is not designed as a malicious activity detection alert'.

  • AML.T0051 — It effectively blocks malicious inputs such as Prompt Injection, Prompt Extraction, and Harmful Content
    https://www.cycraft.com/en/xecguard (read 2026-10-01)
  • AML.T0053 — It intercepts tool calls at runtime, scans for prompt injection, harmful content, PII leakage, and custom policy violations, and can block unsafe actions before execution.
    https://github.com/cycraft-corp/xecclaw-plugin (read 2026-10-01)
    Limit: An OpenClaw plugin only, which sends tool calls to the XecGuard cloud Scan API; no other agent integration is published.
  • AML.T0110 — Detects whether AI Agent Skills and related file content contain malicious or harmful content targeting the system
    https://community.cycraft.ai/xecguard/doc/docs/intro/introduction (read 2026-10-01)
    Limit: Content scan of skill text submitted to the API; CyCraft's FAQ says XecGuard is not recommended for scanning large documents or full-length files.
  • AML.T0054 — XecGuard provides robust protection against prompt injection, prompt extraction, and jailbreak attacks, ensuring enterprise-grade resilience for AI models.
    https://www.cycraft.com/en/news/xecguard-launch-en-20250702 (read 2026-10-01)
  • AML.T0068 — capable of accurately uncovering underlying malicious intent—even when attackers use obfuscated encoding, role-play, or emotional persuasion tactics
    https://www.cycraft.com/en/xecguard (read 2026-10-01)
  • AML.T0056 — Effectively block attackers attempting to override the model, expose system instructions, or bypass security mechanisms through obfuscation and encoding techniques.
    https://www.cycraft.com/en/xecguard (read 2026-10-01)
  • AML.T0057 — Protect privacy and prevent data leakage of enterprise AI, supporting Taiwan personal data, addresses, and plate numbers, ensuring AI does not expose personal or sensitive information.
    https://www.cycraft.com/en/xecguard (read 2026-10-01)
    Limit: CyCraft's FAQ says the PII Policy detects personal-information attributes broadly at a low risk level and 'is not designed as a malicious activity detection alert'.
  • AML.T0048 — Use semantic analysis to detect and prevent AI outputs that violate public morals or contain violence, hatred, or danger.
    https://www.cycraft.com/en/xecguard (read 2026-10-01)
Levo.ai 11 of 76

Levo.ai secures the AI applications, agents and MCP servers an enterprise runs in production, from eBPF sensors and inline enforcement on the server side. Read 2026-10-01 from levo.ai product pages only (the FAQ blocks on each product page carry most of the claims). Levo is an eBPF runtime-visibility platform for in-house AI apps, agents, MCP servers and APIs; most claims are about server-side traffic it observes or sits inline on, not about employee devices. Its AI Threat Detection FAQ states that detection 'does not sit inline or block by default'; blocking is a separate Inline Guardrails / AI Firewall product. Several cells come from the red-teaming and MCP security testing pages and describe pre-deployment testing, not runtime prevention, and are bounded accordingly. Explanations of attacks on the MCP and RAG pages (hidden instructions in tool descriptions, supply-chain risk of third-party MCP servers, memory leaking across sessions) were not credited because the pages explain them rather than claim a control. MCP Discovery (endpoint inventory via MDM) was read as governance/inventory, not adversary-technique coverage, and was not credited. docs.levo.ai was not read in depth.

PointGuard AI 19 of 76

PointGuard AI sells AI security posture management, red teaming, an MCP gateway, agent identity and an AI-EDR endpoint client. Read 1 October 2026: about 380 pages of pointguardai.com (platform pages, 31 use cases, 150 blog posts, 72 news items, case studies, FAQs). The 223 glossary entries and the 137-entry AI Security Incident Tracker were not scored, nor were third-party report excerpts or a republished trade-press article on the news page. PointGuard AI was formerly AppSOC; older posts use that name. The use-case page titled 'Discover Coding Agents Across Developer Environments' carries body copy about open-source model governance, so nothing was scored from it. Inventory cells are bounded. The 36,527-server MCP study grades servers A to F using code scanning plus GitHub adoption signals; it is a rating, not a runtime control, and is scored as one supply-chain cell. PointGuard documents no limits of its own on the pages read. Not credited: a sentence listing 'unsafe content' among what its guardrails inspect, which appears only in a post about third-party recognition, and a sentence on prompt-injection indicators in metadata and surrounding content, which is indirect prompt injection, already credited, rather than obfuscation.

Singulr AI 4 of 76

Singulr AI sells an enterprise AI governance platform (discovery, policy, approvals and audit across SaaS, cloud and browser) with runtime controls it has extended to endpoint coding agents. Read 2026-10-01 from singulr.ai product, solution, FAQ and blog pages. Its press release on extending Agent Pulse to endpoint agents (Claude Code, Cowork, Cursor, ChatGPT Desktop, MCPs) is hosted on BusinessWire, which returned 403/Access Denied to both fetch and browser; only the one-line homepage banner was read. docs.singulr.ai returned an empty page. Most of Singulr's material is governance (shadow-AI discovery, approval workflows, DLP on employee prompts), which this method does not count as adversary-technique coverage. Its runtime-security page lists 'Unauthorized data exfiltration detection.' without saying which path (user, model output or agent tool), so it was not assigned a technique. Its red-teaming FAQ names prompt injection, data poisoning and compliance violations in a single sentence describing testing; not credited beyond the runtime cells. The supply-chain cell comes from a blog post that maps Agent Pulse onto the LiteLLM compromise, mostly in counterfactual 'would have' language; only the present-tense drift-detection sentence is credited.

Trustwise 6 of 76

Trustwise sells a runtime policy and compliance layer for agents that enterprises build, integrated through frameworks and SDKs. Read 2026-10-01 from trustwise.ai (product, pricing, solutions, press and blog pages). Most security claims are about Harmony AI's 'Shields' (Prompt, MCP, Compliance, Brand, Cost, Carbon), introduced in a June 2025 launch post and press release that described Harmony AI as being 'in private preview to select Trustwise customers and OEM partners'. The current site reframes the product as the 'AI Control Plane' (Assess / Control / Optimize) and says less about specific detections. The 'Where AI Runs' page lists coding agents (Claude Code, GitHub Copilot, Cursor, Codex, Windsurf, Amazon Q Developer), stating Trustwise governs them 'without replacing code review, SAST, or SDLC controls', but does not say how it attaches to them. The site states framework mapping to MITRE ATLAS among 1,100+ controls, but publishes no per-technique list, so that earns nothing. The '20,000+ Red-Team Prompts' dataset (injection, jailbreak, misuse, drift) was not credited separately from the runtime cells. Several blog posts explain prompt injection; only the product sentences were credited.

Vijil 6 of 76

Vijil helps teams building agents test and harden them, and ships guardrails that run inside the agent's own code. Read 2026-10-01 from vijil.ai, docs.vijil.ai and the Apache-2.0 vijil-dome README on GitHub (github.com/vijilAI/vijil-dome). Vijil protects agents that the customer builds: Dome is a library and request-path guardrail inside the agent (LangGraph, Google ADK, Strands, MCP tool wrapping), and Diamond is a pre-deployment evaluation and red-team harness. Several cells are drawn from guard tables in the owner guide (threat name followed by its description); the quote is the row as it renders on the page. Dome's README also describes verifying tool identity against a signed manifest via SPIFFE; this was not credited because the prose describes an identity mechanism without stating which adversary technique it addresses. Diamond's security scenarios also include data-leakage, model-privacy, malware and exploit-generation probes; only the denial-of-service probes were credited, as a testing-only cell. No claims were found for RAG poisoning, MCP tool poisoning, memory poisoning or system-prompt extraction as runtime defences.

So you can check any cell against the vendor’s page yourself — and tell us where we read it wrong. The 26 September correction started that way.

What we checked and did not credit

The candidates checked in the 26 September correction that did not become cells, and why. Each quote was confirmed on the live page first; every one of them is a real sentence from the product’s own material, so a different reviewer could reasonably file some of them differently.

ProductTechniqueWhy it was not credited
SentinelOne (Prompt Security)T0071Same ingestion scan as its new RAG-poisoning (T0070) cell, and T0070 contains false RAG entries.
LakeraT0071Same ingestion scan as its existing RAG-poisoning (T0070) cell, and T0070 contains false RAG entries. source
LakeraT0067The sentence is already its User Execution (T0011) cell; one link filter earns one cell. source
LakeraT0069The sentence is already its system-prompt extraction (T0056) cell, which T0069's system-prompt sub-technique restates. source
StraikerT0069Already its system-prompt extraction (T0056) cell; same restatement. source
NetskopeT0069Already its system-prompt extraction (T0056) cell; same restatement.
NetskopeT0067Malicious-URL filtering, the capability its existing User Execution (T0011) cell already credits. source
NetskopeT0059One control earns one cell; the sentence names training and data poisoning, so it is credited to T0020. source
ZenityT0067Links are filed under T0011, which Zenity holds; the sentence's image-rendering detection is credited to T0077. source
ZenityT0096The sentence is already its AI-agent C2 (T0108) cell and names one detection. source
StraikerT0093The sentence is already its tool-data poisoning (T0099) cell; ATLAS says the two overlap. source
CertivT0071, T0092, T0094A copied OWASP category definition with no claim sentence, the basis on which Operant's OWASP badges were not counted. source
Backslash SecurityT0093Tickets are named in an explanation of where injection comes from, not in what the product inspects. source
MoorAI (prose review)T0071Same ingestion scan as its prose RAG-poisoning (T0070) credit; judged as Lakera's was. source

Questions about this study

How were vendors credited for a MITRE ATLAS technique?

It is a documentation review. A vendor is credited for a technique only where its own published material describes doing the thing the technique describes, backed by a source URL and a verbatim quote. Explaining an attack is not covering it, governing usage of AI is not defending against an adversary, and third-party prose on a vendor's site does not count. The scope is the 76 top-level techniques MITRE's ATLAS 2026.09 release tags with the platform Agentic AI.

Which ATLAS agentic techniques do the most vendors document?

AML.T0053 AI Agent Tool Invocation (36 of 43 vendors), AML.T0051 LLM Prompt Injection (35), AML.T0057 LLM Data Leakage (33) and AML.T0086 Exfiltration via AI Agent Tool Invocation (30). Coverage is less concentrated than that list suggests: those four hold 134 of the 517 vendor credits, 26%, and it takes the eleven most-documented techniques to pass half. Of the 548 credits in the review, MoorAI's rule base included, 220 come with a limit the product states itself; tool invocation and deploying an agent carry the most, eighteen each.

Which ATLAS agentic techniques does no vendor document?

32 of the 76 are documented by none of the 43 vendors reviewed; MoorAI's rule base holds five of those, leaving 27 that no product in the review documents. Three of the five were added by MoorAI agent v0.96.0, released on 26 September, after the study. By ATLAS's own tactic definitions, 11 of the 27 are adversary preparation (Reconnaissance, Resource Development, AI Attack Adaptation) and 6 sit in Discovery or AI Model Access. The other 10 are defence-side: 4 in Defense Evasion, 4 in Impact and 2 in Command and Control. Products outside this sample publish material on some of them. A further 9 techniques are documented by exactly one vendor.

Does an empty cell mean a product lacks the capability?

No. An empty cell means nothing was found published, not that a product lacks the capability. Nothing was installed or run; every credit is a claim, including MoorAI's. A low count usually reflects a category, such as a data-loss-prevention platform, rather than a weakness.

How does MoorAI score under the same method?

Scored from published prose only, the way vendors are scored, MoorAI comes out at 31 techniques, and 26 after discarding every credit traceable to one README bullet that names ATLAS ids. On the 20 September read date its rule base gave 27, so the prose method was the more generous of the two. MoorAI agent v0.96.0, released on 26 September and prompted by this study's gaps, added rules for four more techniques; the rule base now gives 31, and the prose review has not been re-run against that release. The current release, agent v1.1.0 of 1 October 2026, carries the same ATLAS mapping. The asymmetry is vocabulary: MoorAI's documentation is written in ATLAS's language, which a prose review rewards.

Changes to this study

The study was first published on 21 September 2026. Every correction, update and expansion since is recorded here with the figures of its own day; the rest of this page states the study as it stands now.

Corrected 26 September 2026

An independent audit of this study, first published on 21 September, found claims the data did not support and vendor evidence the review had missed. We checked every point against the sources and changed the study where it was wrong.

  • Four credits added from vendors’ own material, each quote checked on the live page on 26 September. Certiv documents prompt injection arriving in emails and documents (AML.T0093). SentinelOne’s Prompt Security line documents scanning content before it is embedded in a RAG index (AML.T0070). Zenity documents detecting risky image rendering in model output (AML.T0077). Netskope documents keeping poisoned data out of training data stores, in a hedged press-release sentence recorded as bounded (AML.T0020). Credits went from 249 to 253, bounded credits from 75 to 76, and techniques no product here documents from 32 to 31.
  • 15 further vendor candidates were checked and not credited. Most were sentences already credited to a neighbouring technique, and one sentence earns one cell under the rule applied to every row; two of those sentences fit a different technique better and are credited there (the Netskope and Zenity cells above). The rest were a copied framework definition or an explanation of an attack. Each is listed under What we checked and did not credit, with the reason.
  • Preparation was reclassified. We had counted Discovery and AI Model Access as attacker preparation. ATLAS does not: it describes Discovery as post-compromise. Preparation now means Reconnaissance, Resource Development and AI Attack Adaptation only, 11 of the 31 rather than 17. Six techniques in Discovery and AI Model Access are listed apart, and defence-side techniques number 14 rather than 15, because Certiv now documents AML.T0093.
  • Two claims are withdrawn. “Four techniques carry most of the industry’s published coverage”: they carry 26% of vendor credits, and it takes eleven to pass half. “The qualification clusters on the crowded techniques”: true for tool invocation and tool-invocation exfiltration, not for prompt injection or data leakage.
  • Three claims are narrowed. Defense Evasion has the most undocumented defence-side techniques by count, six of eleven, but Command and Control is emptier by share, and five Defense Evasion techniques do have coverage. It was wrong that no defensive product claims preparation-stage techniques: vendors document nine techniques in those five tactics. And “nobody” means nobody in this sample. MoorAI’s own published prose describes two of the 31, which the post had denied, and products outside the sample publish material on several.
Updated 26 September 2026: MoorAI agent v0.96.0

MoorAI agent v0.96.0, released on 26 September, adds five rules to the rule base. Four of them carry techniques this study had listed as documented by no product: AML.T0061 LLM Prompt Self-Replication; AML.T0092 Manipulate User LLM Chat History, bounded to local agent transcript files; AML.T0067 LLM Trusted Output Components Manipulation, bounded to links; and AML.T0035 AI Artifact Collection, bounded to model files and caches moved in one command. The fifth maps model-loading calls to AML.T0011.000, a sub-technique of User Execution, which MoorAI’s rule base already held, so it changes no cell.

These rules were written after the study, prompted by the gaps it found. None of them existed on the 20 September read date. Only MoorAI’s row changed: its rule base now gives 31 of 76 rather than 27. No vendor cell changed. Techniques no product here documents fall from 31 to 27, and defence-side ones from 14 to 10; credits go from 253 to 257. The prose review of MoorAI has not been re-run against the new release.

This update also corrects MoorAI’s bounded cells, which were understated on the read date too. The rule base records a limit on every credit that covers only part of a technique, but the chart drew only a hand-picked list of them as bounded. A MoorAI cell is now drawn bounded whenever every rule crediting it is partial: 13 of 27 on the read date, where the post showed 4, and 16 of 31 now, where the hand-picked list would have shown 7. Bounded credits across the review go from 76 to 88; on the read date the figure should have been 85. Vendor cells are unaffected. The figures in the correction note above are as they stood before this update.

Expanded 27 September 2026: four vendors added

Four vendors were added to the study on 27 September: Lasso Security, Permiso, Pillar Security and WitnessAI. They appear on an analyst’s market map of agentic runtime enforcement, and three of them document coverage of AI coding agents; Permiso covers AI agents through identity and cloud logs. They were read on 27 September by the same method as the original 19, and every quote was checked as an exact match on the vendor’s page that day. All four keep their product documentation behind a login or a password, so their cells come from marketing sites, blogs, first-party PDFs and, for Lasso, open-source repositories. Each vendor’s note in the sources above says what was read and what was not credited.

What moved. The study now covers 23 vendors. Pillar Security documents 26 techniques, more than any vendor in the original read, where Operant AI and Zenity led with 23; Lasso Security documents 23, WitnessAI 14 and Permiso 9. Vendor credits go from 226 to 298, and all credits from 257 to 329, of which 111 are bounded rather than 88. The median vendor documents 14 rather than 12, and 9 of the 23 document fewer than ten, against 8 of 19. The four most-documented techniques hold 24% of vendor credits rather than 26%, and it still takes eleven to pass half. Techniques documented by exactly one vendor fall from twelve to ten: Pillar Security also documents AML.T0093, and WitnessAI AML.T0129.

What did not. None of the four documents a technique that no vendor documented before: the 43 techniques with any vendor coverage are the same 43. So the 27 techniques no product here documents, their split into 10 defence-side, 6 in Discovery or AI Model Access and 11 preparation, and the 33 no vendor documents are all unchanged, and so is MoorAI’s row. The correction and update notes above keep their figures as published, for the 19 vendors of the original read.

Expanded 1 October 2026: two vendors added

Two vendors were added to the study on 1 October: Above Security and Rig Security. Above sells an insider-risk platform whose AI agents investigate cases from identity, SaaS, endpoint and AI-tool connectors, and its research group co-wrote the Synthetic Insider Threat Matrix. Rig sells identity security for people, machine identities and AI agents, with an endpoint sensor that enforces policy before an agent’s action runs. They were read on 1 October by the same method, and every quote was checked as an exact match on the vendor’s page that day. Rig publishes no product documentation and Above’s customer portal is behind a login, so their cells come from product pages, blogs and first-party PDFs. Each vendor’s note in the sources above says what was read and what was not credited. Our mapping of MoorAI against that matrix is a separate post.

What moved. The study now covers 25 vendors. Above Security documents 2 techniques and Rig Security 2, every one of them with a limit: Above’s are investigation after the fact, and Rig’s are keyed to identity and resource rather than to content. Vendor credits go from 298 to 302, and all credits from 329 to 333, of which 115 are bounded rather than 111. The median vendor documents 12 rather than 14, and 11 of the 25 document fewer than ten, against 9 of 23. The four most-documented techniques still hold 24% of vendor credits, and it still takes eleven to pass half.

What did not. Neither documents a technique that no vendor documented before, and neither changes which techniques have exactly one vendor. The 27 techniques no product here documents, the 33 no vendor documents and MoorAI’s row are unchanged. The notes above keep their figures as published.

Expanded again 1 October 2026: eighteen vendors added

Eighteen vendors were added to the study later on 1 October: Airia, Akto, Aurascape, Cranium, CyCraft, DeepKeep, Enkrypt AI, HiddenLayer, Holistic AI, Levo.ai, NeuralTrust, Noma Security, Onyx Security, PointGuard AI, Singulr AI, Trustwise, Vijil and Virtue AI. They sell AI runtime guardrails and firewalls, AI and MCP gateways, agent discovery and posture, model scanning and red teaming, and many of them describe reaching AI coding agents through a hook in the agent, an endpoint client or a gateway in front of the model. The evidence is each vendor’s own first-party material, read on 1 October: product pages, public documentation, blogs, press releases and GitHub repositories, and for Virtue AI, which Fortinet has acquired, Fortinet’s own release. Every quote was checked as an exact match on the vendor’s live page that day. Analyst content and third-party write-ups were not used. Four proposed cells were not credited under the rules below: a typosquatted package is not a hallucinated entity, one model scanner earns one cell, indirect injection is not obfuscation, and a sentence found only in a post about third-party recognition was set aside. Each vendor’s note in the sources above says what was read and what was not credited.

What moved. The study now covers 43 vendors. The eighteen document 215 techniques between them, 105 of them with a limit; Akto documents the most of the eighteen, 21, and Pillar Security still leads the study with 26. Vendor credits go from 302 to 517, and all credits from 333 to 548, of which 220 are bounded rather than 115: two in five rather than about a third. The median vendor documents 11 rather than 12, and 18 of the 43 document fewer than ten, against 11 of 25. The four most-documented techniques hold 26% of vendor credits rather than 24%, and it still takes eleven to pass half; AI Agent Tool Invocation, AML.T0053, now leads, documented by 36. Techniques documented by exactly one vendor fall from ten to nine: five of the eighteen also document AML.T0018 and one AML.T0024, and Cranium documents AML.T0061, which no vendor had documented before.

What did not. AML.T0061 already had a MoorAI rule, so the 27 techniques no product here documents, their split into 10 defence-side, 6 in Discovery or AI Model Access and 11 preparation, and MoorAI’s row are unchanged. Counting vendors alone, techniques no vendor documents fall from 33 to 32. The notes above keep their figures as published.