Bidda Sovereign Intelligence · 10,099 Verified Nodes · 39 Sovereign Pillars

MITRE ATLAS Application Access Token (AML.T0091.000) - Adversarial use of Application Access Token as adapted in MITRE ATT&CK T1550.001

This node addresses MITRE ATLAS technique AML.T0091.000 (Application Access Token). Adversaries may use stolen application access tokens to bypass the…

What MITRE ATLAS Application Access Token (AML.T0091.000) - Adversarial use of Application Access Token as adapted in MITRE ATT&CK T1550.001 requires

This node addresses MITRE ATLAS technique AML.T0091.000 (Application Access Token). Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials. Application access tokens are used to make authorized API requests on behalf of a user or service and are commonly used to access resources in cloud, container-based applications, software-as-a-service (SaaS), and AI-as-a-service(AIaaS). They are commonly used for AI services such as chatbots, LLMs, and predictive inference APIs. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow. Sub-technique of ATLAS AML.T0091. ATT&CK reference: T1550.001 provides authoritative mitigation guidance for this technique class.

Pillar: AI Governance & Law · Authority: MITRE Corporation · Version: 1.0.1 · Last updated:

Primary source: https://raw.githubusercontent.com/mitre-atlas/atlas-data/main/dist/ATLAS.yaml

SHA-256 integrity: df2cdbb1c1d375687f40ae5bfcceb8894ceac54bb3f298658f091486888dbb98

Primary Citations — 6 traced to source

  • MITRE ATLAS - Application Access Token (AML.T0091.000), https://raw.githubusercontent.com/mitre-atlas/atlas-data/main/dist/ATLAS.yaml#AML.T0091.000, AML.T0091.000 technique entry, 2026
  • EU AI Act - Regulation (EU) 2024/1689 on Artificial Intelligence, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689, Article 15 (Accuracy, Robustness, Cybersecurity), 2024

+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.