What MITRE ATLAS Generate Malicious Commands (AML.T0102) - AI Attack Staging adversarial technique against AI systems requires
This node addresses MITRE ATLAS technique AML.T0102 (Generate Malicious Commands), an adversarial technique in the ATLAS AI Attack Staging tactic. Adversaries may use large language models (LLMs) to dynamically generate malicious commands from natural language. Dynamically generated commands may be harder detect as the attack signature is constantly changing. AI-generated commands may also allow adversaries to more rapidly adapt to different environments and adjust their tactics. Adversaries may utilize LLMs present in the victim's environment or call out to externally hosted services. APT28 utilized a model hosted on HuggingFace in a campaign with their LAMEHUG malware [\[1\]][1]. In either case prompts to generate malicious code can blend in with normal traffic. [1]: https://logpoint.com/en/blog/apt28s-new-arsenal-lamehug-the-first-ai-powered-malware Defending against this technique is required under EU AI Act (accuracy, robustness and cybersecurity), NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.
Pillar: AI Governance & Law · Authority: MITRE Corporation · Version: 1.0.1 · Last updated:
Primary source: https://raw.githubusercontent.com/mitre-atlas/atlas-data/main/dist/ATLAS.yaml#AML.T0102
SHA-256 integrity: b996368d44fd3190f7f6736628114848b4739ddd1f11edcf79092acb528c3c92
Primary Citations — 7 traced to source
- MITRE ATLAS - Generate Malicious Commands (AML.T0102), https://raw.githubusercontent.com/mitre-atlas/atlas-data/main/dist/ATLAS.yaml#AML.T0102, AML.T0102 technique entry, 2026
- EU AI Act - Regulation (EU) 2024/1689 on Artificial Intelligence, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689, Article 15 (Accuracy, Robustness, Cybersecurity), 2024
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-atlas-generate-malicious-commands.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-atlas-generate-malicious-commands.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-atlas-generate-malicious-commands
- Back to registry: Browse all 10,099 compliance nodes