Bidda Sovereign Intelligence · 10,099 Verified Nodes · 39 Sovereign Pillars

MITRE ATLAS RAG Credential Harvesting (AML.T0082) - Adversary Harvesting of Credentials from Retrieval-Augmented Generation Pipelines

This node addresses MITRE ATLAS technique AML.T0082 (RAG Credential Harvesting). Adversaries may attempt to use their access to a large language model…

What MITRE ATLAS RAG Credential Harvesting (AML.T0082) - Adversary Harvesting of Credentials from Retrieval-Augmented Generation Pipelines requires

This node addresses MITRE ATLAS technique AML.T0082 (RAG Credential Harvesting). Adversaries may attempt to use their access to a large language model (LLM) on the victim's system to collect credentials. Credentials may be stored in internal documents which can inadvertently be ingested into a RAG database, where they can ultimately be retrieved by an AI agent. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.

Pillar: AI Governance & Law · Authority: MITRE Corporation · Version: 1.0.1 · Last updated:

Primary source: https://raw.githubusercontent.com/mitre-atlas/atlas-data/main/dist/ATLAS.yaml

SHA-256 integrity: 612d1fefd525f894d11402c8d8ece920e99386130d2bd8c1a801d8a6249f564e

Primary Citations — 8 traced to source

  • MITRE ATLAS - RAG Credential Harvesting (AML.T0082), https://raw.githubusercontent.com/mitre-atlas/atlas-data/main/dist/ATLAS.yaml#AML.T0082, AML.T0082 technique entry, 2026
  • EU AI Act - Regulation (EU) 2024/1689 on Artificial Intelligence, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689, Article 15 (Accuracy, Robustness, Cybersecurity), 2024

+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.