What MITRE ATLAS RAG Credential Harvesting (AML.T0082) - Adversary Harvesting of Credentials from Retrieval-Augmented Generation Pipelines requires
This node addresses MITRE ATLAS technique AML.T0082 (RAG Credential Harvesting). Adversaries may attempt to use their access to a large language model (LLM) on the victim's system to collect credentials. Credentials may be stored in internal documents which can inadvertently be ingested into a RAG database, where they can ultimately be retrieved by an AI agent. Defending against this technique is required under EU AI Act, NIST AI RMF, and ISO/IEC 42001 obligations; this node operationalises the documented ATLAS mitigations and cross-instrument controls into a deterministic verification workflow.
Pillar: AI Governance & Law · Authority: MITRE Corporation · Version: 1.0.1 · Last updated:
Primary source: https://raw.githubusercontent.com/mitre-atlas/atlas-data/main/dist/ATLAS.yaml
SHA-256 integrity: 612d1fefd525f894d11402c8d8ece920e99386130d2bd8c1a801d8a6249f564e
Primary Citations — 8 traced to source
- MITRE ATLAS - RAG Credential Harvesting (AML.T0082), https://raw.githubusercontent.com/mitre-atlas/atlas-data/main/dist/ATLAS.yaml#AML.T0082, AML.T0082 technique entry, 2026
- EU AI Act - Regulation (EU) 2024/1689 on Artificial Intelligence, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689, Article 15 (Accuracy, Robustness, Cybersecurity), 2024
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-atlas-rag-credential-harvesting.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-atlas-rag-credential-harvesting.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-atlas-rag-credential-harvesting
- Back to registry: Browse all 10,099 compliance nodes