Skip to content

Reference

Attack index - by task

Authorized use only Defensive and educational material, for authorized testing and sanctioned engagements. Run techniques only against systems you own or are explicitly permitted to assess.

The offensive path through the book, on one page. The chapters are filed by system layer so each defense sits beside the attack it answers. This index re-slices the same material the way an engagement actually runs - by what you are trying to do - so a tester can move recon, to initial access, to impact without hopping between five parts. It is a lens, not new content: every row points to the chapter that carries the payloads, the commands, and the defense.

1. Reconnaissance & fingerprinting

Work out what you are attacking before you attack it: the model family, the guardrail type, the reachable tools, and the hidden instructions.

TechniqueWhat it isWhereMaps to
Model & guardrail fingerprintingIdentify the model family, version, and whether moderation is a separate classifier or in-bandVI.4-
System-prompt & spec extractionRecover the hidden instructions that leak tools, data sources, and policyII.2LLM08
Tool / agent enumerationList an agent’s capabilities; for A2A, fetch and read the Agent CardIV.4 · IV.3ASI02

2. Injection & initial access

The security-critical primitive: getting attacker-controlled text treated as instructions.

TechniqueWhat it isWhereMaps to
Direct prompt injectionThe user overrides instructions in their own promptII.2LLM01 · AML.T0051.000
Indirect prompt injectionInstructions hidden in content the model ingests - a page, PDF, email, tool resultII.2LLM01 · AML.T0051.001
RAG / knowledge-base poisoningGet a malicious instruction indexed so the model retrieves and trusts itRAG, end to end · V.3LLM01 · LLM05
RAG authority spoofing (DACSI)Metadata-like text that impersonates a policy or provenance signal, evading imperative filtersII.2LLM01 · LLM08
Multimodal injectionInstructions carried in an image, audio, or its metadata, decoded before any text filterII.4LLM01 · AML.T0129

3. Jailbreaks & guardrail bypass

Make an aligned model do what its safety training refuses. The fourteen families, and why each works, are in one chapter.

TechniqueWhat it isWhereMaps to
Persona / authority / Skeleton KeyRole-play and authority framing that talk the model out of its guardrailsII.3AML.T0054
Encoding & obfuscationSmuggle the payload as base64, hex, or a low-resource language past a text filterII.3AML.T0054
Many-shot & CrescendoFlood the context, or escalate across turns, until the model is committedII.3AML.T0054
Gradient-optimized suffixes (GCG)A white-box-optimized token suffix that transfers to flip aligned modelsII.3AML.T0054 · AML.T0043
Chain-of-thought hijackingTurn a reasoning model’s own safety trace against it (refusal dilution, H-CoT)II.3AML.T0054

4. Tool abuse & excessive agency

The injection only matters because the agent can act. This is where model output becomes a real action.

TechniqueWhat it isWhereMaps to
MCP tool poisoningMalicious instructions hidden in a tool’s description or schema, which the model reads and trustsIV.2 · IV.3MCP03 · ASI02 · AML.T0051
Rug pull / tool shadowingSwap a clean tool description for a poisoned one after approval, or shadow another server’s toolIV.2 · IV.3MCP03 · ASI02
Confused deputy & token passthroughRide the agent’s authority to reach a resource, or replay a token not issued to the serverIV.3 · IV.6MCP07 · ASI03
Command-injection sinkA tool handler that shells out on a model-influenced argument, so injection becomes RCEVI.4LLM03
Coding & computer-use agent abuseTurn a coding or browser agent’s own capabilities into the attackIII.2 · III.3LLM03 · ASI02

5. Privilege escalation & lateral movement

Turn a foothold into reach - across the cloud, and across a mesh of agents.

TechniqueWhat it isWhereMaps to
SSRF via an AI featureA model or tool fetches a user-influenced URL, reaching the internal network and cloud metadataV.2-
Cloud IAM escalationFrom leaked metadata creds to the control plane - an ordinary cloud pentest with an AI entry pointV.2-
A2A card spoofing & task tamperingImpersonate a remote agent, or poison the task one agent passes anotherIV.4ASI07 · ASI03

6. Persistence & propagation

The agentic path with no classic equivalent: an attack that outlives the session.

TechniqueWhat it isWhereMaps to
Memory poisoningA durable false instruction written into an agent’s memory, re-firing across sessionsIII.4ASI06 · AML.T0080.000
Self-propagating prompts (worms)An injection that copies itself into the next agent or document it touchesIII.4ASI06 · ASI08

7. Model, data & supply-chain attacks

Attacks on the artifact and its training data, rather than the running prompt.

TechniqueWhat it isWhereMaps to
Adversarial examples (evasion)Crafted input that flips a model’s decision at inferenceI.4AML.T0043
Training-data extraction & memorizationRecover verbatim memorized data, including PII, from a deployed modelI.3LLM02 · AML.T0024
Membership inferenceDecide whether a record was in the training set - a privacy and compliance findingI.3LLM02 · AML.T0024.000
Data & model poisoningCorrupt the training, fine-tune, or web-scale corpus; plant a backdoor triggerI.3LLM05
Embedding inversion & vector leakageReconstruct source text from stored vectors; storing embeddings is not anonymizationRAG, end to end · V.3LLM09
Unsafe deserialization & trojanized modelsA pickle checkpoint that runs code on load, or backdoored weights that pass every format checkI.5LLM04 · ASI04 · AML.T0010

8. Exfiltration & impact

The payoff. Data theft needs the lethal trifecta present at once; break any leg and the path closes.

TechniqueWhat it isWhereMaps to
The lethal trifectaPrivate data + untrusted content + an egress channel = an exploitable theft pathII.2 · Cheat sheetLLM01 · LLM02
Egress via tool argument or fetchRoute stolen data out through a tool call, an outbound fetch, or a rendered imageIV.3LLM02 · ASI02
Sensitive-information disclosureThe model surfaces secrets, another tenant’s data, or its own configurationII.2 · V.3LLM02
Denial of service / walletForce a refusal loop or runaway token spendII.2LLM06