Reference
Attack index - by task
Authorized use only Defensive and educational material, for authorized testing and sanctioned engagements. Run techniques only against systems you own or are explicitly permitted to assess.
The offensive path through the book, on one page. The chapters are filed by system layer so each defense sits beside the attack it answers. This index re-slices the same material the way an engagement actually runs - by what you are trying to do - so a tester can move recon, to initial access, to impact without hopping between five parts. It is a lens, not new content: every row points to the chapter that carries the payloads, the commands, and the defense.
1. Reconnaissance & fingerprinting
Work out what you are attacking before you attack it: the model family, the guardrail type, the reachable tools, and the hidden instructions.
| Technique | What it is | Where | Maps to |
|---|---|---|---|
| Model & guardrail fingerprinting | Identify the model family, version, and whether moderation is a separate classifier or in-band | VI.4 | - |
| System-prompt & spec extraction | Recover the hidden instructions that leak tools, data sources, and policy | II.2 | LLM08 |
| Tool / agent enumeration | List an agent’s capabilities; for A2A, fetch and read the Agent Card | IV.4 · IV.3 | ASI02 |
2. Injection & initial access
The security-critical primitive: getting attacker-controlled text treated as instructions.
| Technique | What it is | Where | Maps to |
|---|---|---|---|
| Direct prompt injection | The user overrides instructions in their own prompt | II.2 | LLM01 · AML.T0051.000 |
| Indirect prompt injection | Instructions hidden in content the model ingests - a page, PDF, email, tool result | II.2 | LLM01 · AML.T0051.001 |
| RAG / knowledge-base poisoning | Get a malicious instruction indexed so the model retrieves and trusts it | RAG, end to end · V.3 | LLM01 · LLM05 |
| RAG authority spoofing (DACSI) | Metadata-like text that impersonates a policy or provenance signal, evading imperative filters | II.2 | LLM01 · LLM08 |
| Multimodal injection | Instructions carried in an image, audio, or its metadata, decoded before any text filter | II.4 | LLM01 · AML.T0129 |
3. Jailbreaks & guardrail bypass
Make an aligned model do what its safety training refuses. The fourteen families, and why each works, are in one chapter.
| Technique | What it is | Where | Maps to |
|---|---|---|---|
| Persona / authority / Skeleton Key | Role-play and authority framing that talk the model out of its guardrails | II.3 | AML.T0054 |
| Encoding & obfuscation | Smuggle the payload as base64, hex, or a low-resource language past a text filter | II.3 | AML.T0054 |
| Many-shot & Crescendo | Flood the context, or escalate across turns, until the model is committed | II.3 | AML.T0054 |
| Gradient-optimized suffixes (GCG) | A white-box-optimized token suffix that transfers to flip aligned models | II.3 | AML.T0054 · AML.T0043 |
| Chain-of-thought hijacking | Turn a reasoning model’s own safety trace against it (refusal dilution, H-CoT) | II.3 | AML.T0054 |
4. Tool abuse & excessive agency
The injection only matters because the agent can act. This is where model output becomes a real action.
| Technique | What it is | Where | Maps to |
|---|---|---|---|
| MCP tool poisoning | Malicious instructions hidden in a tool’s description or schema, which the model reads and trusts | IV.2 · IV.3 | MCP03 · ASI02 · AML.T0051 |
| Rug pull / tool shadowing | Swap a clean tool description for a poisoned one after approval, or shadow another server’s tool | IV.2 · IV.3 | MCP03 · ASI02 |
| Confused deputy & token passthrough | Ride the agent’s authority to reach a resource, or replay a token not issued to the server | IV.3 · IV.6 | MCP07 · ASI03 |
| Command-injection sink | A tool handler that shells out on a model-influenced argument, so injection becomes RCE | VI.4 | LLM03 |
| Coding & computer-use agent abuse | Turn a coding or browser agent’s own capabilities into the attack | III.2 · III.3 | LLM03 · ASI02 |
5. Privilege escalation & lateral movement
Turn a foothold into reach - across the cloud, and across a mesh of agents.
| Technique | What it is | Where | Maps to |
|---|---|---|---|
| SSRF via an AI feature | A model or tool fetches a user-influenced URL, reaching the internal network and cloud metadata | V.2 | - |
| Cloud IAM escalation | From leaked metadata creds to the control plane - an ordinary cloud pentest with an AI entry point | V.2 | - |
| A2A card spoofing & task tampering | Impersonate a remote agent, or poison the task one agent passes another | IV.4 | ASI07 · ASI03 |
6. Persistence & propagation
The agentic path with no classic equivalent: an attack that outlives the session.
| Technique | What it is | Where | Maps to |
|---|---|---|---|
| Memory poisoning | A durable false instruction written into an agent’s memory, re-firing across sessions | III.4 | ASI06 · AML.T0080.000 |
| Self-propagating prompts (worms) | An injection that copies itself into the next agent or document it touches | III.4 | ASI06 · ASI08 |
7. Model, data & supply-chain attacks
Attacks on the artifact and its training data, rather than the running prompt.
| Technique | What it is | Where | Maps to |
|---|---|---|---|
| Adversarial examples (evasion) | Crafted input that flips a model’s decision at inference | I.4 | AML.T0043 |
| Training-data extraction & memorization | Recover verbatim memorized data, including PII, from a deployed model | I.3 | LLM02 · AML.T0024 |
| Membership inference | Decide whether a record was in the training set - a privacy and compliance finding | I.3 | LLM02 · AML.T0024.000 |
| Data & model poisoning | Corrupt the training, fine-tune, or web-scale corpus; plant a backdoor trigger | I.3 | LLM05 |
| Embedding inversion & vector leakage | Reconstruct source text from stored vectors; storing embeddings is not anonymization | RAG, end to end · V.3 | LLM09 |
| Unsafe deserialization & trojanized models | A pickle checkpoint that runs code on load, or backdoored weights that pass every format check | I.5 | LLM04 · ASI04 · AML.T0010 |
8. Exfiltration & impact
The payoff. Data theft needs the lethal trifecta present at once; break any leg and the path closes.
| Technique | What it is | Where | Maps to |
|---|---|---|---|
| The lethal trifecta | Private data + untrusted content + an egress channel = an exploitable theft path | II.2 · Cheat sheet | LLM01 · LLM02 |
| Egress via tool argument or fetch | Route stolen data out through a tool call, an outbound fetch, or a rendered image | IV.3 | LLM02 · ASI02 |
| Sensitive-information disclosure | The model surfaces secrets, another tenant’s data, or its own configuration | II.2 · V.3 | LLM02 |
| Denial of service / wallet | Force a refusal loop or runaway token spend | II.2 | LLM06 |