An evidence-graded kill chain for agent systems: 9 tactics, 61 techniques, 40 attack classes. Each one is tied to something real: observed in the wild, reproduced in the lab, or adapted from established attacks. Built to complement MITRE ATT&CK and OWASP, not replace them.
Every technique carries an evidence grade and a source trail. These panels are computed live from the matrix at build time. Nothing here is estimated.
Each technique cites the HackMyAgent checks that target it and the OASB controls that mitigate it. A citation is a maintained cross-reference, not a tested guarantee that the technique is detected or mitigated in a given deployment. For coverage against OWASP and MITRE ATLAS, see Coverage & gaps.
Nine stages, left to right, the way an agent compromise actually unfolds. Search, filter by evidence grade, and sort by kill-chain order, evidence, or canary observations. Every cell links to the full technique dossier.
Every technique carries one of three evidence grades. The grade tells you exactly how much to trust it.
Confirmed in real-world production systems, security incidents, or internet-wide exposure assessments.
Reproduced in a controlled lab with documented, repeatable steps. The lab is public: DVAA
A well-understood traditional technique applied to the agent context. Not yet observed agent-specifically.
Enterprise network and endpoint attacks. The layer below the agent.
Adversarial ML and model-level attacks. The layer below the agent.
Infrastructure, governance, protocols, memory, and identity: the agent layer, between model and user.