OpenA2A · Threat intelligence

The attacks against AI agents, mapped and graded.

An evidence-graded kill chain for agent systems: 9 tactics, 61 techniques, 40 attack classes. Each one is tied to something real: observed in the wild, reproduced in the lab, or adapted from established attacks. Built to complement MITRE ATT&CK and OWASP, not replace them.

9
Tactics
61
Techniques
40
Attack classes
16,935
Observations
46 of 61 techniques
Coverage dashboard

What the evidence says

Every technique carries an evidence grade and a source trail. These panels are computed live from the matrix at build time. Nothing here is estimated.

Evidence grade mix
61
techniques
Observed 16
Validated 42
Adapted 3
Observed in the wild · reproduced in lab · adapted from prior art.
Evidence by source
AgentPwn16714
HackMyAgent208
Shodan13
Records aggregated across all techniques.
Canary observations (last 30 days)
T-2001 · Direct Prompt Injection210
T-2003 · Role-Play Jailbreak210
T-4007 · Tool Impersonation and Squatting202
T-2007 · Multi-Turn Manipulation162
T-2006 · Unicode/Encoding Bypass154
T-1002 · Tool Discovery152
Observations from the Attack Prevalence Index · 30-day window. Counts canary fetches on honeypot payloads, crawlers included; not confirmed agent behaviour.
Defensive mapping
Techniques mapped to HackMyAgent checks61/61 · 100%
Techniques mapped to OASB controls61/61 · 100%

Each technique cites the HackMyAgent checks that target it and the OASB controls that mitigate it. A citation is a maintained cross-reference, not a tested guarantee that the technique is detected or mitigated in a given deployment. For coverage against OWASP and MITRE ATLAS, see Coverage & gaps.

The matrix

Kill-chain grid

Nine stages, left to right, the way an agent compromise actually unfolds. Search, filter by evidence grade, and sort by kill-chain order, evidence, or canary observations. Every cell links to the full technique dossier.

61 of 61 techniques
Sort
Evidence gradeObservedValidatedAdapted123canary observations
The standard

Nothing here is hand-waved

Every technique carries one of three evidence grades. The grade tells you exactly how much to trust it.

Observed16 techniques

Confirmed in real-world production systems, security incidents, or internet-wide exposure assessments.

Validated42 techniques

Reproduced in a controlled lab with documented, repeatable steps. The lab is public: DVAA

Adapted3 techniques

A well-understood traditional technique applied to the agent context. Not yet observed agent-specifically.

Positioning

Where this fits

Infrastructure layer

MITRE ATT&CK

Enterprise network and endpoint attacks. The layer below the agent.

Model layer

MITRE ATLAS

Adversarial ML and model-level attacks. The layer below the agent.

Agent layer

Agent Threat Matrix

Infrastructure, governance, protocols, memory, and identity: the agent layer, between model and user.