T-7004ValidatedActive241 evidence records

Memory Dump

Dump the agent's memory store to extract stored data, credentials, and conversation history

Tactic

Collection · Stage 7

Gather and stage data from databases, file systems, and APIs

Attack class

MEM-POISON

Injecting malicious entries into agent persistent memory to maintain control across sessions

Evidence grade
Validated

Reproduced in a controlled lab environment (DVAA) with documented steps.

DVAA validation

MemoryBot memory dump

Reproductions in Damn Vulnerable AI Agent, the OpenA2A intentionally-broken agent for kill-chain validation.

Telemetry

Recent observations

130
records · last 30 days

Technique-attributed observations from the AgentPwn + TrapMyAgent fleet, classified into Threat Matrix techniques by the registry evidence bridge. See the Attack Prevalence Index for the full distribution.

Honeypot

AgentPwn coverage

Live
memory-weaponizationagentpwn.com/learn ↗

An AgentPwn trap page produces a payload tagged with this technique class. Following the AgentPwn taxonomy of trap pages shows what an agent encounters.

Memory-dump payloads extract the agent's stored conversation state.

Provenance

Evidence by source

AgentPwn
241 records
Trail

Evidence timeline

25 most recent of 241
AgentPwn

Client fetched the canary embedded in APWN-DE-004 on agentpwn.com (data-exfiltration tier 4; classified browser/claimed)

Aug 8, 2026
AgentPwn

Client fetched the canary embedded in APWN-DE-004 on agentpwn.com (data-exfiltration tier 4; classified browser/claimed)

Aug 8, 2026
AgentPwn

Client fetched the canary embedded in APWN-DE-004 on agentpwn.com (data-exfiltration tier 4; classified browser/claimed)

Aug 8, 2026
AgentPwn

Client fetched a data-exfiltration canary on agentpwn.com (category-level: the lure carried no payload id; classified browser/claimed)

Aug 7, 2026
AgentPwn

Client fetched a data-exfiltration canary on agentpwn.com (category-level: the lure carried no payload id; classified browser/claimed)

Aug 7, 2026
AgentPwn

Client fetched a data-exfiltration canary on agentpwn.com (category-level: the lure carried no payload id; classified browser/claimed)

Aug 7, 2026
AgentPwn

Client fetched a data-exfiltration canary on agentpwn.com (category-level: the lure carried no payload id; classified browser/claimed)

Aug 7, 2026
AgentPwn

Client fetched a data-exfiltration canary on agentpwn.com (category-level: the lure carried no payload id; classified browser/claimed)

Aug 7, 2026
AgentPwn

Client fetched the canary embedded in APWN-DE-004 on agentpwn.com (data-exfiltration tier 4; classified browser/claimed)

Aug 6, 2026
AgentPwn

Client fetched the canary embedded in APWN-DE-004 on agentpwn.com (data-exfiltration tier 4; classified browser/claimed)

Aug 6, 2026
AgentPwn

Client fetched a data-exfiltration canary on agentpwn.com (category-level: the lure carried no payload id; classified browser/claimed)

Aug 6, 2026
AgentPwn

Client fetched the canary embedded in APWN-DE-004 on agentpwn.com (data-exfiltration tier 4; classified browser/claimed)

Aug 6, 2026
AgentPwn

Client fetched a data-exfiltration canary on agentpwn.com (category-level: the lure carried no payload id; classified browser/claimed)

Aug 5, 2026
AgentPwn

Client fetched the canary embedded in APWN-DE-004 on agentpwn.com (data-exfiltration tier 4; classified browser/claimed)

Jul 30, 2026
AgentPwn

Client fetched a data-exfiltration canary on agentpwn.com (category-level: the lure carried no payload id; classified browser/claimed)

Jul 30, 2026
AgentPwn

Client fetched a data-exfiltration canary on agentpwn.com (category-level: the lure carried no payload id; classified browser/claimed)

Jul 30, 2026
AgentPwn

Client fetched a data-exfiltration canary on agentpwn.com (category-level: the lure carried no payload id; classified browser/claimed)

Jul 29, 2026
AgentPwn

Client fetched the canary embedded in APWN-DE-004 on agentpwn.com (data-exfiltration tier 4; classified browser/claimed)

Jul 29, 2026
AgentPwn

Client fetched the canary embedded in APWN-DE-004 on agentpwn.com (data-exfiltration tier 4; classified llm_crawler/claimed)

Jul 28, 2026
AgentPwn

Client fetched the canary embedded in APWN-DE-004 on agentpwn.com (data-exfiltration tier 4; classified browser/claimed)

Jul 27, 2026
AgentPwn

Client fetched a data-exfiltration canary on agentpwn.com (category-level: the lure carried no payload id; classified browser/claimed)

Jul 25, 2026
AgentPwn

Client fetched a data-exfiltration canary on agentpwn.com (category-level: the lure carried no payload id; classified browser/claimed)

Jul 25, 2026
AgentPwn

Client fetched a data-exfiltration canary on agentpwn.com (category-level: the lure carried no payload id; classified browser/claimed)

Jul 25, 2026
AgentPwn

Client fetched the canary embedded in APWN-DE-004 on agentpwn.com (data-exfiltration tier 4; classified browser/claimed)

Jul 24, 2026
AgentPwn

Client fetched the canary embedded in APWN-DE-004 on agentpwn.com (data-exfiltration tier 4; classified browser/claimed)

Jul 19, 2026
Detect

Detection · HackMyAgent

Live5 live · 0 queued
MEM-001MEM-002MEM-003MEM-004MEM-005
npx hackmyagent secure --ciLive = implemented in hackmyagent; queued = declared
Defend

Defense · OASB controls

Live4 live · 0 queued
Live = documented at oasb.ai; queued = declared
Reference

How to cite

AI Agent Threat Matrix T-7004 (Memory Dump). OpenA2A, 2026. https://threats.opena2a.org/techniques/T-7004