00Threat Intelligence

the LLM ATT&CK
navigator.

Where does AI actually move the needle for an adversary — and where is it still hype? This is ankya's living map of AI-enabled cyber threats across two surfaces: AI wielded as a weapon against the classic intrusion lifecycle and AI itself as a target. Every cell is graded by the uplift we assess today. Select any technique to read the analysis.

MITRE ATT&CK® · MITRE ATLAS™ · ANKYA ANALYTIC OVERLAY · GRADED 0–4 · ASSESSMENT v2026.06

01The Instrument

two surfaces, one map.

AI upliftlowcritical
37
techniques
12
high / critical
14
tactics
Reconnaissance
TA00433
Resource Development
TA00423
Initial Access
TA00013
Execution
TA00023
Persistence
TA00032
Privilege Escalation
TA00042
Defense Evasion
TA00053
Credential Access
TA00062
Discovery
TA00073
Lateral Movement
TA00082
Collection
TA00093
Command & Control
TA00113
Exfiltration
TA00102
Impact
TA00403
02Methodology

a judgement, stated plainly.

Tactics and technique identifiers are drawn from MITRE ATT&CK® (Enterprise) and MITRE ATLAS™. The 0–4 grade on each cell is ankya's analytic overlay — a judgement of how materially current large language models change an adversary's cost, speed, scale or reach for that technique, weighted toward observed, attributed activity over speculation. It is not a MITRE rating.

The picture moves quickly; treat it as a snapshot for orientation, not a control inventory. Where the public matrices don't yet name a pattern we are seeing, we assign a synthetic identifier and say so.

Built on MITRE ATT&CK® & MITRE ATLAS™ — © The MITRE Corporationatlas.mitre.org

Assessment log

  • v2026.06Initial public release — 50 techniques graded across ATT&CK and ATLAS.

PRINT THIS PAGE FOR THE FULL WRITTEN BRIEF — EVERY TECHNIQUE, EVERY GRADE.

the map is public. the test is yours.

If your deployment touches the hot cells on this matrix, we'll attack it before an adversary does — and show you exactly how it held.

See How We Red-Team

or request a red-team scope directly