MITRE ATLAS Coverage: Pipelock Technique Mapping

Fourteen MITRE ATLAS techniques mapped to Pipelock controls, with the limits stated beside each partial mapping.

Ready to protect your own setup?

Pipelock maps fourteen MITRE ATLAS techniques. The mapping is specific to runtime controls and the evidence the product produces. It is not a claim of ATLAS-wide coverage.

Each row below comes from Pipelock’s built-in compliance mapping. “Covered” names a direct product mapping. “Partial” names a product contribution and the remaining gap.

Technique mapping

IDTechniqueStatusPipelock mapping
ATLAS01Gather RAG-Indexed TargetsCoveredDiscovery and normalized-text scanning expose RAG target harvesting.
ATLAS02Discover LLM System InformationCoveredReplayed assessments and simulation traces expose leaked system details.
ATLAS03Special Character SetsCoveredCanonicalized scans catch delimiter and control-character probing.
ATLAS04System Instruction KeywordsCoveredPrompt scanning and tool policy inspection surface instruction-keyword discovery.
ATLAS05LLM Prompt CraftingCoveredRed-team chains exercise prompt-crafting bypasses.
ATLAS06Retrieval Content CraftingCoveredContent scanning catches crafted retrieval payloads.
ATLAS07RAG PoisoningPartialResponse scanning, simulation, and attestation help detect the condition. External corpus ownership remains outside Pipelock’s control plane.
ATLAS08LLM Prompt ObfuscationCoveredNormalized scanning detects hidden or obfuscated instruction payloads.
ATLAS09LLM Trusted Output Components ManipulationPartialAttestation and assessment reduce trust abuse. Final user trust decisions remain outside the binary.
ATLAS10Citation ManipulationPartialAttested evidence and assessment can surface manipulated citations. Citation correctness depends on upstream retrieval sources.
ATLAS11False RAG Entry InjectionPartialResponse scanning, discovery, and simulation surface injected entries. The proxy does not own corpus write paths.
ATLAS12Data-Structure InjectionCoveredStructured input validation and policy enforcement catch schema exploitation.
ATLAS13Structured Self-ModelingCoveredDry-run and simulation make structured prompt manipulation easier to validate.
ATLAS14Agent Backdoor PersistencePartialThe flight recorder, attestation, and human review help surface persistence. Persistent agent state and scheduler control remain external.

What the partial mappings leave outside Pipelock

Pipelock can inspect, simulate, record, and attest to activity at its control points. It does not curate an external corpus, decide whether a reader should trust an output, validate the correctness of citations from an upstream retrieval source, or govern the write path for a corpus. It also does not fully govern long-lived agent state or scheduler control.

Those are deployment and system-ownership concerns. Treat the mapping as evidence for the controls Pipelock contributes, then add the controls that own the remaining surface.

Use the mapping as evidence

Pipelock’s compliance catalog feeds the assessment output and its framework summaries. The mapping names the technique IDs and the feature evidence behind them, so a reviewer can see which claim belongs to which control.

For the product’s broader evidence model, read Compliance Evidence Substrate. For the other framework mappings in the catalog, see AI Agent Regulatory Controls.

Further reading

Frequently asked questions

Does Pipelock cover all of MITRE ATLAS?
No. Pipelock maps fourteen MITRE ATLAS techniques. Nine are marked covered and five are marked partial. The partial mappings name the control Pipelock provides and the part that remains outside its control plane.
What does a covered MITRE ATLAS mapping mean?
It means the Pipelock mapping identifies specific product features and evidence for that technique. It does not claim that Pipelock prevents every instance of the technique in every deployment.
What does Pipelock not cover in its ATLAS mapping?
Pipelock does not own external corpus curation, consumer-side trust interpretation, citation correctness, corpus write paths, or long-lived agent state and scheduler control. Those limits appear on the affected technique rows.

Ready to protect your own setup?

See Assess reports →