TL;DR: AI-related detections in Workbench now carry MITRE ATLAS tactic and technique labels alongside ATT&CK, with a one-primary-technique rule and behavior-first labeling that helps analysts triage AI-shaped activity faster, according to Expel. That matters because AI attack surfaces are now operational, but detection engineering still depends on telemetry, intent, and human review.
NHIMG editorial — based on content published by Expel: AI detections in Workbench mapped to MITRE ATLAS and ATT&CK
Questions worth separating out
Q: How should security teams handle prompt injection in AI systems?
A: Treat prompt injection as an authorisation problem, not only a content problem.
Q: Why do AI SOC agents complicate identity governance more than traditional SOAR?
A: Because they do more than execute predefined steps.
Q: What breaks when teams rely only on control plane logs for AI security?
A: Teams miss the reason an action happened.
Practitioner guidance
- Map AI detections to a primary technique Assign one primary MITRE ATLAS or ATT&CK technique to each AI-related detection, then attach adjacent techniques as supporting context.
- Collect prompt and tool-use telemetry Instrument both control plane and content plane signals so analysts can see prompt text, tool invocation, and the relationship between user intent and agent action.
- Treat AI assistants as governed identities Inventory assistants and agents that can reach internal systems, assign owners, and define access scope, approval paths, and logging expectations.
What's in the full article
Expel's full analysis covers the operational detail this post intentionally leaves at the framework level:
- How Workbench maps AI-related detections to MITRE ATLAS and ATT&CK in practice
- What the control plane and content plane signals look like in the detection pipeline
- Why some ATLAS tactics are structurally invisible from SOC telemetry alone
- How early-access Claude signals are being incorporated into detection workflows
👉 Read Expel's analysis of MITRE ATLAS mapping for AI detections →
AI detection labels and ATLAS mapping: are SOC teams ready?
Explore further
AI detection now needs an identity lens, not just an alerting lens. Once assistants and agents are wired into internal tools, they start behaving like governed systems with permissions, scope, and operational consequences. That makes AI telemetry inseparable from identity governance, especially where prompt injection or tool misuse can turn a model into an unwitting executor. Practitioners should treat AI-connected systems as identity-bearing workloads with visible boundaries.
A question worth separating out:
Q: Who should own the decision when AI suggests removing or granting access?
A: The access owner, manager, or control owner should own the decision, depending on the entitlement type. AI can recommend removal, reduction, or escalation, but governance remains a human responsibility. That separation preserves accountability and prevents the organisation from confusing workflow speed with control effectiveness.
👉 Read our full editorial: AI detection labels need ATLAS context for agentic attack triage