LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1682: Query Public AI Services

Adversaries may query publicly accessible artificial intelligence (AI) services, such as large language models (LLMs), to support targeting and operations. In addition to searching websites or databases directly (i.e., Search Open Websites/Domains), adversaries may use AI services to synthesize, aggregate, and analyze publicly available information at scale. This may include identifying individuals or organizations to target, researching organizational structures and personnel, identifying technologies used by target organizations, researching business relationships to develop plausible pretexts for Social Engineering approaches, identifying contact information for use in Phishing or Phishing for Information, or gathering derogatory or sensitive information about individuals that may be used for extortion or coercion.CitationMSFT-AICitationGTIG AI Threat Tracker

Information gathered through AI services may be leveraged for other behaviors, such as establishing operational resources (i.e., Generate Content or Establish Accounts. For obtaining access to AI tools and services, see Artificial Intelligence.

EnterpriseT1682TechniqueObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Query Public AI Services describes adversaries using publicly accessible AI, including LLMs, to speed up reconnaissance. The business issue is not the AI tool itself; it is that public information about people, technologies, relationships, and contact paths can be aggregated into better targeting, phishing, social engineering, or coercion opportunities before the organization sees any intrusion telemetry.

Executive priority

Treat this as a pre-compromise risk management issue. Leaders should ask what public information would help an adversary identify executives, sensitive teams, business partners, exposed technologies, or believable pretexts. Priority should go to reducing unnecessary public disclosure, maintaining evidence of attack-surface review, and ensuring SOC and IR teams are prepared for AI-assisted reconnaissance feeding phishing or social engineering scenarios.

Technical view

This is an Enterprise ATT&CK reconnaissance technique on the PRE platform. MITRE does not provide official detection text, so defenders should not assume direct visibility into adversary AI queries. SOC and detection teams should validate indirect coverage: public exposure monitoring, external attack surface findings, brand/personnel impersonation monitoring, phishing and phishing-for-information detections, and IR enrichment that links suspicious outreach to publicly available organizational details. Relationship context includes DET0919 as a detection strategy, M1056 Pre-compromise as mitigation, and reported use by Kimsuky and APT42; use that context for threat-informed prioritization without assuming local targeting.

Likely telemetry

  • External attack surface and public web exposure inventories
  • Public website, careers page, press release, documentation, and metadata review records
  • Threat intelligence or brand monitoring related to impersonation, targeting, or exposed organizational details
  • Email security, phishing-reporting, and phishing-for-information case data
  • Web, DNS, or proxy logs only where AI service use occurs from organization-managed assets; these do not normally reveal external adversary queries

Detection direction

  • Acknowledge the primary blind spot: adversaries can query public AI services off-network, leaving little or no enterprise telemetry.
  • Use DET0919 relationship context as a prompt to define what your organization can detect indirectly rather than claiming direct detection.
  • Tune downstream detections for reconnaissance-enabled outcomes such as targeted phishing, phishing for information, social engineering pretexts, and suspicious contact with named personnel or business units.
  • Correlate suspicious outreach with recently published or overly detailed public information, such as org structure, technology disclosures, business relationships, or contact data.
  • Separate legitimate employee use of AI services from adversary reconnaissance; internal AI-service logs may support governance and data-leak prevention but are not proof of external adversary activity.

Mitigation priorities

  • Apply M1056 Pre-compromise principles: reduce the information that makes targeting easier before an intrusion begins.
  • Review and limit unnecessary public disclosure of personnel details, org charts, contact information, technology stacks, business relationships, and sensitive narratives that could support coercion or pretexting.
  • Maintain recurring external exposure reviews and document remediation for audit and risk evidence.
  • Prepare executives, help desks, recruiters, communications teams, and other public-facing staff for plausible AI-assisted social engineering and phishing-for-information attempts.
  • Feed exposure findings into SOC playbooks, incident response triage, and security awareness so suspicious outreach can be evaluated against known public data.
Additional notes and limits

The technique is important because AI can scale synthesis of information that was already public. The supplied relationships identify Kimsuky and APT42 as groups using this behavior and M1056 as the mitigation category, but they do not establish that any specific organization is being targeted. Defensive value comes from reducing exploitable public information and strengthening detection of the follow-on behaviors described by ATT&CK.

Official ATT&CK detection content is not provided for T1682. Direct enterprise detection is inherently limited when adversaries use third-party public AI services outside the victim environment. Local conclusions require organization-specific public exposure data, telemetry from downstream phishing/social-engineering events, and any available threat intelligence.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Query Public AI Services

Adversaries may query publicly accessible artificial intelligence (AI) services, such as large language models (LLMs), to support targeting and operations. In addition to searching websites or databases directly (i.e., Search Open Websites/Domains), adversaries may use AI services to synthesize, aggregate, and analyze publicly available information at scale. This may include identifying individuals or organizations to target, researching organizational structures and personnel, identifying technologies used by target organizations, researching business relationships to develop plausible pretexts for Social Engineering approaches, identifying contact information for use in Phishing or Phishing for Information, or gathering derogatory or sensitive information about individuals that may be used for extortion or coercion.CitationMSFT-AICitationGTIG AI Threat Tracker

Information gathered through AI services may be leveraged for other behaviors, such as establishing operational resources (i.e., Generate Content or Establish Accounts. For obtaining access to AI tools and services, see Artificial Intelligence.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
5b9e9621bce9bbbb...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.