Skip to content
← LibraryTechnique entry
AI-RAG-POISONPersistence

RAG Index Poisoning

Insert documents into the vector DB whose embeddings rank high for sensitive queries — the model retrieves and trusts attacker content.

§ Where this technique fits

AI-RAG-POISON is catalogued under the Persistence tactic of the offensive-security kill-chain. It appears in 3 approved dossiers in the registry, typically at step 1 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Valid Accounts
    T1078 · Initial Access
    seen 2×
  2. 02
    User Execution
    T1204 · Execution
    seen 1×