RAXE Labs

Independent AI threat research

RAXE Labs discovers new AI attack techniques and publishes what it finds – security advisories, threat landscape reports, and open detection signatures, every one mapped to MITRE ATLAS and OWASP ASI. The same signatures ship in the RAXE detection stack.

Security Advisories Threat Intelligence → Research Radar →
Research-to-Product

How discoveries become detections

1

Discover

Labs researchers find new AI vulnerability

2

Analyse

Characterise attack, map to MITRE ATLAS

3

Publish

Advisory + CVE + YAML detection signatures

4

Detect

Signatures join the RAXE detection stack as open, auditable rules

5 Research Streams

Where we focus

S1

Adversarial ML

Prompt injection, jailbreaking, role hijacking, instruction override, and model behaviour manipulation techniques.

S2

AI Agent Security

Tool-call abuse, MCP server exploitation, agent manipulation, multi-turn attacks, and autonomous system threats.

S3

Model Supply Chain

Training data poisoning, model backdoors, weight manipulation, and supply chain integrity threats.

S4

Prompt Injection Taxonomy

Systematic classification of injection techniques, encoding tricks, evasion patterns, and context manipulation methods.

S5

Agent Cloud Activity

Agent behaviour in cloud accounts: CloudTrail patterns for agent roles reading secrets, IAM misuse by autonomous agents, and AgentCore telemetry. Agents on AWS →

Sharing Terms

How our reports may be shared

Every RAXE Labs publication carries a Traffic Light Protocol marking that states exactly how far it may travel.

TLP:CLEAR

Public research

Advisories, threat reports, and radar issues published on this site. Unrestricted distribution – share them freely, with attribution.

TLP:AMBER

Design-partner briefings

Briefings shared with design partners may circulate within your organisation, sector peers, and partner network – never on public channels.

See the research running against your agents

Every advisory ships with open detection signatures, mapped to MITRE ATLAS and OWASP ASI. See them at work in the RAXE console, self-hosted in your environment. Early access – design partner programme.

Book a 30-min walkthrough → Talk to an Engineer