center-for-threat-informed-defense/adversary_emulation_library resource
An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs. observed · 2026-08-28
Health v2 · maintenance only
33/100
- Activity 23
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2318
- days_rel: n/a
- days_push: 462
- n_releases_24m: 0
Adoption not part of the score
2156 stars · 367 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
An open library of adversary emulation plans from MITRE's Center for Threat-Informed Defense, mapping real-world adversary TTPs to MITRE ATT&CK. It includes full emulation plans for specific threat actors and micro emulation plans for compound behaviors like webshells.
Use cases
- test my defenses against real-world adversary TTPs
- run a red team exercise emulating APT29
- build purple team exercises based on MITRE ATT&CK
- emulate webshell behaviors to validate detections
- prioritize security controls based on actual threat actor behavior
When to choose
- you want structured, ATT&CK-mapped emulation plans for red or purple teaming
- you need to validate detections against real-world adversary behavior
- you want free, vendor-neutral threat emulation content
When to avoid
- you need an automated attack execution framework - this provides plans, not tooling
- you want vulnerability scanning or general penetration testing tooling
- you need adversary intelligence beyond the included summaries
Facets
dataset · maturity active
security penetration-testing developer-tools security penetration-testing cross-platform mitre-attack red-team adversary-emulation threat-intelligence cyber-threat-intelligence purple-team
1 source
- readme: https://github.com/center-for-threat-informed-defense/adversary_emulation_library · fetched 2026-08-28 · d49c8dad7413
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| center-for-threat-informed-defense/adversary_emulation_library | main | 33 |
For agents
markdown · JSON · MCP: product_card(name="center-for-threat-informed-defense/adversary_emulation_library")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem