Ross ROSS = Recommend OSS · open-source software intelligence for agents

center-for-threat-informed-defense/adversary_emulation_library resource

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs. observed · 2026-08-28

github.com/center-for-threat-informed-defense/adversary_emulation_library · homepage · C · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

33/100

  • Activity 23
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2318
  • days_rel: n/a
  • days_push: 462
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2156 stars · 367 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

An open library of adversary emulation plans from MITRE's Center for Threat-Informed Defense, mapping real-world adversary TTPs to MITRE ATT&CK. It includes full emulation plans for specific threat actors and micro emulation plans for compound behaviors like webshells.

Use cases

  • test my defenses against real-world adversary TTPs
  • run a red team exercise emulating APT29
  • build purple team exercises based on MITRE ATT&CK
  • emulate webshell behaviors to validate detections
  • prioritize security controls based on actual threat actor behavior

When to choose

  • you want structured, ATT&CK-mapped emulation plans for red or purple teaming
  • you need to validate detections against real-world adversary behavior
  • you want free, vendor-neutral threat emulation content

When to avoid

  • you need an automated attack execution framework - this provides plans, not tooling
  • you want vulnerability scanning or general penetration testing tooling
  • you need adversary intelligence beyond the included summaries

Facets

dataset · maturity active

security penetration-testing developer-tools security penetration-testing cross-platform mitre-attack red-team adversary-emulation threat-intelligence cyber-threat-intelligence purple-team

1 source

Member repositories

For agents

markdown · JSON · MCP: product_card(name="center-for-threat-informed-defense/adversary_emulation_library")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem