{"adoption": {"forks": 367, "observed_at": "2026-08-28T04:06:19.703035+00:00", "stars": 2156}, "canonical_url": "https://ross.abutalabs.com/products/adversary_emulation_library", "card": {"archived": false, "artifact_type": "dataset", "description": "An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs. ", "domain": ["security", "penetration-testing"], "enriched": true, "function": ["security", "penetration-testing", "developer-tools"], "health_score": 34, "homepage": "https://ctid.io/adversary-emulation", "language": "C", "license": "Apache-2.0", "license_family": "permissive", "maturity": "active", "member_repos": ["center-for-threat-informed-defense/adversary_emulation_library"], "name": "center-for-threat-informed-defense/adversary_emulation_library", "platform": ["cross-platform"], "pushed_at": "2025-05-28T19:37:18+00:00", "repo": "center-for-threat-informed-defense/adversary_emulation_library", "stars": 2156, "tags": ["mitre-attack", "red-team", "adversary-emulation", "threat-intelligence", "cyber-threat-intelligence", "purple-team"], "topics": ["ctid", "cybersecurity", "threat-informed-defense", "mitre-attack", "red-team", "cyber-threat-intelligence", "adversary-emulation", "adversary-emulation-plans"], "urls": [], "use_cases": ["test my defenses against real-world adversary TTPs", "run a red team exercise emulating APT29", "build purple team exercises based on MITRE ATT&CK", "emulate webshell behaviors to validate detections", "prioritize security controls based on actual threat actor behavior"], "what_it_is": "An open library of adversary emulation plans from MITRE's Center for Threat-Informed Defense, mapping real-world adversary TTPs to MITRE ATT&CK. It includes full emulation plans for specific threat actors and micro emulation plans for compound behaviors like webshells.", "when_to_avoid": ["you need an automated attack execution framework - this provides plans, not tooling", "you want vulnerability scanning or general penetration testing tooling", "you need adversary intelligence beyond the included summaries"], "when_to_choose": ["you want structured, ATT&CK-mapped emulation plans for red or purple teaming", "you need to validate detections against real-world adversary behavior", "you want free, vendor-neutral threat emulation content"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/adversary_emulation_library", "repo": "center-for-threat-informed-defense/adversary_emulation_library", "role": "main", "score": 33}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:06:19.703035+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T02:50:27.649003+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d49c8dad741388839f61ee1c40ac9ee356cbc8ecf4974590ab56cd051469c6dd", "fetched_at": "2026-08-28T04:06:19.703035+00:00", "kind": "readme", "missing": false, "url": "https://github.com/center-for-threat-informed-defense/adversary_emulation_library"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:06:19.703035+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T02:50:27.649003+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d49c8dad741388839f61ee1c40ac9ee356cbc8ecf4974590ab56cd051469c6dd", "fetched_at": "2026-08-28T04:06:19.703035+00:00", "kind": "readme", "missing": false, "url": "https://github.com/center-for-threat-informed-defense/adversary_emulation_library"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T02:50:27.649003+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d49c8dad741388839f61ee1c40ac9ee356cbc8ecf4974590ab56cd051469c6dd", "fetched_at": "2026-08-28T04:06:19.703035+00:00", "kind": "readme", "missing": false, "url": "https://github.com/center-for-threat-informed-defense/adversary_emulation_library"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:06:19.703035+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:06:19.703035+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:06:19.703035+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T02:50:27.649003+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d49c8dad741388839f61ee1c40ac9ee356cbc8ecf4974590ab56cd051469c6dd", "fetched_at": "2026-08-28T04:06:19.703035+00:00", "kind": "readme", "missing": false, "url": "https://github.com/center-for-threat-informed-defense/adversary_emulation_library"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:06:19.703035+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:06:19.703035+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T02:50:27.649003+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d49c8dad741388839f61ee1c40ac9ee356cbc8ecf4974590ab56cd051469c6dd", "fetched_at": "2026-08-28T04:06:19.703035+00:00", "kind": "readme", "missing": false, "url": "https://github.com/center-for-threat-informed-defense/adversary_emulation_library"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:06:19.703035+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:06:19.703035+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:06:19.703035+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T02:50:27.649003+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d49c8dad741388839f61ee1c40ac9ee356cbc8ecf4974590ab56cd051469c6dd", "fetched_at": "2026-08-28T04:06:19.703035+00:00", "kind": "readme", "missing": false, "url": "https://github.com/center-for-threat-informed-defense/adversary_emulation_library"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:06:19.703035+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:06:19.703035+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T02:50:27.649003+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d49c8dad741388839f61ee1c40ac9ee356cbc8ecf4974590ab56cd051469c6dd", "fetched_at": "2026-08-28T04:06:19.703035+00:00", "kind": "readme", "missing": false, "url": "https://github.com/center-for-threat-informed-defense/adversary_emulation_library"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T02:50:27.649003+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d49c8dad741388839f61ee1c40ac9ee356cbc8ecf4974590ab56cd051469c6dd", "fetched_at": "2026-08-28T04:06:19.703035+00:00", "kind": "readme", "missing": false, "url": "https://github.com/center-for-threat-informed-defense/adversary_emulation_library"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T02:50:27.649003+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d49c8dad741388839f61ee1c40ac9ee356cbc8ecf4974590ab56cd051469c6dd", "fetched_at": "2026-08-28T04:06:19.703035+00:00", "kind": "readme", "missing": false, "url": "https://github.com/center-for-threat-informed-defense/adversary_emulation_library"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T02:50:27.649003+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d49c8dad741388839f61ee1c40ac9ee356cbc8ecf4974590ab56cd051469c6dd", "fetched_at": "2026-08-28T04:06:19.703035+00:00", "kind": "readme", "missing": false, "url": "https://github.com/center-for-threat-informed-defense/adversary_emulation_library"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 23, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2318, "days_push": 462, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 33, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}