{"adoption": {"forks": 159, "observed_at": "2026-08-28T04:03:13.069190+00:00", "stars": 1010}, "canonical_url": "https://ross.abutalabs.com/products/atomic-threat-coverage", "card": {"archived": false, "artifact_type": "framework", "description": "Actionable analytics designed to combat threats", "domain": ["security", "developer-tools", "documentation"], "enriched": true, "function": ["security", "documentation", "workflow-automation", "developer-tools"], "health_score": 20, "homepage": null, "language": "Python", "license": "Apache-2.0", "license_family": "permissive", "maturity": "maintenance", "member_repos": ["atc-project/atomic-threat-coverage"], "name": "atc-project/atomic-threat-coverage", "platform": ["python", "cli", "cross-platform"], "pushed_at": "2022-05-25T11:05:20+00:00", "repo": "atc-project/atomic-threat-coverage", "stars": 1010, "tags": ["mitre-attack", "threat-hunting", "incident-response", "threat-intelligence", "sigma-rules", "siem", "detection-rules", "knowledge-base-generation"], "topics": ["mitre-attack", "threat-model", "threathunting", "incidentresponse", "threatintelligence", "threatdetection"], "urls": [], "use_cases": ["generate a threat detection knowledge base from MITRE ATT&CK", "map Sigma detection rules to ATT&CK techniques", "build incident response playbooks linked to detections", "document logging policies needed for threat detection", "automatically publish security analytics to Confluence", "create threat hunting dashboards and triage visualizations"], "what_it_is": "Atomic Threat Coverage is a Python framework that automatically generates actionable security analytics from Detection, Response, Mitigation, and Simulation perspectives based on the MITRE ATT&CK adversary model. It produces Confluence and Markdown knowledge bases linking Sigma detection rules, data needs, logging policies, Atomic Red Team triggers, and response playbooks.", "when_to_avoid": ["you need a SIEM or real-time alerting engine rather than documentation generation", "you want a simple rule repository without knowledge-base generation", "you don't use MITRE ATT&CK-based workflows"], "when_to_choose": ["your security team uses MITRE ATT&CK and wants automated, interconnected detection/response documentation", "you need to link Sigma rules, data collection requirements, and response playbooks in one knowledge base", "you want to automate publishing security analytics to Confluence or Markdown wikis"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/atomic-threat-coverage", "repo": "atc-project/atomic-threat-coverage", "role": "main", "score": 32}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:03:13.069190+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T07:11:55.897733+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ab9ec6523a1e8568a5bbd36737b4af8be2fc5dec0313fffb4cb9654fba3cb6dd", "fetched_at": "2026-08-28T04:03:13.069190+00:00", "kind": "readme", "missing": false, "url": "https://github.com/atc-project/atomic-threat-coverage"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:03:13.069190+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T07:11:55.897733+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ab9ec6523a1e8568a5bbd36737b4af8be2fc5dec0313fffb4cb9654fba3cb6dd", "fetched_at": "2026-08-28T04:03:13.069190+00:00", "kind": "readme", "missing": false, "url": "https://github.com/atc-project/atomic-threat-coverage"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T07:11:55.897733+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ab9ec6523a1e8568a5bbd36737b4af8be2fc5dec0313fffb4cb9654fba3cb6dd", "fetched_at": "2026-08-28T04:03:13.069190+00:00", "kind": "readme", "missing": false, "url": "https://github.com/atc-project/atomic-threat-coverage"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:03:13.069190+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:03:13.069190+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:03:13.069190+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T07:11:55.897733+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ab9ec6523a1e8568a5bbd36737b4af8be2fc5dec0313fffb4cb9654fba3cb6dd", "fetched_at": "2026-08-28T04:03:13.069190+00:00", "kind": "readme", "missing": false, "url": "https://github.com/atc-project/atomic-threat-coverage"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:03:13.069190+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:03:13.069190+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T07:11:55.897733+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ab9ec6523a1e8568a5bbd36737b4af8be2fc5dec0313fffb4cb9654fba3cb6dd", "fetched_at": "2026-08-28T04:03:13.069190+00:00", "kind": "readme", "missing": false, "url": "https://github.com/atc-project/atomic-threat-coverage"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:03:13.069190+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:03:13.069190+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:03:13.069190+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T07:11:55.897733+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ab9ec6523a1e8568a5bbd36737b4af8be2fc5dec0313fffb4cb9654fba3cb6dd", "fetched_at": "2026-08-28T04:03:13.069190+00:00", "kind": "readme", "missing": false, "url": "https://github.com/atc-project/atomic-threat-coverage"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:03:13.069190+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:03:13.069190+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T07:11:55.897733+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ab9ec6523a1e8568a5bbd36737b4af8be2fc5dec0313fffb4cb9654fba3cb6dd", "fetched_at": "2026-08-28T04:03:13.069190+00:00", "kind": "readme", "missing": false, "url": "https://github.com/atc-project/atomic-threat-coverage"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T07:11:55.897733+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ab9ec6523a1e8568a5bbd36737b4af8be2fc5dec0313fffb4cb9654fba3cb6dd", "fetched_at": "2026-08-28T04:03:13.069190+00:00", "kind": "readme", "missing": false, "url": "https://github.com/atc-project/atomic-threat-coverage"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T07:11:55.897733+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ab9ec6523a1e8568a5bbd36737b4af8be2fc5dec0313fffb4cb9654fba3cb6dd", "fetched_at": "2026-08-28T04:03:13.069190+00:00", "kind": "readme", "missing": false, "url": "https://github.com/atc-project/atomic-threat-coverage"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T07:11:55.897733+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ab9ec6523a1e8568a5bbd36737b4af8be2fc5dec0313fffb4cb9654fba3cb6dd", "fetched_at": "2026-08-28T04:03:13.069190+00:00", "kind": "readme", "missing": false, "url": "https://github.com/atc-project/atomic-threat-coverage"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2821, "days_push": 1561, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 32, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}