# atc-project/atomic-threat-coverage

Actionable analytics designed to combat threats

Repository: https://github.com/atc-project/atomic-threat-coverage
Canonical: https://ross.abutalabs.com/products/atomic-threat-coverage
Language: Python
License: Apache-2.0
License Family: permissive
Topics: mitre-attack, threat-model, threathunting, incidentresponse, threatintelligence, threatdetection
Last push: 2022-05-25T11:05:20+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 2821, "days_push": 1561, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1010, forks 159 (observed 2026-08-28T04:03:13.069190+00:00)

## What it is
Atomic Threat Coverage is a Python framework that automatically generates actionable security analytics from Detection, Response, Mitigation, and Simulation perspectives based on the MITRE ATT&CK adversary model. It produces Confluence and Markdown knowledge bases linking Sigma detection rules, data needs, logging policies, Atomic Red Team triggers, and response playbooks.

## Use cases
- generate a threat detection knowledge base from MITRE ATT&CK
- map Sigma detection rules to ATT&CK techniques
- build incident response playbooks linked to detections
- document logging policies needed for threat detection
- automatically publish security analytics to Confluence
- create threat hunting dashboards and triage visualizations

## When to choose
- your security team uses MITRE ATT&CK and wants automated, interconnected detection/response documentation
- you need to link Sigma rules, data collection requirements, and response playbooks in one knowledge base
- you want to automate publishing security analytics to Confluence or Markdown wikis

## When to avoid
- you need a SIEM or real-time alerting engine rather than documentation generation
- you want a simple rule repository without knowledge-base generation
- you don't use MITRE ATT&CK-based workflows

## Facets
- artifact type: framework
- maturity: maintenance
- function: security, documentation, workflow-automation, developer-tools
- domain: security, developer-tools, documentation
- platform: python, cli, cross-platform
- tags: mitre-attack, threat-hunting, incident-response, threat-intelligence, sigma-rules, siem, detection-rules, knowledge-base-generation

## Member repositories
- atc-project/atomic-threat-coverage (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:13.069190+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T07:11:55.897733+00:00, confidence not recorded.
  - readme: https://github.com/atc-project/atomic-threat-coverage (fetched 2026-08-28T04:03:13.069190+00:00, sha ab9ec6523a1e)
- Data as of 2026-08-30T08:39:29.467469+00:00.
