Ross ROSS = Recommend OSS · open-source software intelligence for agents

splunk/attack_range

A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk observed · 2026-08-28

github.com/splunk/attack_range · Python · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

84/100

  • Activity 97
  • Release rhythm 57
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 77.5
  • age_days: 2678
  • days_rel: 205
  • days_push: 22
  • n_releases_24m: 7

Full methodology

Adoption not part of the score

2545 stars · 418 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Splunk Attack Range is a tool that builds instrumented, vulnerable lab environments in the cloud (AWS, Azure, GCP) or locally using Terraform and Ansible, then simulates adversary attacks with tools like Atomic Red Team. The generated security telemetry is collected into Splunk for detection development, testing, and validation.

Use cases

  • build a splunk lab environment in aws for detection engineering
  • simulate mitre att&ck techniques and collect telemetry into splunk
  • test and validate security detections against real attack data
  • spin up a vulnerable windows and linux range for purple team exercises
  • automate attack simulation in ci pipelines via rest api
  • share a security lab with teammates over wireguard vpn
  • generate realistic endpoint and network logs for detection rule tuning

When to choose

  • you develop or test Splunk detections and need realistic attack telemetry
  • you want a reproducible, production-like security lab without manual setup
  • you run purple team exercises with Atomic Red Team simulations
  • you need to validate detection rules before deploying them to production

When to avoid

  • you need a general-purpose penetration testing lab without Splunk integration
  • you cannot or do not want to incur cloud provider costs for lab infrastructure
  • you only need attack simulation without log collection and detection testing
  • you need a lightweight local sandbox rather than a full multi-server environment

Facets

application · maturity active

simulation security infrastructure-as-code deployment cli monitoring security penetration-testing cloud-computing self-hosted cloud windows python cli attack-simulation detection-engineering splunk atomic-red-team cyber-range terraform ansible purple-team telemetry lab-environment devops docker linux web-server

1 source

Member repositories

RepositoryRoleHealth v2
splunk/attack_rangemain84

For agents

markdown · JSON · MCP: product_card(name="splunk/attack_range")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem