splunk/attack_range
A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk observed · 2026-08-28
Health v2 · maintenance only
84/100
- Activity 97
- Release rhythm 57
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 77.5
- age_days: 2678
- days_rel: 205
- days_push: 22
- n_releases_24m: 7
Adoption not part of the score
2545 stars · 418 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Splunk Attack Range is a tool that builds instrumented, vulnerable lab environments in the cloud (AWS, Azure, GCP) or locally using Terraform and Ansible, then simulates adversary attacks with tools like Atomic Red Team. The generated security telemetry is collected into Splunk for detection development, testing, and validation.
Use cases
- build a splunk lab environment in aws for detection engineering
- simulate mitre att&ck techniques and collect telemetry into splunk
- test and validate security detections against real attack data
- spin up a vulnerable windows and linux range for purple team exercises
- automate attack simulation in ci pipelines via rest api
- share a security lab with teammates over wireguard vpn
- generate realistic endpoint and network logs for detection rule tuning
When to choose
- you develop or test Splunk detections and need realistic attack telemetry
- you want a reproducible, production-like security lab without manual setup
- you run purple team exercises with Atomic Red Team simulations
- you need to validate detection rules before deploying them to production
When to avoid
- you need a general-purpose penetration testing lab without Splunk integration
- you cannot or do not want to incur cloud provider costs for lab infrastructure
- you only need attack simulation without log collection and detection testing
- you need a lightweight local sandbox rather than a full multi-server environment
Facets
application · maturity active
simulation security infrastructure-as-code deployment cli monitoring security penetration-testing cloud-computing self-hosted cloud windows python cli attack-simulation detection-engineering splunk atomic-red-team cyber-range terraform ansible purple-team telemetry lab-environment devops docker linux web-server
1 source
- readme: https://github.com/splunk/attack_range · fetched 2026-08-28 · d44578e89211
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| splunk/attack_range | main | 84 |
For agents
markdown · JSON · MCP: product_card(name="splunk/attack_range")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem