{"adoption": {"forks": 418, "observed_at": "2026-08-28T04:07:00.213807+00:00", "stars": 2545}, "canonical_url": "https://ross.abutalabs.com/products/attack_range", "card": {"archived": false, "artifact_type": "application", "description": "A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk ", "domain": ["security", "penetration-testing", "cloud-computing", "self-hosted"], "enriched": true, "function": ["simulation", "security", "infrastructure-as-code", "deployment", "cli", "monitoring"], "health_score": 95, "homepage": null, "language": "Python", "license": "Apache-2.0", "license_family": "permissive", "maturity": "active", "member_repos": ["splunk/attack_range"], "name": "splunk/attack_range", "platform": ["cloud", "windows", "python", "cli"], "pushed_at": "2026-08-11T19:22:44+00:00", "repo": "splunk/attack_range", "stars": 2545, "tags": ["attack-simulation", "detection-engineering", "splunk", "atomic-red-team", "cyber-range", "terraform", "ansible", "purple-team", "telemetry", "lab-environment", "devops", "docker", "linux", "web-server"], "topics": ["attack-range", "attack-simulation", "adversary", "simulation", "simulations", "detection", "lab"], "urls": [], "use_cases": ["build a splunk lab environment in aws for detection engineering", "simulate mitre att&ck techniques and collect telemetry into splunk", "test and validate security detections against real attack data", "spin up a vulnerable windows and linux range for purple team exercises", "automate attack simulation in ci pipelines via rest api", "share a security lab with teammates over wireguard vpn", "generate realistic endpoint and network logs for detection rule tuning"], "what_it_is": "Splunk Attack Range is a tool that builds instrumented, vulnerable lab environments in the cloud (AWS, Azure, GCP) or locally using Terraform and Ansible, then simulates adversary attacks with tools like Atomic Red Team. The generated security telemetry is collected into Splunk for detection development, testing, and validation.", "when_to_avoid": ["you need a general-purpose penetration testing lab without Splunk integration", "you cannot or do not want to incur cloud provider costs for lab infrastructure", "you only need attack simulation without log collection and detection testing", "you need a lightweight local sandbox rather than a full multi-server environment"], "when_to_choose": ["you develop or test Splunk detections and need realistic attack telemetry", "you want a reproducible, production-like security lab without manual setup", "you run purple team exercises with Atomic Red Team simulations", "you need to validate detection rules before deploying them to production"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/attack_range", "repo": "splunk/attack_range", "role": "main", "score": 84}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.213807+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T02:24:37.252257+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d44578e89211051750a2759f066027549fc1d04214405db8b7b51a3f00f8ab3c", "fetched_at": "2026-08-28T04:07:00.213807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/attack_range"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.213807+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T02:24:37.252257+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d44578e89211051750a2759f066027549fc1d04214405db8b7b51a3f00f8ab3c", "fetched_at": "2026-08-28T04:07:00.213807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/attack_range"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T02:24:37.252257+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d44578e89211051750a2759f066027549fc1d04214405db8b7b51a3f00f8ab3c", "fetched_at": "2026-08-28T04:07:00.213807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/attack_range"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.213807+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.213807+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.213807+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T02:24:37.252257+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d44578e89211051750a2759f066027549fc1d04214405db8b7b51a3f00f8ab3c", "fetched_at": "2026-08-28T04:07:00.213807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/attack_range"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.213807+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.213807+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T02:24:37.252257+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d44578e89211051750a2759f066027549fc1d04214405db8b7b51a3f00f8ab3c", "fetched_at": "2026-08-28T04:07:00.213807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/attack_range"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.213807+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.213807+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.213807+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T02:24:37.252257+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d44578e89211051750a2759f066027549fc1d04214405db8b7b51a3f00f8ab3c", "fetched_at": "2026-08-28T04:07:00.213807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/attack_range"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.213807+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:07:00.213807+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T02:24:37.252257+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d44578e89211051750a2759f066027549fc1d04214405db8b7b51a3f00f8ab3c", "fetched_at": "2026-08-28T04:07:00.213807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/attack_range"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T02:24:37.252257+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d44578e89211051750a2759f066027549fc1d04214405db8b7b51a3f00f8ab3c", "fetched_at": "2026-08-28T04:07:00.213807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/attack_range"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T02:24:37.252257+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d44578e89211051750a2759f066027549fc1d04214405db8b7b51a3f00f8ab3c", "fetched_at": "2026-08-28T04:07:00.213807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/attack_range"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T02:24:37.252257+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d44578e89211051750a2759f066027549fc1d04214405db8b7b51a3f00f8ab3c", "fetched_at": "2026-08-28T04:07:00.213807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/attack_range"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 97, "longevity": 100, "rhythm": 57}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2678, "days_push": 22, "days_rel": 205, "gap_med": 77.5, "n_releases_24m": 7}, "score": 84, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}