# splunk/attack_range

A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk

Repository: https://github.com/splunk/attack_range
Canonical: https://ross.abutalabs.com/products/attack_range
Language: Python
License: Apache-2.0
License Family: permissive
Topics: attack-range, attack-simulation, adversary, simulation, simulations, detection, lab
Last push: 2026-08-11T19:22:44+00:00

## Health v2 (maintenance only)
Score: 84/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 97, release rhythm 57, longevity 100
- inputs: {"age_days": 2678, "days_push": 22, "days_rel": 205, "gap_med": 77.5, "n_releases_24m": 7}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2545, forks 418 (observed 2026-08-28T04:07:00.213807+00:00)

## What it is
Splunk Attack Range is a tool that builds instrumented, vulnerable lab environments in the cloud (AWS, Azure, GCP) or locally using Terraform and Ansible, then simulates adversary attacks with tools like Atomic Red Team. The generated security telemetry is collected into Splunk for detection development, testing, and validation.

## Use cases
- build a splunk lab environment in aws for detection engineering
- simulate mitre att&ck techniques and collect telemetry into splunk
- test and validate security detections against real attack data
- spin up a vulnerable windows and linux range for purple team exercises
- automate attack simulation in ci pipelines via rest api
- share a security lab with teammates over wireguard vpn
- generate realistic endpoint and network logs for detection rule tuning

## When to choose
- you develop or test Splunk detections and need realistic attack telemetry
- you want a reproducible, production-like security lab without manual setup
- you run purple team exercises with Atomic Red Team simulations
- you need to validate detection rules before deploying them to production

## When to avoid
- you need a general-purpose penetration testing lab without Splunk integration
- you cannot or do not want to incur cloud provider costs for lab infrastructure
- you only need attack simulation without log collection and detection testing
- you need a lightweight local sandbox rather than a full multi-server environment

## Facets
- artifact type: application
- maturity: active
- function: simulation, security, infrastructure-as-code, deployment, cli, monitoring
- domain: security, penetration-testing, cloud-computing, self-hosted
- platform: cloud, windows, python, cli
- tags: attack-simulation, detection-engineering, splunk, atomic-red-team, cyber-range, terraform, ansible, purple-team, telemetry, lab-environment, devops, docker, linux, web-server

## Member repositories
- splunk/attack_range (main) score 84

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:00.213807+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:24:37.252257+00:00, confidence not recorded.
  - readme: https://github.com/splunk/attack_range (fetched 2026-08-28T04:07:00.213807+00:00, sha d44578e89211)
- Data as of 2026-08-30T08:39:29.467469+00:00.
