{"adoption": {"forks": 354, "observed_at": "2026-08-28T04:04:29.509737+00:00", "stars": 1357}, "canonical_url": "https://ross.abutalabs.com/products/attackdetection", "card": {"archived": true, "artifact_type": "dataset", "description": "Attack Detection", "domain": ["security", "penetration-testing", "networking"], "enriched": true, "function": ["security", "monitoring", "vulnerability-scanning"], "health_score": 10, "homepage": null, "language": null, "license": "NOASSERTION", "license_family": "other", "maturity": "maintenance", "member_repos": ["ptresearch/AttackDetection"], "name": "ptresearch/AttackDetection", "platform": ["self-hosted"], "pushed_at": "2022-08-31T09:26:21+00:00", "repo": "ptresearch/AttackDetection", "stars": 1357, "tags": ["suricata", "intrusion-detection", "network-detection", "ids-rules", "poc-exploits", "threat-detection", "pcap-samples", "linux"], "topics": [], "urls": [], "use_cases": ["detect network exploitation attempts with suricata rules", "find ids rules for known cves and 0-days", "get pcap traffic samples to test intrusion detection", "improve network-layer detection of malware c2 traffic", "reproduce vulnerabilities and verify detection coverage"], "what_it_is": "A collection of Suricata IDS rules, PoC exploits, and network traffic samples from Positive Technologies' Attack Detection Team. The ruleset targets detection of vulnerabilities, 0-days, malware, and attacker TTPs at the network layer.", "when_to_avoid": ["you use an IDS other than Suricata without rule conversion", "you need a supported, SLA-backed commercial ruleset", "you want endpoint rather than network detection"], "when_to_choose": ["you run Suricata and want community rules covering recent vulnerabilities and attacker TTPs", "you need PoC exploits and traffic samples to validate IDS coverage", "you research network-based detection of exploits and malware"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/attackdetection", "repo": "ptresearch/AttackDetection", "role": "main", "score": 10}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:29.509737+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T04:41:51.538827+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2e400f5f5aaa08b73d0a9c83dbc1a3e19b163c6b9380cceaad6ff1882d1f4108", "fetched_at": "2026-08-28T04:04:29.509737+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ptresearch/AttackDetection"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:29.509737+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T04:41:51.538827+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2e400f5f5aaa08b73d0a9c83dbc1a3e19b163c6b9380cceaad6ff1882d1f4108", "fetched_at": "2026-08-28T04:04:29.509737+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ptresearch/AttackDetection"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T04:41:51.538827+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2e400f5f5aaa08b73d0a9c83dbc1a3e19b163c6b9380cceaad6ff1882d1f4108", "fetched_at": "2026-08-28T04:04:29.509737+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ptresearch/AttackDetection"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:29.509737+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:29.509737+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:29.509737+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T04:41:51.538827+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2e400f5f5aaa08b73d0a9c83dbc1a3e19b163c6b9380cceaad6ff1882d1f4108", "fetched_at": "2026-08-28T04:04:29.509737+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ptresearch/AttackDetection"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:29.509737+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:29.509737+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T04:41:51.538827+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2e400f5f5aaa08b73d0a9c83dbc1a3e19b163c6b9380cceaad6ff1882d1f4108", "fetched_at": "2026-08-28T04:04:29.509737+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ptresearch/AttackDetection"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:29.509737+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:29.509737+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:29.509737+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T04:41:51.538827+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2e400f5f5aaa08b73d0a9c83dbc1a3e19b163c6b9380cceaad6ff1882d1f4108", "fetched_at": "2026-08-28T04:04:29.509737+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ptresearch/AttackDetection"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:29.509737+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:29.509737+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T04:41:51.538827+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2e400f5f5aaa08b73d0a9c83dbc1a3e19b163c6b9380cceaad6ff1882d1f4108", "fetched_at": "2026-08-28T04:04:29.509737+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ptresearch/AttackDetection"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T04:41:51.538827+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2e400f5f5aaa08b73d0a9c83dbc1a3e19b163c6b9380cceaad6ff1882d1f4108", "fetched_at": "2026-08-28T04:04:29.509737+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ptresearch/AttackDetection"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T04:41:51.538827+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2e400f5f5aaa08b73d0a9c83dbc1a3e19b163c6b9380cceaad6ff1882d1f4108", "fetched_at": "2026-08-28T04:04:29.509737+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ptresearch/AttackDetection"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T04:41:51.538827+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "2e400f5f5aaa08b73d0a9c83dbc1a3e19b163c6b9380cceaad6ff1882d1f4108", "fetched_at": "2026-08-28T04:04:29.509737+00:00", "kind": "readme", "missing": false, "url": "https://github.com/ptresearch/AttackDetection"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["no_releases", "archived", "no_license"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 3814, "days_push": 1463, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 10, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}