mrwadams/attackgen
AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK framework. The tool generates tailored incident response scenarios based on user-selected threat actor groups and your organisation's details. observed · 2026-08-28
Health v2 · maintenance only
95/100
- Activity 99
- Release rhythm 99
- Longevity 80
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 6
- age_days: 1121
- days_rel: 11
- days_push: 11
- n_releases_24m: 6
Adoption not part of the score
1237 stars · 169 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
AttackGen is a Streamlit-based cybersecurity tool that uses large language models to generate tailored incident response testing scenarios based on MITRE ATT&CK and ATLAS frameworks. It lets users select threat actor groups and provide organisation details to produce downloadable tabletop exercise scenarios via multiple LLM providers.
Use cases
- generate incident response tabletop exercise scenarios
- create purple team testing scenarios from MITRE ATT&CK techniques
- simulate AI insider threat incidents for response training
- tailor cyber incident scenarios to my organisation's size and industry
- generate scenarios for specific threat actor groups
- run incident response drills using LLM-generated scenarios
- create AI/ML-specific attack response exercises
When to choose
- you need tailored incident response or tabletop exercise scenarios quickly
- your team trains against MITRE ATT&CK, ICS, or ATLAS techniques
- you want LLM-generated security scenarios with multiple provider options
- you run purple team exercises and need scenario templates
When to avoid
- you need automated technical attack simulation rather than written scenarios
- you require a fully offline tool without any LLM API access
- you need a commercial incident response platform with ticketing and workflow
Facets
application · maturity active
llm-inference prompt-engineering security chat-interface mcp security artificial-intelligence large-language-models developer-tools python self-hosted mitre-attack incident-response purple-team tabletop-exercise threat-intelligence streamlit generative-ai cybersecurity docker web-server
1 source
- readme: https://github.com/mrwadams/attackgen · fetched 2026-08-28 · 5378121813bc
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| mrwadams/attackgen | main | 95 |
For agents
markdown · JSON · MCP: product_card(name="mrwadams/attackgen")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem