# mrwadams/attackgen

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK framework. The tool generates tailored incident response scenarios based on user-selected threat actor groups and your organisation's details.

Repository: https://github.com/mrwadams/attackgen
Canonical: https://ross.abutalabs.com/products/attackgen
Language: Python
License: GPL-3.0
License Family: copyleft
Topics: ai-security, cybersecurity, generative-ai, incident-response, llm, mitre-atlas, mitre-attack, purple-team, security-tools, streamlit, tabletop-exercise, threat-intelligence
Last push: 2026-08-22T07:53:18+00:00

## Health v2 (maintenance only)
Score: 95/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 99, release rhythm 99, longevity 80
- inputs: {"age_days": 1121, "days_push": 11, "days_rel": 11, "gap_med": 6, "n_releases_24m": 6}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1237, forks 169 (observed 2026-08-28T04:04:05.339493+00:00)

## What it is
AttackGen is a Streamlit-based cybersecurity tool that uses large language models to generate tailored incident response testing scenarios based on MITRE ATT&CK and ATLAS frameworks. It lets users select threat actor groups and provide organisation details to produce downloadable tabletop exercise scenarios via multiple LLM providers.

## Use cases
- generate incident response tabletop exercise scenarios
- create purple team testing scenarios from MITRE ATT&CK techniques
- simulate AI insider threat incidents for response training
- tailor cyber incident scenarios to my organisation's size and industry
- generate scenarios for specific threat actor groups
- run incident response drills using LLM-generated scenarios
- create AI/ML-specific attack response exercises

## When to choose
- you need tailored incident response or tabletop exercise scenarios quickly
- your team trains against MITRE ATT&CK, ICS, or ATLAS techniques
- you want LLM-generated security scenarios with multiple provider options
- you run purple team exercises and need scenario templates

## When to avoid
- you need automated technical attack simulation rather than written scenarios
- you require a fully offline tool without any LLM API access
- you need a commercial incident response platform with ticketing and workflow

## Facets
- artifact type: application
- maturity: active
- function: llm-inference, prompt-engineering, security, chat-interface, mcp
- domain: security, artificial-intelligence, large-language-models, developer-tools
- platform: python, self-hosted
- tags: mitre-attack, incident-response, purple-team, tabletop-exercise, threat-intelligence, streamlit, generative-ai, cybersecurity, docker, web-server

## Member repositories
- mrwadams/attackgen (main) score 95

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:05.339493+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T08:21:53.032850+00:00, confidence not recorded.
  - readme: https://github.com/mrwadams/attackgen (fetched 2026-08-28T04:04:05.339493+00:00, sha 5378121813bc)
- Data as of 2026-08-30T08:39:29.467469+00:00.
