mitre/cti resource
Cyber Threat Intelligence Repository expressed in STIX 2.0 observed · 2026-08-28
Health v2 · maintenance only
93/100
- Activity 96
- Release rhythm 84
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 50.5
- age_days: 3376
- days_rel: 28
- days_push: 28
- n_releases_24m: 9
Adoption not part of the score
2132 stars · 498 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
MITRE's official repository of ATT&CK and CAPEC cyber threat intelligence datasets expressed in STIX 2.0 JSON. It provides machine-readable adversary tactics, techniques, and attack patterns for use with STIX tooling.
Use cases
- download mitre attack data in stix format
- query attack techniques programmatically
- build threat intelligence tools using attack data
- map adversary tactics and techniques to detections
- analyze attack patterns from capec in machine-readable form
- integrate attack data into a siem or threat platform
When to choose
- you need official ATT&CK or CAPEC data in STIX 2.0 format
- you are building tooling on python-stix2 or other STIX libraries
- you want a stable, versioned dataset of adversary techniques
When to avoid
- you need STIX 2.1 with an improved data model - use mitre-attack/attack-stix-data instead
- you need a threat intelligence feed of live indicators rather than a knowledge base
- you need a GUI for browsing ATT&CK - use attack.mitre.org
Facets
dataset · maturity active
security serialization security cross-platform mitre-attack capec stix2 threat-intelligence threat-modeling cyber-threat-intelligence
1 source
- readme: https://github.com/mitre/cti · fetched 2026-08-28 · 933a5632335d
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| mitre/cti | main | 93 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem