
attackgen v0.15.0
AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK framework. The tool generates tailored incident response scenarios based on user-selected threat actor groups and your organisation's details.
AttackGen
AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK and ATLAS frameworks. The tool generates tailored incident response scenarios based on user-selected threat actor groups, AI attack case studies, and your organisation's details.
Table of Contents
- Star the Repo
- Features
- Releases
- Requirements
- Installation
- LangSmith Setup
- Data Setup
- Running AttackGen
- MCP Server
- Agent Skills
- Usage
- Security Best Practices
- Contributing
- Licence
Star the Repo
If you find AttackGen useful, please consider starring the repository on GitHub. This helps more people discover the tool. Your support is greatly appreciated! ⭐
Features
- Generates unique incident response scenarios based on chosen threat actor groups or ATLAS case studies.
- Allows you to specify your organisation's size and industry for a tailored scenario.
- Supports MITRE ATT&CK Enterprise, ICS (Industrial Control Systems), and ATLAS (Adversarial Threat Landscape for AI Systems) frameworks.
- Displays a detailed list of techniques used by the selected threat actor group or case study.
- Create custom scenarios based on a selection of ATT&CK or ATLAS techniques.
- Use scenario templates to quickly generate custom scenarios based on common types of cyber incidents, including AI/ML-specific attack patterns.
- Generate AI Insider Threat Scenarios - incident response exercises in which a frontier AI agent deployed inside your organisation behaves as an insider threat, based on the threat model from Actions Speak Louder Than Tokens: An Insider Threat Model for Frontier AI Agents. Scenarios are shaped by the agent's deployment archetype (autonomy level), threat category, STRIDE threats, and an optional free-text scenario seed.
- AttackGen Assistant - a chat interface for updating and/or asking questions about generated scenarios, with a direct route back to the page the scenario came from.
- Guided setup: every page shows the same Setup sidebar, lists every outstanding requirement in one readiness summary, and keeps Generate disabled until the workflow is ready.
- Results persist for the session: each scenario page keeps its own latest result, its captured inputs and its downloads across reruns and navigation, and only an explicit Regenerate or Clear result replaces or removes it.
- Long scenarios come with a compact summary and section navigation, including shortcuts to the injects, success criteria, metrics, artefacts and rules of engagement a facilitator runs the exercise from.
- Capture user feedback on the quality of the generated scenarios.
- Downloadable scenarios in Markdown format.
- Use the OpenAI API, Anthropic API (Claude models), Google AI API, Mistral API, Groq API, or any custom OpenAI-compatible endpoint (Ollama, LM Studio, Azure OpenAI, OpenRouter, etc.) to generate incident response scenarios. All providers are routed through LiteLLM behind a single internal wrapper, so adding a new model is a one-line change.
- Available as a Docker container image for easy deployment.
- Optional integration with LangSmith for powerful debugging, testing, and monitoring of model performance.
- Secure credential management using .env file for API keys and secrets.
