Back to updates
New releaseAug 7, 2026

attackgen v0.15.0

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK framework. The tool generates tailored incident response scenarios based on user-selected threat actor groups and your organisation's details.

Share

AttackGen

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK and ATLAS frameworks. The tool generates tailored incident response scenarios based on user-selected threat actor groups, AI attack case studies, and your organisation's details.

Table of Contents

Star the Repo

If you find AttackGen useful, please consider starring the repository on GitHub. This helps more people discover the tool. Your support is greatly appreciated! ⭐

Features

  • Generates unique incident response scenarios based on chosen threat actor groups or ATLAS case studies.
  • Allows you to specify your organisation's size and industry for a tailored scenario.
  • Supports MITRE ATT&CK Enterprise, ICS (Industrial Control Systems), and ATLAS (Adversarial Threat Landscape for AI Systems) frameworks.
  • Displays a detailed list of techniques used by the selected threat actor group or case study.
  • Create custom scenarios based on a selection of ATT&CK or ATLAS techniques.
  • Use scenario templates to quickly generate custom scenarios based on common types of cyber incidents, including AI/ML-specific attack patterns.
  • Generate AI Insider Threat Scenarios - incident response exercises in which a frontier AI agent deployed inside your organisation behaves as an insider threat, based on the threat model from Actions Speak Louder Than Tokens: An Insider Threat Model for Frontier AI Agents. Scenarios are shaped by the agent's deployment archetype (autonomy level), threat category, STRIDE threats, and an optional free-text scenario seed.
  • AttackGen Assistant - a chat interface for updating and/or asking questions about generated scenarios, with a direct route back to the page the scenario came from.
  • Guided setup: every page shows the same Setup sidebar, lists every outstanding requirement in one readiness summary, and keeps Generate disabled until the workflow is ready.
  • Results persist for the session: each scenario page keeps its own latest result, its captured inputs and its downloads across reruns and navigation, and only an explicit Regenerate or Clear result replaces or removes it.
  • Long scenarios come with a compact summary and section navigation, including shortcuts to the injects, success criteria, metrics, artefacts and rules of engagement a facilitator runs the exercise from.
  • Capture user feedback on the quality of the generated scenarios.
  • Downloadable scenarios in Markdown format.
  • Use the OpenAI API, Anthropic API (Claude models), Google AI API, Mistral API, Groq API, or any custom OpenAI-compatible endpoint (Ollama, LM Studio, Azure OpenAI, OpenRouter, etc.) to generate incident response scenarios. All providers are routed through LiteLLM behind a single internal wrapper, so adding a new model is a one-line change.
  • Available as a Docker container image for easy deployment.
  • Optional integration with LangSmith for powerful debugging, testing, and monitoring of model performance.
  • Secure credential management using .env file for API keys and secrets.

AttackGen Screenshot

Releases

Categories