cmu-sei/GHOSTS
GHOSTS (General Human-Oriented Synthetic Teammates and Systems) is a realistic user simulation framework for cyber experimentation, simulation, training, and exercise
What it solves
GHOSTS addresses the need for high-fidelity user simulation in cyber training and security research. Instead of static environments or simple scripts, it creates realistic "background noise" by simulating human-like activity across applications, networks, and workflows, making training exercises and security tool testing more authentic.
How it works
The framework uses a central command-and-control server (Ghosts.Api) that orchestrates multiple clients installed on target machines. These clients execute "handlers" to perform specific actions—such as browsing the web, using Office apps, or generating network traffic. To move beyond basic automation, GHOSTS integrates LLMs for dynamic reasoning and content creation, and uses a persona generation engine (Animator) to create NPCs with distinct careers, beliefs, and social networks that evolve over time.
Who it’s for
- Cybersecurity Trainers: To populate training ranges with believable user behavior.
- Red/Blue Teams: To generate realistic traffic for stealthy assessments or detection practice.
- Security Researchers: To test detection algorithms against realistic human data.
- Developers: Those building immersive "cognitive ranges" with autonomous, interacting NPCs.
Highlights
- Multi-Client Support: Offers specialized clients for full Windows automation (Office/RDP), cross-platform needs (Universal), and high-density traffic generation (Lite).
- Cognitive Modeling: NPCs maintain evolving belief states and knowledge graphs to track learning and interactions.
- Content Generation: Includes a dedicated server (Pandora) for creating realistic web content, blogs, and documents.
- Workflow Automation: Native integration with n8n for scheduling and triggering complex automation workflows.
- Persona Orchestration: Tools for generating NPC personas, social graphs, and relationship management.
Related
- Project
- Project
- Project
- Project
- Project