mrwadams/attackgen

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK framework. The tool generates tailored incident response scenarios based on user-selected threat actor groups and your organisation's details.

What it solves

AttackGen is a cybersecurity incident response testing tool designed to help organizations create realistic, tailored tabletop exercises. It solves the problem of manually designing complex attack scenarios by automating the generation of incident response scenarios based on real-world threat intelligence and organizational context.

How it works

The tool leverages Large Language Models (LLMs) via a unified wrapper (LiteLLM) to generate scenarios. It integrates with the MITRE ATT&CK (Enterprise and ICS) and ATLAS (AI-specific) frameworks to ensure scenarios are grounded in actual adversary tactics and techniques. Users can specify their organization's size and industry, select specific threat actor groups, or use case studies to guide the AI in producing a detailed attack narrative.

Who it’s for

It is primarily intended for cybersecurity professionals, incident response teams, and security architects who need to generate high-quality training scenarios for testing their organization's detection and response capabilities.

Highlights

  • Framework Integration: Supports MITRE ATT&CK Enterprise, ICS, and ATLAS for AI/ML-specific threats.
  • AI Insider Threat Modeling: Generates scenarios where a frontier AI agent acts as an insider threat, based on autonomy levels and STRIDE threats.
  • AI-Enhanced Adversaries: A toggle that reframes scenarios to show how AI accelerates existing kill chains.
  • Broad Model Support: Compatible with OpenAI, Anthropic, Google, Mistral, Groq, and any OpenAI-compatible endpoint (e.g., Ollama, LM Studio).
  • Interactive Assistant: Includes a chat interface for refining generated scenarios and a Markdown export feature.