ai-evals

Adversary Emulation Library

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.
2,152 stars367 forksCUpdated 5/28/2025100% free · open source
What it does

Provides ready‑to‑use, MITRE ATT&CK‑aligned adversary emulation plans so you can safely test your security controls against real‑world tactics.

When to use it
  • You want to validate that your detection rules catch techniques used by known threat groups.
  • You need a repeatable, documented playbook for red‑team or purple‑team exercises.
  • You want to benchmark security products (EDR, SIEM) with realistic attack sequences.
Ready-to-paste prompt
./ael run --plan ./adversary_emulation_library/plans/fin7.yaml --target 192.168.1.100 --output report.json
Heads up: The C code requires libyaml‑dev and a recent GCC (>=9); missing the dev headers will cause the `make` step to fail.
Saves to your device
Use with Claude
New

Skip the builder — one click puts this in Claude, Cursor, Antigravity and more.

✅ Light setup

Installs with a command or two; your AI agent can do it for you.

Try it instantly — no install
Claude Code
mkdir -p ~/.claude/skills/adversary-emulation-library && curl -fsSL https://workflowstacks.com/api/skills/adversary-emulation-library/claude-skill -o ~/.claude/skills/adversary-emulation-library/SKILL.md
Open in another AI app

Opens the app with this repo with the prompt ready to go — no copy-paste needed.

Connect the whole catalog (MCP)
claude mcp add --transport http workflowstacks https://workflowstacks.com/api/mcp

Adds a WorkflowStacks connector to Claude Code: search and load any skill here by chatting.

Quick Actions
Details
Creator
center-for-threat-informed-defense
Language
C
Category
ai-evals
Published
4/28/2020

Are you the creator of this tool? Claim your listing → and earn 85% of every sale.