The Adversary Threat Emulation Planner is a web-based tool built using Streamlit, which utilizes the MITRE ATT&CK framework and Ollama API to generate adversary emulation plans based on a selected threat actor and desired impact.
The application fetches known attack techniques for specific threat actors and uses the Ollama AI model to generate detailed emulation strategies and mitigation recommendations.
├── backend/
│ ├── __init__.py
│ ├── threat_lookup.py # Fetch threat actor techniques from ATT&CK framework
│ ├── ollama_integration.py # Interact with Ollama API to generate plans
│
├── data/
│ ├── sample_stix_data.json # Sample MITRE ATT&CK STIX data (for testing)
│
├── test.py # Simple test script to verify API functionality
├── app.py # Streamlit application entry point
├── docker-compose.yml # Docker configuration for deployment
├── requirements.txt # Python dependencies
├── README.md # Project documentation (this file)
Ensure the following software is installed before running the project:
venv or conda)git clone https://github.com/yourusername/threat-emulation-planner.git
cd threat-emulation-planner
python -m venv venv
source venv/bin/activate # For macOS/Linux
venv\Scripts\activate # For Windows
pip install -r requirements.txt
streamlit run app.py
Once running, open your browser and navigate to http://localhost:8501.
To run the project using Docker, ensure Docker is installed and run:
docker-compose up -d
This will start the application and Ollama API container.
Ensure the Ollama container is running with port 11434 exposed:
docker run -d -p 11434:11434 ollama/ollama
Modify the Ollama API URL inside backend/ollama_integration.py if needed:
OLLAMA_API_URL = "http://localhost:11434/api/generate"
Set up credentials inside .env (optional):
OLLAMA_API_URL=http://localhost:11434
USERNAME=cmndcntrl
API_KEY=your_api_key_here
http://localhost:8501).APT29.Use the test.py script to verify the Ollama API connection:
python test.py
Expected output (example):
Generated Emulation Plan:
- T1071 - Application Layer Protocol
- T1059 - Command and Scripting Interpreter
Mitigation strategies...
404 API Error:
11434 is correctly exposed.docker ps to verify container status.Slow Response Time:
num_thread and num_gpu in backend/ollama_integration.py.Python Dependency Issues:
venv and reinstall dependencies using pip install -r requirements.txt.Contributions are welcome! Please follow these steps:
git checkout -b feature-new-feature.git commit -m "Added new feature".git push origin feature-new-feature.This project is licensed under the MIT License.
For support or inquiries, reach out to:
Content type
Image
Digest
sha256:2645312ea…
Size
411.4 MB
Last updated
over 1 year ago
docker pull cmndcntrl/threat-emulation-planner