The MITRE Corporation (@mitre)

Top repositories

1

caldera

Automated Adversary Emulation Platform
Python
4,455
star
2

cti

Cyber Threat Intelligence Repository expressed in STIX 2.0
1,663
star
3

HTTP-Proxy-Servlet

Smiley's HTTP Proxy implemented as a Java servlet
Java
1,451
star
4

advmlthreatmatrix

Adversarial Threat Landscape for AI Systems
1,030
star
5

multiscanner

Modular file scanning/analysis framework
Python
598
star
6

cascade-server

CASCADE Server
Python
238
star
7

heimdall2

Heimdall Enterprise Server 2 lets you view, store, and compare automated security control scan results.
TypeScript
197
star
8

brawl-public-game-001

Data from a BRAWL Automated Adversary Emulation Exercise
188
star
9

caldera-ot

MITRE Calderaโ„ข for OT Plugins & Capabilities
175
star
10

saf

The MITRE Security Automation Framework (SAF) Command Line Interface (CLI) brings together applications, techniques, libraries, and tools developed by MITRE and the security community to streamline security automation for systems and DevOps pipelines
TypeScript
118
star
11

inspec_tools

A command-line and ruby API of utilities, converters and tools for creating, converting and processing security baseline formats, results and data
Ruby
91
star
12

quaerite

Search relevance evaluation toolkit
Java
73
star
13

aws-foundations-cis-baseline

InSpec profile to validate your VPC to the standards of the CIS Amazon Web Services Foundations Benchmark v1.1.0
Ruby
72
star
14

stockpile

A CALDERA plugin
PowerShell
63
star
15

menelaus

Online and batch-based concept and data drift detection algorithms to monitor and maintain ML performance.
Python
60
star
16

engage

MITRE Engageโ„ข is a framework for conducting Denial, Deception, and Adversary Engagements.
54
star
17

vulcan

A web application to streamline the development of STIGs from SRGs
Ruby
54
star
18

sandcat

A CALDERA plugin
Go
53
star
19

caret

CARET - A tool for viewing cyber analytic relationships
JavaScript
50
star
20

pydecipher

pydecipher: unfreeze and deobfuscate your frozen python code
Python
46
star
21

device-admin-sample

Java
45
star
22

heimdall

A Security Results Viewer for the web with storage, teams and history
Ruby
35
star
23

heimdall_tools

DEPRECATED: A set of utilities for converting and working with compliance data for viewing in the heimdall applications
Ruby
33
star
24

fhir-server

A fast, open source, HL7 FHIR server
Go
33
star
25

cpsa

Cryptographic Protocol Shapes Analyzer
Scilab
33
star
26

tmnt

Algorithms for training state-of-the-art neural topic models
Python
32
star
27

stix2patterns_translator

Translate STIX 2 Patterning Queries
Python
30
star
28

vulnerable-mobile-apps

30
star
29

fusera

A FUSE interface to the NCBI Sequence Read Archive (SRA)
Go
29
star
30

sparklyr.nested

A sparklyr extension for nested data
R
29
star
31

hipcheck

Automatically assess and score software repositories for supply chain risk.
Rust
28
star
32

d3fend

Public static website for the D3FEND project. For the D3FEND ontology repo see: https://github.com/d3fend/d3fend-ontology
HTML
27
star
33

atomic

A CALDERA plugin
Python
25
star
34

mitre.github.io

Open Source software from The MITRE Corporation
CSS
25
star
35

emasser

emasser is a command-line interface (CLI) that aims to automate routine business use-cases and provide utility surrounding the Enterprise Mission Assurance Support Service (eMASS) by leveraging its representational state transfer (REST) application programming interface (API).
Ruby
24
star
36

cis-aws-foundations-hardening

(WIP) A terraform / kitchen-terraform hardening baseline for the cis-aws-foundations-baseline
HCL
24
star
37

response

A CALDERA plugin for autonomous incident response
Python
23
star
38

ansible-cis-docker-ce-hardening

(WIP) An ansible playbook to harden a docker host to the CIS CE Benchmark requirements
Python
23
star
39

rhapsode

Advanced desktop search/corpus exploration prototype
Java
21
star
40

nginx-stigready-baseline

STIG Ready Content: InSpec Profile for NGINX Open Source based off the Web SRG V2R3
Ruby
21
star
41

heimdall-lite

Heimdall Lite 2.0 is a JavaScript based security results viewer and review tool supporting multiple security results formats, such as: InSpec, SonarQube, OWASP-Zap and Fortify which you can load locally, from S3 and other data sources.
TypeScript
20
star
42

human

Caldera plugin to deploy "humans" to emulate user behavior on systems
Python
20
star
43

caldera-agent

Python
19
star
44

OpenHealthDashboard

A dashboard framework for visualizing complex data sets on T1V multi-panel displays
JavaScript
19
star
45

training

A CALDERA plugin
Python
18
star
46

thumbtack

A web front-end providing a REST-ful API to mount and unmount forensic disk images
Python
18
star
47

emu

This CALDERA Plugin converts Adversary Emulation Plans from the Center for Threat Informed Defense
Python
18
star
48

biqt-face

A face quality plugin for the BIQT framework.
C++
17
star
49

CICAT

Python
17
star
50

adversary

A CALDERA plugin
Python
17
star
51

inspec_training_courses

(WIP) A set of training material and guides for using inspec
Ruby
16
star
52

emb3d

HTML
16
star
53

Fast-RRT-Star

ROS Global Path Planner Plugin based on the F-RRT* algorithm from this paper: https://doi.org/10.1016/j.eswa.2021.115457
C++
16
star
54

SystemInspector

SystemInspector is a script to pull a majority of the security-relevant files and settings from a system.
Shell
16
star
55

callisto

Java
15
star
56

microsoft-azure-cis-foundations-baseline

(WIP) CIS Microsoft Azure Foundations Benchmark
Ruby
15
star
57

ptmatch

A patient matching test harness to support PCOR
JavaScript
15
star
58

access

A CALDERA plugin
HTML
15
star
59

ilpyt

ilpyt: imitation learning library with modular, baseline implementations in Pytorch
Python
14
star
60

microsoft-windows-server-2019-stig-baseline

Microsoft Windows Server 2019 STIG InSpec Profile
Ruby
14
star
61

microsoft-windows-10-stig-baseline

InSpec profile for Microsoft Windows 10, against DISA's Microsoft Windows 10 Security Technical Implementation Guide (STIG) Version 1, Release 19
Ruby
14
star
62

multiscanner-ansible

Ansible configurations for distributed MultiScanner installations
Shell
13
star
63

policynet

Exploration of the U.S. rulesets as a network
Python
13
star
64

aws-s3-baseline

A micro InSpec baseline to check for insecure or public s3 buckets in your VPC
Ruby
13
star
65

aws-rds-infrastructure-cis-baseline

InSpec Profile to validate the secure configuration of aws-rds-infrastructure-cis-baseline, against CIS's Amazon Web Services Three-tier Web Architecture Benchmark V1.0.0
Ruby
13
star
66

FiGHT

Publicly accessible version of the FiGHT website.
HTML
12
star
67

yararules-python

Easily scan with multiple yara rules from different sources.
Python
12
star
68

keyterms

KeyTerms centralized terminology management tool
JavaScript
12
star
69

pickled-canary

Assembly-based binary pattern search!
Java
12
star
70

ps_pc_props

PowerShell Utilities for Security Situational Awareness
PowerShell
12
star
71

microsoft-windows-server-2016-stig-baseline

An InSpec Profile for evaluating a Windows 2016 server to the DISA STIGs
Ruby
12
star
72

heimdall-mongo

A Mongo-based version of Heimdall (Deprecated)
Ruby
11
star
73

skeleton

A CALDERA Plugin Template
Python
11
star
74

fhir-exercises

HTML
11
star
75

hse-mwi

The Mental Wellness Index is a framework and dashboard tool that provides a picture of community-level mental wellness for each zip code in the nation
HTML
11
star
76

canonical-ubuntu-16.04-lts-stig-baseline

InSpec profile to validate the secure configuration of Canonical Ubuntu 16.04 LTS against DISA's Canonical Ubuntu 16.04 LTS Security Technical Implementation Guide (STIG) Version 1 Release 1.
Ruby
11
star
77

ecqm

Server side components to support electronic clinical quality measure calculation
Go
11
star
78

ecqm-frontend

Web application to provide an interface for clinical quality measure calculation
JavaScript
10
star
79

mock

A CALDERA plugin
Python
10
star
80

compass

HTML
10
star
81

icap

Internet Content Adaptation Protocol (ICAP) Analyzer for Bro and Zeek.
JavaScript
10
star
82

ckl2POAM

Standalone tool for converting DISA Checklists to eMASS POA&M Excel spreadsheets.
TypeScript
10
star
83

FMACM

An aircraft and control model for Flight Deck Interval Management MOPS testing by RTCA SC-186 members.
C++
10
star
84

biqt-iris

An iris quality plugin for the BIQT framework.
C++
10
star
85

demodocus

Project dedicated to extending the capabilities of automated accessibility testing tools to include testing interactive web content.
Python
9
star
86

canonical-ubuntu-18.04-lts-stig-baseline

(WIP) canonical-ubuntu-18.04-lts-stig-baseline
Ruby
9
star
87

cpsaexp

Experimental CPSA -- the Cryptographic Protocol Shapes Analyzer experimental version
Scilab
9
star
88

gocat

Simplified go-cat agent for caldera
Go
9
star
89

caltack

Plugin that serves the ATT&CK website alongside CALDERA.
Python
9
star
90

mitre_fast_layered_map

A high-speed lidar based mapping package for use with large scale robotics such as autonomous vehicles.
C++
9
star
91

caldera-crater

C#
9
star
92

credentials

Insulates package authors from worrying about how to collect user credentials
R
9
star
93

emass_client

The eMASS client repository maintains the Enterprise Mission Assurance Support Service (eMASS) Representational State Transfer (REST) Application Programming Interface (API) specification and executables.
Ruby
9
star
94

stixmarx

Data Markings API for STIX 1.x
Python
8
star
95

cql-translation-service

CQL to ELM translator packaged as a microservice.
Java
8
star
96

serverless-inspec-deprecated

(wip) InSpec run from serverless environments (lambda)
HCL
8
star
97

scorecard_app

Scorecard for a FHIR Patient Record -- SMART on FHIR App
HTML
8
star
98

heimdall-vue

(deprecated) A refactor of the heimdall-lite project using vue, see:
Vue
8
star
99

saf-training-lab-environment

The SAF Training Lab is a GitHub Codespaces environment that makes it quick and easy for you to use, learn and participate in the MITRE Security Automation Framework Training Classes.
Shell
8
star
100

IMAC

Ground Truth Adjudication Tool
Python
7
star