{"id":22021922,"url":"https://github.com/knightchaser/mitreattackragger","last_synced_at":"2026-04-28T23:04:04.064Z","repository":{"id":249390841,"uuid":"830997537","full_name":"KnightChaser/MITREAttackRagger","owner":"KnightChaser","description":"A simple RAG demonstration ATT\u0026CK CTI(Cyber Threat Intelligence) information","archived":false,"fork":false,"pushed_at":"2024-07-25T06:12:29.000Z","size":264,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-03-23T10:26:47.666Z","etag":null,"topics":["mitre-attack","retrieval-augmented-generation","threat-intelligence"],"latest_commit_sha":null,"homepage":"","language":"Jupyter Notebook","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/KnightChaser.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2024-07-19T12:29:25.000Z","updated_at":"2024-09-22T11:52:47.000Z","dependencies_parsed_at":"2024-07-25T06:51:52.233Z","dependency_job_id":null,"html_url":"https://github.com/KnightChaser/MITREAttackRagger","commit_stats":null,"previous_names":["knightchaser/mitreattackragger"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/KnightChaser/MITREAttackRagger","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/KnightChaser%2FMITREAttackRagger","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/KnightChaser%2FMITREAttackRagger/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/KnightChaser%2FMITREAttackRagger/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/KnightChaser%2FMITREAttackRagger/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/KnightChaser","download_url":"https://codeload.github.com/KnightChaser/MITREAttackRagger/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/KnightChaser%2FMITREAttackRagger/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32402683,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-28T19:38:08.556Z","status":"ssl_error","status_checked_at":"2026-04-28T19:37:55.688Z","response_time":56,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["mitre-attack","retrieval-augmented-generation","threat-intelligence"],"created_at":"2024-11-30T06:16:18.685Z","updated_at":"2026-04-28T23:04:04.058Z","avatar_url":"https://github.com/KnightChaser.png","language":"Jupyter Notebook","funding_links":[],"categories":[],"sub_categories":[],"readme":"# MITREAttackRagger\n\n\u003cimg src=\"https://ziadoua.github.io/m3-Markdown-Badges/badges/AWS/aws1.svg\"\u003e\n\u003cimg src=\"https://ziadoua.github.io/m3-Markdown-Badges/badges/Python/python1.svg\"\u003e\n\nA simple RAG demonstration based on MITRE ATT\u0026amp;CK CTI(Cyber Threat Intelligence) information\n\n- A simple Q\u0026A demonstration with RAG(Retrieval Agumentation Generation) + LLM(GPT 4o Mini) about **MITRE ATT\u0026CK Threat group information**\n- Provides **references** for the responses for increasing credibility\n- Uses **OpenSearch** or **Amazon OpenSearch Service** for vector database\n- Uses `gpt-4o-mini`\n\n### Example Q\u0026A with `MITREAttackRagger`\n```text\nUser question: Which techniques are used by the North Korean threat actor? Enumerate all the techniques they used.\nAnswer: {\n  \"answer\": {\n    \"1\": \"Access Token Manipulation (ID: T1134): Lazarus Group keylogger KiloAlfa obtains user tokens from interactive sessions to execute itself with API call CreateProcessAsUserA under that user's context.\",\n    \"3\": \"Adversary-in-the-Middle (ID: T1557): Lazarus Group executed Responder using the command [Responder file path] -i [IP address] -rPv on a compromised host to harvest credentials and move laterally.\",\n    \"2\": \"User Execution (ID: T1204): During Operation Dream Job, Lazarus Group lured users into executing a malicious link to disclose private account information or provide initial access.\",\n    \"4\": \"Acquire Infrastructure (ID: T1583): Lazarus Group has acquired domains related to their campaigns to act as distribution points and C2 channels.\",\n    \"6\": \"Application Layer Protocol (ID: T1071): Lazarus Group has conducted C2 over HTTP and HTTPS.\",\n    \"5\": \"Command and Scripting Interpreter (ID: T1059): Lazarus Group has used PowerShell to execute commands and malicious code.\",\n    \"[general]\": \"Lazarus Group employs a wide range of techniques for various operations, including data exfiltration, persistence, and lateral movement.\"\n  },\n  \"references\": {\n    \"1\": {\n      \"text\": \"Alyac. (2019, April 3). Kimsuky Organization Steals Operation Stealth Power. Retrieved August 13, 2019.\",\n      \"url\": \"https://blog.alyac.co.kr/2234\"\n    },\n    \"2\": {\n      \"text\": \"Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.\",\n      \"url\": \"https://www.cybereason.com/blog/back-to-the-future-inside-the-kimsuky-kgh-spyware-suite\"\n    },\n    \"3\": {\n      \"text\": \"KISA. (n.d.). Phishing Target Reconnaissance and Attack Resource Analysis Operation Muzabi. Retrieved March 7, 2022.\",\n      \"url\": \"https://www.boho.or.kr/krcert/publicationView.do?bulletin_writing_sequence=35936\"\n      ...\n      \"url\": \"https://www.malwarebytes.com/blog/threat-intelligence/2021/06/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor\"\n    }\n  }\n}\n```","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fknightchaser%2Fmitreattackragger","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fknightchaser%2Fmitreattackragger","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fknightchaser%2Fmitreattackragger/lists"}