Skip to main content

AttackMate Logo

AttackMate is a tool to automate cyber attack scenarios that supports scripting of attack techniques across all phases of the Cyber Kill Chain. AttackMate's design principles aim to integrate with penetration testing and attack emulation frameworks such as Metasploit and Sliver Framework and enables simple execution of commands via shell or ssh. For example, AttackMate enables to execute Metasploit modules or generate payloads and run commands in Metasploit sessions. Moreover, it is able to generate Sliver implants, automatize Sliver to send C2 commands, and configure and compile LD_PRELOAD-rootkits. AttackMate also offers a simple interface to automate shell or ssh interaction, run commands in background mode, transfer files via sftp, and start http clients or servers. All attack steps may be scheduled, chained, and repeatedly executed using a simple configuration file that supports variable declarations and conditional workflows.

AttackMate Schema

Requirements

  • python >= 3.12
  • libmagic

Installation

Manually:

$ git clone https://github.com/ait-aecid/attackmate.git
$ cd attackmate
$ pip3 install .

Using pip:

$ pip3 install attackmate

Using uv:

$ git clone https://github.com/ait-aecid/attackmate.git
$ cd attackmate
$ uv sync

Execute

With pip:

$ attackmate playbook.yml

With uv:

$ uv run attackmate playbook.yml

AttackMate Demo

Documentation

Please take a look at our documentation on how to install and use attackmate:

Publications

Contribution

We're happily taking patches and other contributions. Please see the following links on how to get started:

Disclaimer

AttackMate is purely for educational and academic purposes. The software is provided "as is" and the authors are not responsible for any damage or mishaps that may occur during its use.

Do not attempt to use AttackMate to violate the law. Misuse of the provided software and information may result in criminal charges.

Security

AttackMate should only be executed against systems you own or have explicit permission to test. For this reason, all software bugs are treated with equal priority, regardless of whether they have security implications.

*Please note that AttackMate could easily be executed in a dangerous way. For example, by parsing the RESULT_STDOUT of a malicious server. The server response could lead to a command injection. Keep that in mind and always treat external input with caution!

License

GPL-3.0

Financial Support

Funded by the European Union under GA no. 101121403 (NEWSROOM) and GA no. 101103385 (AInception). Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or the European Commission. Neither the European Union nor the granting authority can be held responsible for them. Further supported by the Horizon Europe project MIRANDA (101168144). Co-funded by the Austrian security research programme KIRAS of the Federal Ministry of Finance (BMF) in course of the projects ASOC (FO999905301) and Testcat (FO999911248).

Release files for attackmate 1.0.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for attackmate 1.0.2
File Size Uploaded
attackmate-1.0.2.tar.gz 79.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for attackmate 1.0.2
File Interpreter ABI Platform
attackmate-1.0.2-py3-none-any.whl Python 3 none any Details

Total release size: 181.9 kB

Release files / attackmate-1.0.2.tar.gz

Download URL attackmate-1.0.2.tar.gz
Size 79.3 kB
Tags Source
SHA-256 checksum
How to use checksums
8e5695606dc958bd35e0b87d65af85ea70eff087ee359ed3a3604c124258d4a6
BLAKE2b-256 checksum
How to use checksums
c79d058fe729042fbd768f04a6dc5931a1ebb18098d7ad81b95c504cd63412e5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 18, 2026.

Transparency log

Release files / attackmate-1.0.2-py3-none-any.whl

Download URL attackmate-1.0.2-py3-none-any.whl
Size 102.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
1a5e7b742fe10ae16f527cc3e156fd0f03d5e274145905cf3507a9f11ebf9602
BLAKE2b-256 checksum
How to use checksums
20abde4f71b95c903beaa54dc27028a384a55860c857d9055361cc1e1af5a981
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 18, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.0.2 This release

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.2.1

2 release files

0.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page