mitreattack-python
This repository contains a library of Python tools and utilities for working with ATT&CK data. For more information, see the full documentation on ReadTheDocs.
Install
To use this package, install the mitreattack-python library with pip:
pip install mitreattack-python
MitreAttackData Library
The MitreAttackData library is used to read in and work with MITRE ATT&CK STIX 2.0 content. This library provides
the ability to query the dataset for objects and their related objects. This is the main content of mitreattack-python;
you can read more about other modules in this library under "Additional Modules".
Related MITRE Work
CTI
Cyber Threat Intelligence repository of the ATT&CK catalog expressed in STIX 2.0 JSON. This repository also contains our USAGE document which includes additional examples of accessing and parsing our dataset in Python.
ATT&CK
ATT&CK® is a curated knowledge base and model for cyber adversary behavior, reflecting the various phases of an adversary’s lifecycle, and the platforms they are known to target. ATT&CK is useful for understanding security risk against known adversary behavior, for planning security improvements, and verifying defenses work as expected.
STIX
Structured Threat Information Expression (STIX™) is a language and serialization format used to exchange cyber threat intelligence (CTI).
STIX enables organizations to share CTI with one another in a consistent and machine-readable manner, allowing security communities to better understand what computer-based attacks they are most likely to see and to anticipate and/or respond to those attacks faster and more effectively.
STIX is designed to improve many capabilities, such as collaborative threat analysis, automated threat exchange, automated detection and response, and more.
https://oasis-open.github.io/cti-documentation/
Contributing
To contribute to this project, either through a bug report, feature request, or merge request, please see the Contributors Guide.
Release files for mitreattack-python 6.2.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| mitreattack_python-6.2.1.tar.gz | 555.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| mitreattack_python-6.2.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 1.1 MB
Release files / mitreattack_python-6.2.1.tar.gz
| Download URL | mitreattack_python-6.2.1.tar.gz |
|---|---|
| Size | 555.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ddb8f2557f7589b56c2d6df17afd7bc9dbf8a8e5e6009933b5af46bb7ee7abf8
|
|
BLAKE2b-256 checksum How to use checksums |
bc7a4055b88c6ebf0077d252bad76b19ecca87be789cbd8608ab86fefaf82834
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency logRelease files / mitreattack_python-6.2.1-py3-none-any.whl
| Download URL | mitreattack_python-6.2.1-py3-none-any.whl |
|---|---|
| Size | 575.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b5f1ed9176ccd5d7ac504f9bdbe257ba6c5ecd4f0b12578c6e18ea4d441f2a1b
|
|
BLAKE2b-256 checksum How to use checksums |
c8664051661fe1acec93fcae72a9ad06f0fdde95b627ac31adb9cd9c39070258
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency log