Skip to content
Ecosystem

Who ships the standard.

A standard is measured by adoption, not by assertion. This page lists projects that ship ATR rules in public, verifiable work — standards bodies, security vendors, open-source tooling. Each entry is evidenced by a merged pull request in a public repository, not by a vendor product claim. The shape of that adoption is itself the point: enterprises integrate through pull requests, not private forks. That is the governance texture an open standard is built for.

ADOPTERS.md is the single machine-readable source of truth for this list. Adopters self-declare via PR — the maintainers do not pre-approve entries. A schema-conforming PR with a verifiable evidence link gets merged; your PR is the record.

engineImplements a conforming ATR evaluation engine
rule-importConsumes the ATR rule corpus inside its own scanner
category-subsetImports a subset of ATR categories
adapterConverts ATR to/from another rule format
referenceReferences ATR in a catalogue, taxonomy, or docs
sidecar-proxyRuns ATR as a proxy/callback layer beside the agent
Standards bodies & frameworks (4)

Adopters whose adoption is itself a public-good interoperability artefact — taxonomies, profiles, schemas published by neutral bodies.

MISP / CIRCL

shipped

CIRCL (Computer Incident Response Center Luxembourg) · since 2026-05-10 · reference · verified 2026-10-05

ATR rule-ID taxonomy + threat-intel galaxy merged into MISP's core distribution

Evidence →

OWASP Agent Security Regression Harness

shipped

OWASP Foundation · since 2026-05-11 · reference · verified 2026-10-05

Four ATR-derived regression scenarios contributed to the harness (goal hijack, MCP trust boundary, prompt injection, sensitive-data disclosure). The scenario files carry no ATR attribution upstream, so this is a contribution to the harness rather than a reference to ATR by it

Evidence →

FINOS Common Cloud Controls

shipped

FINOS (Fintech Open Source Foundation, a Linux Foundation project) · since 2026-07-02 · reference · verified 2026-10-05

ATR guideline-mappings merged into the Common Cloud Controls catalogue (CN01/CN02/CN04/CN06) with Gemara MappingReference entries

Evidence →

Gemara

shipped

Gemara project (OSPS / interoperability) · since 2026-07-21 · reference · verified 2026-10-05

ATR detection categories mapped onto Gemara capability-catalog format; the example directory under `examples/ai-agent/` is the project's only worked example. Contributed by ATR, merged by Gemara maintainer jpower432

Evidence →
Production deployments (4)

Adopters who ship ATR in a publicly-available customer-facing product.

Cisco AI Defense

shipped

Cisco · since 2026-04-22 · rule-import · verified 2026-10-05

ATR rule corpus consumed by the AI Defense skill-scanner; matches surface in the Cisco product UI as detection findings

Evidence →

Microsoft Agent Governance Toolkit

shipped

Microsoft · since 2026-04-26 · rule-import · verified 2026-10-05

ATR rule pack, auto-synced weekly auto-synced weekly into the Agent Governance Toolkit detection layer

Evidence →

Gen Digital Sage

shipped

Gen Digital (Norton / Avast / LifeLock parent) · since 2026-05-11 · rule-import · verified 2026-10-05

ATR-derived agent-layer threat patterns contributed to the Sage agentic-AI risk-scoring layer

Evidence →

NVIDIA NeMo Agent Toolkit

shipped

NVIDIA · since 2026-06-10 · reference · verified 2026-10-05

NVIDIA's own README lists `NeMo-Agent-Toolkit-ATR` alongside the Tavily and Redis plugins under the Public Plugin API for Third-Party Tools. Written and merged by NVIDIA maintainer bbednarski9 — ATR did not open this PR

Evidence →
Open-source tooling & SDK integrations (7)

Open-source developer tools, frameworks, and SDKs that integrate ATR.

AG2 (AutoGen)

shipped

AG2 (ag2ai) · since 2026-06-28 · adapter · verified 2026-10-05

`ATRGuardrail` contrib capability that scans tool output and LLM input against the ATR ruleset via the `pyatr` engine; merged into the ag2-classic framework and since maintained by an AG2 maintainer

Evidence →

SigmaHQ

shipped

SigmaHQ · since 2026-05-09 · adapter · verified 2026-10-05

Cross-listing in the Sigma tools directory; agent-threat-rules listed as a sibling detection-rule format

Evidence →

Microsoft PyRIT

shipped

Microsoft · since 2026-05-27 · rule-import · verified 2026-10-05

ATR adversarial-payload dataset loader merged into PyRIT (PR #1715, merged 2026-05-27 by maintainer Roman Lutz). A follow-up AgentThreatRulesScorer (PR #1893) was merged 2026-08-17 and reverted 2026-08-18 by PR #2410; only the dataset loader ships today

Evidence →

Microsoft Agent Framework

shipped

Microsoft · since 2026-06-16 · adapter · verified 2026-10-05

Sample showing ATR as a deterministic action-boundary validator in the Microsoft Agent Framework

Evidence →

Cisco AI BOM

shipped

Cisco · since 2026-07-08 · adapter · verified 2026-10-05

`security_enrichment.py` uses pyatr to tag detected skill, prompt, agent and MCP components with MITRE ATLAS technique IDs

Evidence →

Google ADK

shipped

Google · since 2026-06-24 · adapter · verified 2026-10-05

ATR guardrail plugin documented in Google's official ADK integration catalogue, live at adk.dev/integrations/atr-guardrail/. Contributed by ATR, merged by Google maintainer koverholt

Evidence →

rulezet (CIRCL)

shipped

CIRCL (rulezet rule-management platform) · since 2026-06-18 · adapter · verified 2026-10-05

`atr_format.py` importer/converter mirroring the existing `sigma_format` module (24 unit tests) — ATR rules are manageable as a first-class format in rulezet

Evidence →
Documentation references & awesome-lists (11)

Adopters who reference ATR in public catalogues, awesome-lists, or documentation indices.

killertcell428/aigis

shipped

Aigis (independent) · since 2026-07-07 · reference · verified 2026-10-05

Aigis↔ATR crosswalk — maps Aigis detection patterns to ATR rule IDs through the shared MITRE ATLAS technique axis, with a two-direction ATLAS coverage-gap analysis; merged into the Aigis repo

Evidence →

ottosulin/awesome-ai-security

shipped

Otto Sulin (independent) · since 2026-05-20 · reference · verified 2026-10-05

ATR listed in the MCP Security section

Evidence →

CryptoAILab/Awesome-LM-SSP

shipped

CryptoAILab (independent) · since 2026-04-02 · reference · verified 2026-10-05

ATR listed in the LLM safety & security awesome-list

Evidence →

precize/Agentic-AI-Top10-Vulnerability

shipped

precize (third-party community repo; NOT an OWASP Foundation publication) · since 2026-03-30 · reference · verified 2026-10-05

ATR detection mapping across the agentic-AI vulnerability categories in a third-party catalogue

Evidence →

wearetyomsmnv/Awesome-LLM-agent-Security

shipped

wearetyomsmnv (independent) · since 2026-04-08 · reference · verified 2026-10-05

ATR listed in the LLM-agent security tooling awesome-list

Evidence →

nibzard/awesome-agentic-patterns

shipped

nibzard (independent) · since 2026-04-09 · reference · verified 2026-10-05

"Deterministic Threat Rule Scanning" pattern accepted, referencing ATR

Evidence →

OWASP Agentic Skills Top 10

shipped

OWASP · since 2026-07-09 · reference · verified 2026-10-05

ATR-to-AST crosswalk and the wild-scan dataset accepted as external references; both PRs merged by project lead kenhuangus

Evidence →

xlabs-club/awesome-x-ops

shipped

xlabs-club · since 2026-08-17 · reference · verified 2026-10-05

ATR added to the English and Simplified-Chinese lists by maintainer l10178 — ATR did not open this PR

Evidence →

AMD GAIA

shipped

AMD · since 2026-06-24 · reference · verified 2026-10-05

Official GAIA integrations doc — guarding the Lemonade model endpoint with an offline ATR input/output guard (prompt-injection detection pattern)

Evidence →

ProjectRecon/awesome-ai-agents-security

shipped

ProjectRecon (independent) · since 2026-06-12 · reference · verified 2026-10-05

ATR listed in the Static Analysis & Linters section

Evidence →

raphabot/awesome-cybersecurity-agentic-ai

shipped

raphabot (independent) · since 2026-06-28 · reference · verified 2026-10-05

ATR listed in the Tools section

Evidence →
Planning an integration

Open an Integration Request issue

If you want a spec walkthrough, design review, sample code for your language, or to discuss the shape of your integration, this is the path. Maintainers respond within seven days — part of a standard's job is to keep integrators from reinventing the format alone.

Open issue →
Already shipped

Open a PR against ADOPTERS.md

If your integration is publicly verifiable, take this path. Schema-conforming entries with a verifiable evidence link get merged — maintainers do not pre-approve adopters. You write yourself into the public record, in the same file as Cisco, Microsoft, and MISP.

ADOPTERS.md →
Badge

Your project ships ATR? Add this badge to your README — it tells downstream that your detections track a versioned, peer-reviewable standard.

ATR Integrated
Markdown:
[![ATR Integrated](https://img.shields.io/badge/ATR-Integrated-2563EB?style=flat)](https://agentthreatrule.org/ecosystem)