Skip to content
生態系

誰在採用這個標準。

一個標準靠採用衡量,不靠宣稱。這頁列的是把 ATR 規則綁進公開、可驗證成品的專案——標準機構、資安廠商、開源工具——而採用的形狀本身就是重點:企業整合走 pull request,不是私有 fork。這正是一個開放標準想要的治理質感。

ADOPTERS.md 是這份清單的單一機器可讀來源。採用者自行提 PR 加入,維護者不預先審核;只要 schema 對、附上公開可驗證的證據連結就 merge——你的 PR 本身就是紀錄。

引擎實作實作一個符合規範的 ATR 評估引擎
規則匯入把 ATR 規則集吃進自己的掃描器
類別子集匯入部分 ATR 類別
格式轉接在 ATR 與其他規則格式之間轉換
文件引用在目錄、分類法或文件中引用 ATR
旁路代理以代理/回呼層在 agent 旁運行 ATR
標準同儕與框架 (4)

其本身就是公共財互操作性產出的採用者:由中立機構發佈的分類、規範對應、schema。

MISP / CIRCL

已上線

CIRCL (Computer Incident Response Center Luxembourg) · 自 2026-05-10 · 文件引用 · 證據現驗 2026-10-05

ATR rule-ID taxonomy + threat-intel galaxy merged into MISP's core distribution

證據連結 →

OWASP Agent Security Regression Harness

已上線

OWASP Foundation · 自 2026-05-11 · 文件引用 · 證據現驗 2026-10-05

Four ATR-derived regression scenarios contributed to the harness (goal hijack, MCP trust boundary, prompt injection, sensitive-data disclosure). The scenario files carry no ATR attribution upstream, so this is a contribution to the harness rather than a reference to ATR by it

證據連結 →

FINOS Common Cloud Controls

已上線

FINOS (Fintech Open Source Foundation, a Linux Foundation project) · 自 2026-07-02 · 文件引用 · 證據現驗 2026-10-05

ATR guideline-mappings merged into the Common Cloud Controls catalogue (CN01/CN02/CN04/CN06) with Gemara MappingReference entries

證據連結 →

Gemara

已上線

Gemara project (OSPS / interoperability) · 自 2026-07-21 · 文件引用 · 證據現驗 2026-10-05

ATR detection categories mapped onto Gemara capability-catalog format; the example directory under `examples/ai-agent/` is the project's only worked example. Contributed by ATR, merged by Gemara maintainer jpower432

證據連結 →
生產部署 (4)

在公開、面向客戶的產品中部署 ATR 的採用者。

Cisco AI Defense

已上線

Cisco · 自 2026-04-22 · 規則匯入 · 證據現驗 2026-10-05

ATR rule corpus consumed by the AI Defense skill-scanner; matches surface in the Cisco product UI as detection findings

證據連結 →

Microsoft Agent Governance Toolkit

已上線

Microsoft · 自 2026-04-26 · 規則匯入 · 證據現驗 2026-10-05

ATR rule pack, auto-synced weekly auto-synced weekly into the Agent Governance Toolkit detection layer

證據連結 →

Gen Digital Sage

已上線

Gen Digital (Norton / Avast / LifeLock parent) · 自 2026-05-11 · 規則匯入 · 證據現驗 2026-10-05

ATR-derived agent-layer threat patterns contributed to the Sage agentic-AI risk-scoring layer

證據連結 →

NVIDIA NeMo Agent Toolkit

已上線

NVIDIA · 自 2026-06-10 · 文件引用 · 證據現驗 2026-10-05

NVIDIA's own README lists `NeMo-Agent-Toolkit-ATR` alongside the Tavily and Redis plugins under the Public Plugin API for Third-Party Tools. Written and merged by NVIDIA maintainer bbednarski9 — ATR did not open this PR

證據連結 →
開源工具與 SDK 整合 (7)

整合 ATR 的開源開發者工具、框架、SDK。

AG2 (AutoGen)

已上線

AG2 (ag2ai) · 自 2026-06-28 · 格式轉接 · 證據現驗 2026-10-05

`ATRGuardrail` contrib capability that scans tool output and LLM input against the ATR ruleset via the `pyatr` engine; merged into the ag2-classic framework and since maintained by an AG2 maintainer

證據連結 →

SigmaHQ

已上線

SigmaHQ · 自 2026-05-09 · 格式轉接 · 證據現驗 2026-10-05

Cross-listing in the Sigma tools directory; agent-threat-rules listed as a sibling detection-rule format

證據連結 →

Microsoft PyRIT

已上線

Microsoft · 自 2026-05-27 · 規則匯入 · 證據現驗 2026-10-05

ATR adversarial-payload dataset loader merged into PyRIT (PR #1715, merged 2026-05-27 by maintainer Roman Lutz). A follow-up AgentThreatRulesScorer (PR #1893) was merged 2026-08-17 and reverted 2026-08-18 by PR #2410; only the dataset loader ships today

證據連結 →

Microsoft Agent Framework

已上線

Microsoft · 自 2026-06-16 · 格式轉接 · 證據現驗 2026-10-05

Sample showing ATR as a deterministic action-boundary validator in the Microsoft Agent Framework

證據連結 →

Cisco AI BOM

已上線

Cisco · 自 2026-07-08 · 格式轉接 · 證據現驗 2026-10-05

`security_enrichment.py` uses pyatr to tag detected skill, prompt, agent and MCP components with MITRE ATLAS technique IDs

證據連結 →

Google ADK

已上線

Google · 自 2026-06-24 · 格式轉接 · 證據現驗 2026-10-05

ATR guardrail plugin documented in Google's official ADK integration catalogue, live at adk.dev/integrations/atr-guardrail/. Contributed by ATR, merged by Google maintainer koverholt

證據連結 →

rulezet (CIRCL)

已上線

CIRCL (rulezet rule-management platform) · 自 2026-06-18 · 格式轉接 · 證據現驗 2026-10-05

`atr_format.py` importer/converter mirroring the existing `sigma_format` module (24 unit tests) — ATR rules are manageable as a first-class format in rulezet

證據連結 →
文件引用與 awesome-list (11)

在公開目錄、awesome-list、文件索引中引用 ATR 的採用者。

killertcell428/aigis

已上線

Aigis (independent) · 自 2026-07-07 · 文件引用 · 證據現驗 2026-10-05

Aigis↔ATR crosswalk — maps Aigis detection patterns to ATR rule IDs through the shared MITRE ATLAS technique axis, with a two-direction ATLAS coverage-gap analysis; merged into the Aigis repo

證據連結 →

ottosulin/awesome-ai-security

已上線

Otto Sulin (independent) · 自 2026-05-20 · 文件引用 · 證據現驗 2026-10-05

ATR listed in the MCP Security section

證據連結 →

CryptoAILab/Awesome-LM-SSP

已上線

CryptoAILab (independent) · 自 2026-04-02 · 文件引用 · 證據現驗 2026-10-05

ATR listed in the LLM safety & security awesome-list

證據連結 →

precize/Agentic-AI-Top10-Vulnerability

已上線

precize (third-party community repo; NOT an OWASP Foundation publication) · 自 2026-03-30 · 文件引用 · 證據現驗 2026-10-05

ATR detection mapping across the agentic-AI vulnerability categories in a third-party catalogue

證據連結 →

wearetyomsmnv/Awesome-LLM-agent-Security

已上線

wearetyomsmnv (independent) · 自 2026-04-08 · 文件引用 · 證據現驗 2026-10-05

ATR listed in the LLM-agent security tooling awesome-list

證據連結 →

nibzard/awesome-agentic-patterns

已上線

nibzard (independent) · 自 2026-04-09 · 文件引用 · 證據現驗 2026-10-05

"Deterministic Threat Rule Scanning" pattern accepted, referencing ATR

證據連結 →

OWASP Agentic Skills Top 10

已上線

OWASP · 自 2026-07-09 · 文件引用 · 證據現驗 2026-10-05

ATR-to-AST crosswalk and the wild-scan dataset accepted as external references; both PRs merged by project lead kenhuangus

證據連結 →

xlabs-club/awesome-x-ops

已上線

xlabs-club · 自 2026-08-17 · 文件引用 · 證據現驗 2026-10-05

ATR added to the English and Simplified-Chinese lists by maintainer l10178 — ATR did not open this PR

證據連結 →

AMD GAIA

已上線

AMD · 自 2026-06-24 · 文件引用 · 證據現驗 2026-10-05

Official GAIA integrations doc — guarding the Lemonade model endpoint with an offline ATR input/output guard (prompt-injection detection pattern)

證據連結 →

ProjectRecon/awesome-ai-agents-security

已上線

ProjectRecon (independent) · 自 2026-06-12 · 文件引用 · 證據現驗 2026-10-05

ATR listed in the Static Analysis & Linters section

證據連結 →

raphabot/awesome-cybersecurity-agentic-ai

已上線

raphabot (independent) · 自 2026-06-28 · 文件引用 · 證據現驗 2026-10-05

ATR listed in the Tools section

證據連結 →
規劃整合中

開 Integration Request issue

想要 spec walkthrough、design review、你的語言的 sample code,或先討論整合形狀,就走這條。維護者七天內回覆——標準的責任之一,是讓整合的人不必獨自摸索格式。

開 issue →
已經 ship 了

提 PR 加進 ADOPTERS.md

整合已經公開可驗證,直接走這條。Schema 對、附 evidence link 就 merge——維護者不預先審核採用者,把你自己寫進公開紀錄,跟 Cisco、Microsoft、MISP 列在同一份檔案。

ADOPTERS.md →
徽章

你的專案 ship 了 ATR?在 README 加上這個徽章——讓下游知道你的偵測規則對著一個版本化、可審查的標準。

ATR Integrated
Markdown:
[![ATR Integrated](https://img.shields.io/badge/ATR-Integrated-2563EB?style=flat)](https://agentthreatrule.org/ecosystem)