Profiles

AttackTree profiles supply the scales the engine computes with and libraries of actor archetypes, attack vectors, and controls: the default and agentic profiles, and how to write your own.

A profile is a YAML file in profiles/. It supplies two things:

  • Scales the engine computes with: capability levels, complexity, cost tiers, requires tags, control effect and cost levels, impact classes, likelihood levels, and the risk matrix.
  • Libraries the model command draws on: actor archetypes, attack vector proposals, control proposals, and, for agentic systems, zones. Proposals are a checklist for the agent, never inserted automatically.

Activate profiles with profiles in the configuration. A tree records the profiles it was built with in attacktree.profiles, and that list wins over the configuration. The default profile’s scales always apply; other profiles add libraries on top.

# default

PartContents
Scalesthe values documented in Risk model
requires tagsauthenticated, insider-access, privileged-access, special-equipment, long-duration, illegal, physical-presence, violence
Actor archetypes8, following Christian Schneider’s scenario-driven set: script kiddie, hacktivist, outside and inside attacker groups, social engineer, compromised employee, malicious administrator, state-sponsored group
Vector proposals20 common attacks, from credential stuffing and SQL injection to dependency compromise and bribery, with MITRE CAPEC, CWE, and ATT&CK references
Control proposals16 safeguards with default kind and effect and OWASP ASVS 4.0.3 references (one, immutable backups, cites NIST CSF)

The ASVS references use the key asvs-4.0 because ASVS 5.0 renumbered every chapter. Edition-pinned keys keep references meaningful when standards move.

# agentic

PartContents
Zonesinput, reasoning, tools, memory, inter-agent
Actor archetypes4: author of content the agent reads, publisher of a malicious tool or MCP server, model-assisted adversary, compromised peer agent
Vector proposals15, with OWASP Top 10 for LLM Applications 2026, OWASP Top 10 for Agentic Applications 2026, MITRE ATLAS, and MAESTRO references
Control proposals16: 11 deterministic (tool pinning, allowlists, credential isolation, sandboxing, recursion caps, …) and 5 probabilistic (injection classifier, goal-lock check, human-in-the-loop, output guardrail, behaviour monitoring)

See Agentic and LLM systems for how to use it.

# Write your own

Add profiles/<id>.yaml to the extension, in an installed project .specify/extensions/attacktree/profiles/. Give it a unique profile.id and add the id to profiles. Keep the file under version control elsewhere too: specify extension update replaces the extension directory. To change the arithmetic, declare only the scales keys you change; everything else comes from default:

profile:
  id: fintech
  name: Payment platform
  version: "0.1"

scales:
  requires:
    authenticated: { access: user }
    payment-instrument: { resources: moderate }   # a new tag for leaves
  likelihood_levels: { low: 0, medium: 10, high: 30, very-high: 60 }   # stricter bands

actor_archetypes:
  - { id: fraud-ring, name: Organised fraud ring, skill: advanced, resources: substantial, access: external, risk_appetite: high }

Keep it consistent: every complexity maps to a defined skill, every requires tag names defined capability levels, and every risk-matrix row covers every impact level. attacktree.sh validate rejects trees that use a requires tag no active profile defines.