awesome-repositories.com
Blog
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektÜber unsRanking-MethodikPresseMCP-Server
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to mitre/caldera

Open-source alternatives to Caldera

30 open-source projects similar to mitre/caldera, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Caldera alternative.

  • redcanaryco/atomic-red-teamAvatar von redcanaryco

    redcanaryco/atomic-red-team

    12,089Auf GitHub ansehen↗

    Atomic Red Team is an adversary simulation tool and detection validation suite designed to emulate attacker behaviors. It functions as a security control testing framework that uses a library of portable tests to verify if security monitoring and alerting systems correctly identify specific malicious techniques. The project serves as a MITRE ATT&CK emulation framework, mapping individual test executions to a standardized industry taxonomy of adversary behaviors. This mapping allows for the validation of security controls against the MITRE ATT&CK matrix to identify gaps in detection and respon

    Cmitremitre-attack
    Auf GitHub ansehen↗12,089
  • bishopfox/sliverAvatar von BishopFox

    BishopFox/sliver

    10,707Auf GitHub ansehen↗

    Sliver is a command and control framework designed for adversary emulation and security assessment operations. It provides a centralized platform for managing remote systems, enabling security professionals to coordinate multi-operator sessions and maintain persistent, secure communication channels across diverse network environments. The framework distinguishes itself through its focus on stealth and infrastructure flexibility. It utilizes dynamic payload obfuscation to generate unique binaries and supports in-memory execution to minimize disk artifacts. Communication is secured through mutu

    Goadversarial-attacksadversary-simulationc2
    Auf GitHub ansehen↗10,707
  • samratashok/nishangAvatar von samratashok

    samratashok/nishang

    9,951Auf GitHub ansehen↗

    Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows targets. It functions as a post-exploitation toolkit and payload generator to automate attacks and manage remote targets. The project provides specialized capabilities for bypassing security controls, such as disabling the Antimalware Scan Interface and employing in-memory execution to avoid disk-based detection. It includes a variety of stealthy command and control mechanisms, utilizing non-standard channels like DNS TXT records, ICMP traffic, and webmail for communication a

    PowerShellactivedirectoryhackinginfosec
    Auf GitHub ansehen↗9,951

KI-Suche

Entdecke weitere awesome Repositories

Beschreibe in einfachen Worten, was du brauchst — die KI bewertet tausende kuratierte Open-Source-Projekte nach Relevanz.

Find more with AI search
  • cobbr/covenantAvatar von cobbr

    cobbr/Covenant

    4,699Auf GitHub ansehen↗

    Covenant is a .NET-based command and control framework designed for red team operations and adversary simulation. It serves as a collaborative platform for coordinating security assessments, managing remote implants, and executing tasks on compromised systems through a centralized server. The project is distinguished by its dynamic payload generator, which compiles and obfuscates executable binaries and scripts on the fly to bypass detection. It further separates itself through a collaborative environment that allows multiple authenticated operators to share a synchronized state, track operat

    C#
    Auf GitHub ansehen↗4,699
  • uber-common/mettaAvatar von uber-common

    uber-common/metta

    1,140Auf GitHub ansehen↗

    An information security preparedness tool to do adversarial simulation.

    Python
    Auf GitHub ansehen↗1,140
  • endgameinc/rtaAvatar von endgameinc

    endgameinc/RTA

    1,096Auf GitHub ansehen↗

    RTA provides a framework of scripts designed to allow blue teams to test their detection capabilities against malicious tradecraft, modeled after MITRE ATT&CK.

    Python
    Auf GitHub ansehen↗1,096
  • alphasoc/flightsimAvatar von alphasoc

    alphasoc/flightsim

    1,360Auf GitHub ansehen↗

    A utility to safely generate malicious network traffic patterns and evaluate controls.

    Go
    Auf GitHub ansehen↗1,360
  • nextronsystems/aptsimulatorAvatar von NextronSystems

    NextronSystems/APTSimulator

    2,750Auf GitHub ansehen↗

    A toolset to make a system look as if it was the victim of an APT attack

    Batchfile
    Auf GitHub ansehen↗2,750
  • n1nj4sec/pupyAvatar von n1nj4sec

    n1nj4sec/pupy

    8,942Auf GitHub ansehen↗

    Pupy is a command and control framework and post-exploitation suite used for remote administration and system management. It functions as a cross-platform tool for deploying payloads and controlling multiple remote agents through encrypted communication channels. The framework features a multi-platform payload generator that creates custom executable files using configurable network launchers. It employs a network traffic obfuscator that stacks encryption and obfuscation protocols to hide communication from observation. The system provides capabilities for in-memory code execution, remote pr

    Pythonandroidbackdoorlinux
    Auf GitHub ansehen↗8,942
  • its-a-feature/apfellAvatar von its-a-feature

    its-a-feature/Apfell

    4,570Auf GitHub ansehen↗

    Apfell is a red teaming framework and command and control server designed for collaborative adversary simulation. It provides a centralized infrastructure to manage remote agents and distribute tasking across multiple operating systems using a message broker for real-time synchronization. The system functions as a distributed agent orchestrator, allowing teams to coordinate complex attack chains and synchronize container data. It features a multi-platform payload manager that enables the downloading and integration of custom agents and command profiles from remote repositories. The platform

    JavaScript
    Auf GitHub ansehen↗4,570
  • trycatchhcf/dumpsterfireAvatar von TryCatchHCF

    TryCatchHCF/DumpsterFire

    1,036Auf GitHub ansehen↗

    "Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.

    Pythonautomationblue-teamblue-teams
    Auf GitHub ansehen↗1,036
  • redhuntlabs/redhunt-osAvatar von redhuntlabs

    redhuntlabs/RedHunt-OS

    1,316Auf GitHub ansehen↗

    Virtual Machine for Adversary Emulation and Threat Hunting

    Auf GitHub ansehen↗1,316
  • guardicore/monkeyAvatar von guardicore

    guardicore/monkey

    7,014Auf GitHub ansehen↗

    Monkey is an adversary emulation platform and breach and attack simulation tool designed to test network defenses through automated lateral movement and exploit delivery. It functions as a network security testing system that evaluates security posture by attempting to propagate through vulnerabilities and extract sensitive system credentials. The platform distinguishes itself by simulating specific real-world attacker behaviors, such as ransomware encryption, cryptojacking, and the theft of browser-stored credentials and secure shell keys. It utilizes binary hash randomization to evade antiv

    Python
    Auf GitHub ansehen↗7,014
  • havocframework/havocAvatar von HavocFramework

    HavocFramework/Havoc

    8,182Auf GitHub ansehen↗

    Havoc is a post-exploitation framework used for red team operations. It provides a centralized command and control system for managing remote agents through persistent network connections and customizable communication profiles. The framework focuses on security evasion and stealth, utilizing indirect syscall execution, return address spoofing, and hardware-breakpoint patching to bypass endpoint detection and response tools. It includes a payload generation workflow to create executable shellcode or DLLs for initial remote access. The system covers a broad range of operational capabilities,

    Go
    Auf GitHub ansehen↗8,182
  • thehive-project/thehiveAvatar von TheHive-Project

    TheHive-Project/TheHive

    3,891Auf GitHub ansehen↗

    TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables. The platform is distinguished by its multi-tenant architecture, which isolates data across different organizations while supporting selective cross-tenant sharing. It features a SOAR automation engine capable of executing sandboxed JavaScript logic to automate workflows and trigger response actions thro

    Scalaanalyzerapicortex
    Auf GitHub ansehen↗3,891
  • bc-security/empireAvatar von BC-SECURITY

    BC-SECURITY/Empire

    5,045Auf GitHub ansehen↗

    Empire is a post-exploitation command-and-control (C2) framework designed for red team operations. It deploys and manages agents written in PowerShell, Python, C#, Go, and C across Windows, Linux, and macOS, using encrypted communication channels over HTTP, HTTPS, and SMB. The framework executes over 400 built-in modules for reconnaissance, privilege escalation, credential theft, and lateral movement, and provides a modular engine for authoring custom attack modules. What sets Empire apart is its multi-language agent deployment system, which allows operators to choose implants that suit each

    PowerShellc2empirehacktoberfest
    Auf GitHub ansehen↗5,045
  • nyan-x-cat/asyncrat-c-sharpAvatar von NYAN-x-CAT

    NYAN-x-CAT/AsyncRAT-C-Sharp

    2,837Auf GitHub ansehen↗
    C#adminasynchronousbackdoor
    Auf GitHub ansehen↗2,837
  • bluscreenofjeff/red-team-infrastructure-wikiAvatar von bluscreenofjeff

    bluscreenofjeff/Red-Team-Infrastructure-Wiki

    4,498Auf GitHub ansehen↗

    This project is a collection of technical resources, blueprints, and guides for building resilient and stealthy red team infrastructure. It provides a comprehensive framework for designing offensive security environments that resist detection and remain operational throughout security engagements. The repository distinguishes itself through detailed playbooks for adversary simulation and hardening manuals. It covers advanced obfuscation techniques such as domain fronting, the use of platform-as-a-service redirectors, and the leveraging of third-party content sites to inherit domain reputation

    Auf GitHub ansehen↗4,498
  • quasar/quasarQ

    quasar/Quasar

    9,865Auf GitHub ansehen↗

    Quasar is an encrypted TCP-based remote administration tool for Windows that combines command-and-control capabilities with credential extraction, keystroke logging, file and registry management, desktop monitoring, and SOCKS5 reverse proxy tunneling. It operates through a modular framework where individual capabilities are loaded as plugins communicating over an encrypted command channel. The tool distinguishes itself by integrating credential recovery from browsers and FTP clients, keystroke capture with full Unicode support, and a SOCKS5 reverse proxy for routing network traffic through th

    C#
    Auf GitHub ansehen↗9,865
  • datadog/stratus-red-teamAvatar von DataDog

    DataDog/stratus-red-team

    2,264Auf GitHub ansehen↗
    Goadversary-emulationawsaws-security
    Auf GitHub ansehen↗2,264
  • its-a-feature/mythicAvatar von its-a-feature

    its-a-feature/Mythic

    4,571Auf GitHub ansehen↗

    Mythic is a red teaming framework and command and control server designed for managing post-exploitation activities. It provides a centralized system for issuing tasks and receiving telemetry from agents deployed across diverse target platforms and operating systems. The platform features a collaborative operator interface that allows multiple security researchers to coordinate operations and track target activity within a shared environment. It supports the deployment and updating of diverse agent payloads through a multi-platform payload manager. The framework utilizes a plugin-based archi

    JavaScript
    Auf GitHub ansehen↗4,571
  • specterops/bloodhoundAvatar von SpecterOps

    SpecterOps/BloodHound

    2,789Auf GitHub ansehen↗

    BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity relationships and permissions in Active Directory. It functions as a security tool for auditing directory services, uncovering unintended privilege relationships, and visualizing sequences of permissions that can lead to domain compromise. The project differentiates itself as a comprehensive adversary emulation framework that coordinates remote agents and executes post-exploitation commands. It includes a reverse proxy for bypassing multi-factor authentication via real-time session hij

    Go
    Auf GitHub ansehen↗2,789
  • mandiant/commando-vmAvatar von mandiant

    mandiant/commando-vm

    7,667Auf GitHub ansehen↗

    Commando VM is a Windows-based penetration testing distribution and offensive security virtual machine. It serves as a toolset manager for deploying and maintaining a curated collection of security tools, scripts, and configurations designed for security auditing, red teaming, and adversary simulation. The project automates the provisioning of a specialized workstation by using PowerShell scripts and a modular repository to orchestrate the installation of offensive security software. It utilizes a community-driven package manager to handle dependency resolution and binary installations, ensur

    PowerShellfireeye-flarepenetration-testingred-teaming
    Auf GitHub ansehen↗7,667
  • lolbas-project/lolbasAvatar von LOLBAS-Project

    LOLBAS-Project/LOLBAS

    8,323Auf GitHub ansehen↗

    LOLBAS is a curated database and knowledge base of signed Windows binaries that can be misused to bypass security restrictions and execute unauthorized code. It serves as a technical registry that maps trusted system files to their functional capabilities and the offensive tactics they enable. The project distinguishes itself by providing a capability-driven indexing system and a tactics registry that relates legitimate binary functionality to known security evasion techniques. It includes an association layer that links specific system binaries to attack patterns and tactical objectives, pro

    XSLTblueteamdfirliving-off-the-land
    Auf GitHub ansehen↗8,323
  • fireeye/commando-vmAvatar von fireeye

    fireeye/commando-vm

    7,668Auf GitHub ansehen↗

    Commando-VM is a Windows penetration testing distribution and offensive security toolkit. It provides a specialized virtual machine environment loaded with a curated suite of security auditing and exploitation tools designed for red teaming operations. The project facilitates the creation of red team infrastructure and security audit environments. It focuses on windows security auditing and penetration testing to help simulate adversary behavior and identify exploitable security flaws. The environment is established through script-based provisioning and modular toolset deployment. This proce

    PowerShell
    Auf GitHub ansehen↗7,668
  • veil-framework/veil-evasionAvatar von Veil-Framework

    Veil-Framework/Veil-Evasion

    1,838Auf GitHub ansehen↗

    Veil-Evasion is a framework designed for generating custom executable files to test defensive systems. It functions as a security testing utility that simulates patterns used to bypass security software during authorized penetration testing. The platform distinguishes itself through a modular build system that transforms scripts into standalone native binaries, ensuring consistent execution across different operating systems without external dependencies. It utilizes template-based source injection to construct these payloads, allowing for the dynamic configuration of executable files during

    Pythonantivirusantivirus-evasionpython
    Auf GitHub ansehen↗1,838
  • albertlauncher/albertAvatar von albertlauncher

    albertlauncher/albert

    7,945Auf GitHub ansehen↗

    Albert is a keyboard launcher that opens files, applications, and runs commands by typing search queries into a search bar. It functions as a keyboard-driven workflow tool, enabling users to navigate their file system, launch installed applications, and execute shell commands without touching a mouse. The launcher processes user input through a plugin-based modular architecture, where functionality is extended by dynamically loaded C++ and Python plugins. Queries are dispatched to all enabled handlers in parallel, with results merged and ranked by a combination of match quality and historical

    C++albertalbertlauncherapplication-launcher
    Auf GitHub ansehen↗7,945
  • ckeditor/ckeditor4Avatar von ckeditor

    ckeditor/ckeditor4

    5,817Auf GitHub ansehen↗

    CKEditor 4 is a browser-based WYSIWYG rich text editor that enables users to create and format HTML content directly in the browser. It operates on a plugin-based architecture with a configurable toolbar system, DOM-based content editing, and an event-driven lifecycle, all delivered through a CDN-based distribution model. The editor supports skin-based theming and includes a legacy plugin compatibility layer for backward compatibility. The editor distinguishes itself as a cross-platform framework that integrates natively with Angular, React, Vue, Electron, Android, and iOS environments. It of

    Rich Text Formatckeditorckeditor4contenteditable
    Auf GitHub ansehen↗5,817
  • screetsec/thefatratAvatar von screetsec

    screetsec/TheFatRat

    11,038Auf GitHub ansehen↗

    TheFatRat is a security exploitation framework designed to automate the creation, obfuscation, and deployment of payloads for penetration testing. It functions as a comprehensive toolkit that streamlines the exploitation lifecycle, enabling users to generate malicious executables, manage network listeners, and execute post-exploitation tasks through a unified command-line interface. The framework distinguishes itself by integrating various third-party exploitation utilities into a single, orchestrated workflow. It provides specialized capabilities for embedding code into legitimate binaries a

    Caccessibilityantivirusautorun
    Auf GitHub ansehen↗11,038
  • ccfos/nightingaleAvatar von ccfos

    ccfos/nightingale

    13,108Auf GitHub ansehen↗

    Nightingale is a Prometheus-compatible monitoring and alerting platform designed to centralize telemetry management across multiple time-series databases. It functions as a multi-source alerting engine and metric data pipeline that ingests telemetry via remote write protocols and triggers alarms based on data from sources such as Prometheus, Elasticsearch, Loki, and ClickHouse. The system is distinguished by its automated alert healing system, which executes predefined scripts and RPC-based corrective actions when monitoring thresholds are breached. It supports distributed alert processing, a

    Goalertingccfmetrics
    Auf GitHub ansehen↗13,108