9 dépôts
Tools and frameworks for simulating malicious behavior to test detection capabilities.
Explore 9 awesome GitHub repositories matching part of an awesome list · Adversary Emulation. Refine with filters or upvote what's useful.
Atomic Red Team is an adversary simulation tool and detection validation suite designed to emulate attacker behaviors. It functions as a security control testing framework that uses a library of portable tests to verify if security monitoring and alerting systems correctly identify specific malicious techniques. The project serves as a MITRE ATT&CK emulation framework, mapping individual test executions to a standardized industry taxonomy of adversary behaviors. This mapping allows for the validation of security controls against the MITRE ATT&CK matrix to identify gaps in detection and respon
Executes detection tests mapped to the MITRE ATT&CK framework.
Caldera is an adversary emulation platform and command and control framework designed to simulate cyber attack patterns. It functions as an automated red team tool and threat framework orchestrator, executing attack sequences based on standardized cybersecurity threat frameworks to validate security defenses and detection capabilities. The platform distinguishes itself through the dynamic compilation of customized executable payloads and the use of framework-mapped adversary modeling to structure attack techniques. It manages asynchronous agents on targeted endpoints via a central server acce
Automates post-compromise adversarial behavior in enterprise networks.
A toolset to make a system look as if it was the victim of an APT attack
Simulates compromise behavior using Windows batch scripts.
A utility to safely generate malicious network traffic patterns and evaluate controls.
Generates malicious network traffic to evaluate security controls.
Virtual Machine for Adversary Emulation and Threat Hunting
Virtual machine environment for threat hunting and adversary simulation.
An information security preparedness tool to do adversarial simulation.
Simulates adversarial activity for security preparedness.
RTA provides a framework of scripts designed to allow blue teams to test their detection capabilities against malicious tradecraft, modeled after MITRE ATT&CK.
Provides scripts to test blue team detection against malicious tradecraft.
"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.
Builds repeatable, distributed security events for testing.
Automated Tactics Techniques & Procedures
Automates complex sequences of tactics and techniques for testing.