awesome-repositories.com
Blog
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

BAS certification training

Ranking updated Jun 30, 2026

For a professional certification for breach and attack simulation, the strongest matches are mitre/caldera (Caldera is a comprehensive adversary emulation platform that provides), guardicore/monkey (This is a dedicated breach and attack simulation platform) and redcanaryco/atomic-red-team (Atomic Red Team is a comprehensive adversary emulation framework). datadog/stratus-red-team and endgameinc/rta round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

Find the best Breach and Attack Simulation certifications. Compare top-rated training programs by curriculum, hands-on labs, and cost to pick the right one.

BAS certification training

Find the best repos with AI.We'll search the best matching repositories with AI.
  • mitre/calderamitre avatar

    mitre/caldera

    7,047View on GitHub↗

    Caldera is an adversary emulation platform and command and control framework designed to simulate cyber attack patterns. It functions as an automated red team tool and threat framework orchestrator, executing attack sequences based on standardized cybersecurity threat frameworks to validate security defenses and detection capabilities. The platform distinguishes itself through the dynamic compilation of customized executable payloads and the use of framework-mapped adversary modeling to structure attack techniques. It manages asynchronous agents on targeted endpoints via a central server acce

    Caldera is a comprehensive adversary emulation platform that provides automated attack scenarios, MITRE ATT&CK mapping, and agent-based execution to validate security controls, making it a flagship tool for breach and attack simulation.

    PythonAdversary Emulation FrameworksAdversary EmulationAdversary Emulation
    View on GitHub↗7,047
  • guardicore/monkeyguardicore avatar

    guardicore/monkey

    7,014View on GitHub↗

    Monkey is an adversary emulation platform and breach and attack simulation tool designed to test network defenses through automated lateral movement and exploit delivery. It functions as a network security testing system that evaluates security posture by attempting to propagate through vulnerabilities and extract sensitive system credentials. The platform distinguishes itself by simulating specific real-world attacker behaviors, such as ransomware encryption, cryptojacking, and the theft of browser-stored credentials and secure shell keys. It utilizes binary hash randomization to evade antiv

    This is a dedicated breach and attack simulation platform that automates lateral movement and adversary emulation to validate security controls against real-world threats.

    PythonAdversary Emulation FrameworksAttack SimulationsSecurity Control Validations
    View on GitHub↗7,014
  • redcanaryco/atomic-red-teamredcanaryco avatar

    redcanaryco/atomic-red-team

    12,089View on GitHub↗

    Atomic Red Team is an adversary simulation tool and detection validation suite designed to emulate attacker behaviors. It functions as a security control testing framework that uses a library of portable tests to verify if security monitoring and alerting systems correctly identify specific malicious techniques. The project serves as a MITRE ATT&CK emulation framework, mapping individual test executions to a standardized industry taxonomy of adversary behaviors. This mapping allows for the validation of security controls against the MITRE ATT&CK matrix to identify gaps in detection and respon

    Atomic Red Team is a comprehensive adversary emulation framework that maps directly to MITRE ATT&CK techniques to validate security controls, serving as a foundational tool for testing detection capabilities against simulated attacks.

    CAdversary Emulation FrameworksAdversary EmulationAdversary Emulation
    View on GitHub↗12,089
  • datadog/stratus-red-teamDataDog avatar

    DataDog/stratus-red-team

    2,264View on GitHub↗

    This tool provides a framework for executing targeted, cloud-native adversary emulation scenarios that map directly to the MITRE ATT&CK framework, making it a specialized solution for validating security controls in cloud environments.

    GoAdversary EmulationAdversary Emulation Tools
    View on GitHub↗2,264
  • endgameinc/rtaendgameinc avatar

    endgameinc/RTA

    1,096View on GitHub↗

    RTA provides a framework of scripts designed to allow blue teams to test their detection capabilities against malicious tradecraft, modeled after MITRE ATT&CK.

    This framework provides a collection of scripts for executing adversary emulation scenarios mapped to MITRE ATT&CK, allowing security teams to validate their detection capabilities against specific malicious tradecraft.

    PythonAdversary EmulationAdversary Emulation
    View on GitHub↗1,096
  • nextronsystems/aptsimulatorNextronSystems avatar

    NextronSystems/APTSimulator

    2,750View on GitHub↗

    A toolset to make a system look as if it was the victim of an APT attack

    This toolset simulates the artifacts and behaviors of an APT attack to test security detection capabilities, serving as a practical utility for adversary emulation and security posture validation.

    BatchfileAdversary EmulationAdversary Emulation
    View on GitHub↗2,750
  • uber-common/mettauber-common avatar

    uber-common/metta

    1,140View on GitHub↗

    An information security preparedness tool to do adversarial simulation.

    Metta is an adversary emulation framework that allows you to define and execute automated attack scenarios to test security controls, fitting the core requirements of a breach and attack simulation tool.

    PythonAdversary EmulationAdversary Emulation
    View on GitHub↗1,140
  • funnywolf/viperFunnyWolf avatar

    FunnyWolf/Viper

    4,964View on GitHub↗

    Viper is a command and control infrastructure manager and post-exploitation framework designed for adversary attack simulation and security assessment. It functions as an orchestrator for penetration testing, combining a system for managing compromised hosts across multiple operating systems with tools for security workflow automation. The platform is distinguished by its use of large language model agents to coordinate red team tasks, automate data processing, and provide intelligent decision support. It includes a network pivot visualizer that uses directional graphs to map relationships an

    Viper is a post-exploitation and command-and-control framework that facilitates adversary simulation and red team operations, serving as a functional tool for testing security posture through automated attack workflows.

    Attack SimulationsRed Team Workflow Automations
    View on GitHub↗4,964
  • fsecurelabs/leonidasfsecurelabs avatar

    fsecurelabs/leonidas

    616View on GitHub↗

    Automated Attack Simulation in the Cloud, complete with detection use cases.

    Leonidas is an automated adversary emulation tool designed to simulate cloud-based attack scenarios and validate detection capabilities, fitting the core requirements of a breach and attack simulation platform.

    PythonAdversary Emulation Tools
    View on GitHub↗616
  • bishopfox/sliverBishopFox avatar

    BishopFox/sliver

    10,707View on GitHub↗

    Sliver is a command and control framework designed for adversary emulation and security assessment operations. It provides a centralized platform for managing remote systems, enabling security professionals to coordinate multi-operator sessions and maintain persistent, secure communication channels across diverse network environments. The framework distinguishes itself through its focus on stealth and infrastructure flexibility. It utilizes dynamic payload obfuscation to generate unique binaries and supports in-memory execution to minimize disk artifacts. Communication is secured through mutu

    Sliver is a command-and-control framework designed for adversary emulation and red team engagements, providing the core infrastructure for executing attack scenarios and testing security posture.

    GoAdversary Emulation Frameworks
    View on GitHub↗10,707
  • splunk/attack_rangesplunk avatar

    splunk/attack_range

    2,507View on GitHub↗

    Attack Range is a cybersecurity breach simulation framework designed to orchestrate the lifecycle of security labs and execute controlled attack scenarios. It functions as a security simulation infrastructure orchestrator, enabling the deployment of instrumented cloud and local environments to validate defensive capabilities and generate security telemetry. The platform distinguishes itself through configuration-driven automation and infrastructure-as-code orchestration, which allow for the repeatable provisioning of vulnerable environments. It manages the entire simulation lifecycle, from th

    This framework provides the infrastructure orchestration and automated attack execution necessary to simulate cyberattacks and validate security controls, making it a functional tool for testing security posture.

    PythonAttack Simulations
    View on GitHub↗2,507
  • aquasecurity/kube-hunteraquasecurity avatar

    aquasecurity/kube-hunter

    5,064View on GitHub↗

    Kube-hunter is a security scanner and vulnerability hunter for Kubernetes clusters. It operates as a cloud-native penetration tool designed to identify security weaknesses, infrastructure misconfigurations, and exploitable gaps by simulating attacker techniques. The tool distinguishes itself through a dual-mode scanning engine that executes both remote external probes and internal network scans. It features identity-based impersonation, allowing it to use service account tokens and pod identities to simulate security access from specific cluster roles and determine the potential blast radius

    Kube-hunter is a specialized penetration testing tool that simulates attacker techniques within Kubernetes environments to validate security posture, fitting the category by actively testing infrastructure against known vulnerabilities and misconfigurations.

    PythonKubernetes Vulnerability HuntersPenetration Testing FrameworksAccount Impersonation
    View on GitHub↗5,064
  • rapid7/metasploit-frameworkrapid7 avatar

    rapid7/metasploit-framework

    38,415View on GitHub↗

    The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures. The platform distinguishes itself through a modular architecture that supports reflective payload injection, allowing for the execution of code directly in memory without writing to disk. It utilizes an asynchronous event loop to

    This is a comprehensive penetration testing framework that provides the core capabilities for executing security exploits and validating vulnerabilities, though it focuses more on manual and semi-automated testing than the continuous, automated simulation typical of a dedicated BAS platform.

    RubyPenetration Testing PlatformsExploit FrameworksExploitation Frameworks
    View on GitHub↗38,415
Compare the top 10 at a glance
RepositoryStarsLanguageLicenseLast push
mitre/caldera7KPythonApache-2.0Jun 17, 2026
guardicore/monkey7KPythonGPL-3.0May 1, 2025
redcanaryco/atomic-red-team12.1KCMITJun 15, 2026
datadog/stratus-red-team2.3KGoapache-2.0Feb 13, 2026
endgameinc/rta1.1KPythonNOASSERTIONMay 1, 2019
nextronsystems/aptsimulator2.8KBatchfileMITSep 23, 2025
uber-common/metta1.1KPythonMITApr 1, 2019
funnywolf/viper5K——Jan 18, 2026
fsecurelabs/leonidas616PythonMITNov 28, 2024
bishopfox/sliver10.7KGogpl-3.0Feb 20, 2026

Related searches

  • a professional certification for network security
  • an open source toolkit for penetration testing
  • a professional certification for API design
  • a platform for practicing cybersecurity skills
  • an adversary emulation toolkit
  • an autonomous framework for penetration testing
  • a phishing simulation platform
  • an intentionally vulnerable cloud environment for practice