awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
redcanaryco avatar

redcanaryco/atomic-red-team

0
View on GitHub↗
12,089 stars·3,133 forks·C·MIT·25 views

Atomic Red Team

Atomic Red Team is an adversary simulation tool and detection validation suite designed to emulate attacker behaviors. It functions as a security control testing framework that uses a library of portable tests to verify if security monitoring and alerting systems correctly identify specific malicious techniques.

The project serves as a MITRE ATT&CK emulation framework, mapping individual test executions to a standardized industry taxonomy of adversary behaviors. This mapping allows for the validation of security controls against the MITRE ATT&CK matrix to identify gaps in detection and response capabilities.

The system covers security detection engineering and control verification by executing attack patterns through shell-based commands. These tests are defined as structured data files and can be run within containerized environments or via cloud-based development containers to ensure consistent results across different hosts.

Features

  • Adversary Emulation Tools - Provides modular scripts that mimic real-world attacker behaviors to test security monitoring and alerting.
  • Adversary Technique Mappings - Aligns individual security tests with the MITRE ATT&CK taxonomy to identify gaps in detection capabilities.
  • Adversary Emulation Frameworks - Implements a library of portable security tests mapped to the MITRE ATT&CK matrix for validating detection capabilities.
  • Security Testing - Provides a standardized system for executing attack patterns to find gaps in endpoint and network security visibility.
  • Security Testing Tools - Provides portable tests that mimic threat actor methods to verify that security tools function as expected.
  • Security Detection Test Suites - Ships a collection of atomic tests used to verify that security software correctly identifies malicious techniques.
  • Framework-Based Validation - Tests security controls against the MITRE ATT&CK framework to identify gaps in detection and response.
  • Shell Command Execution - Executes portable shell commands across different operating systems to trigger and verify security alerts.
  • YAML-Based Task Definitions - Uses YAML-formatted files to declaratively define attack techniques, shell commands, and expected security outcomes.
  • Threat Simulation Tools - Library of small, portable tests mapped to adversary tactics.
  • Adversary Simulation - Portable detection tests based on MITRE ATT&CK.
  • Adversary Emulation - Executes detection tests mapped to the MITRE ATT&CK framework.
  • General Security Utilities - Library of tests mapped to the ATT&CK framework for security validation.
  • Adversary Emulation - Portable detection tests mapped to the MITRE ATT&CK framework.
  • Blue Team Tools - Detection tests based on MITRE ATT&CK.
  • Detection Engineering - Library of tests mapped to MITRE ATT&CK techniques.
  • Penetration Testing Toolkits - A library of tests mapped to the MITRE ATT&CK framework.
  • Vulnerability Scanning and Auditing - Library of tests mapped to adversary tactics.

Star history

Star history chart for redcanaryco/atomic-red-teamStar history chart for redcanaryco/atomic-red-team

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Atomic Red Team

These projects share indexed features with Atomic Red Team. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • mitre/calderamitre avatar

    mitre/caldera

    7,047View on GitHub↗

    Caldera is an adversary emulation platform and command and control framework designed to simulate cyber attack patterns. It functions as an automated red team tool and threat framework orchestrator, executing attack sequences based on standardized cybersecurity threat frameworks to validate security defenses and detection capabilities. The platform distinguishes itself through the dynamic compilation of customized executable payloads and the use of framework-mapped adversary modeling to structure attack techniques. It manages asynchronous agents on targeted endpoints via a central server acce

    Python
    View on GitHub↗7,047
  • endgameinc/rtaendgameinc avatar

    endgameinc/RTA

    1,096View on GitHub↗

    RTA provides a framework of scripts designed to allow blue teams to test their detection capabilities against malicious tradecraft, modeled after MITRE ATT&CK.

    Python
    View on GitHub↗1,096
  • alphasoc/flightsimalphasoc avatar

    alphasoc/flightsim

    1,360View on GitHub↗

    A utility to safely generate malicious network traffic patterns and evaluate controls.

    Go
    View on GitHub↗1,360
  • nextronsystems/aptsimulatorNextronSystems avatar

    NextronSystems/APTSimulator

    2,750View on GitHub↗

    A toolset to make a system look as if it was the victim of an APT attack

    Batchfile
    View on GitHub↗2,750
Compare all 30 related projects→

Frequently asked questions

What does redcanaryco/atomic-red-team do?

Atomic Red Team is an adversary simulation tool and detection validation suite designed to emulate attacker behaviors. It functions as a security control testing framework that uses a library of portable tests to verify if security monitoring and alerting systems correctly identify specific malicious techniques.

What are the main features of redcanaryco/atomic-red-team?

The main features of redcanaryco/atomic-red-team are: Adversary Emulation Tools, Adversary Technique Mappings, Adversary Emulation Frameworks, Security Testing, Security Testing Tools, Security Detection Test Suites, Framework-Based Validation, Shell Command Execution.

Which projects share features with redcanaryco/atomic-red-team?

Projects with overlapping indexed features include: mitre/caldera — Caldera is an adversary emulation platform and command and control framework designed to simulate cyber attack… endgameinc/rta — RTA provides a framework of scripts designed to allow blue teams to test their detection capabilities against… alphasoc/flightsim — A utility to safely generate malicious network traffic patterns and evaluate controls. nextronsystems/aptsimulator — A toolset to make a system look as if it was the victim of an APT attack. uber-common/metta — An information security preparedness tool to do adversarial simulation. guardicore/monkey — Monkey is an adversary emulation platform and breach and attack simulation tool designed to test network defenses…