awesome-repositories.com
博客
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

BAS 认证培训

排名更新于 2026年6月30日

For a professional certification for breach and attack simulation, the strongest matches are mitre/caldera (Caldera is a comprehensive adversary emulation platform that provides), guardicore/monkey (This is a dedicated breach and attack simulation platform) and redcanaryco/atomic-red-team (Atomic Red Team is a comprehensive adversary emulation framework). datadog/stratus-red-team and endgameinc/rta round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

寻找最优秀的入侵与攻击模拟(BAS)认证。通过课程内容、实操实验和成本对比热门培训项目,挑选最合适的方案。

BAS 认证培训

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • mitre/calderamitre 的头像

    mitre/caldera

    7,047在 GitHub 上查看↗

    Caldera is an adversary emulation platform and command and control framework designed to simulate cyber attack patterns. It functions as an automated red team tool and threat framework orchestrator, executing attack sequences based on standardized cybersecurity threat frameworks to validate security defenses and detection capabilities. The platform distinguishes itself through the dynamic compilation of customized executable payloads and the use of framework-mapped adversary modeling to structure attack techniques. It manages asynchronous agents on targeted endpoints via a central server acce

    Caldera is a comprehensive adversary emulation platform that provides automated attack scenarios, MITRE ATT&CK mapping, and agent-based execution to validate security controls, making it a flagship tool for breach and attack simulation.

    PythonAdversary Emulation FrameworksAdversary EmulationAdversary Emulation
    在 GitHub 上查看↗7,047
  • guardicore/monkeyguardicore 的头像

    guardicore/monkey

    7,014在 GitHub 上查看↗

    Monkey is an adversary emulation platform and breach and attack simulation tool designed to test network defenses through automated lateral movement and exploit delivery. It functions as a network security testing system that evaluates security posture by attempting to propagate through vulnerabilities and extract sensitive system credentials. The platform distinguishes itself by simulating specific real-world attacker behaviors, such as ransomware encryption, cryptojacking, and the theft of browser-stored credentials and secure shell keys. It utilizes binary hash randomization to evade antiv

    This is a dedicated breach and attack simulation platform that automates lateral movement and adversary emulation to validate security controls against real-world threats.

    PythonAdversary Emulation FrameworksAttack SimulationsSecurity Control Validations
    在 GitHub 上查看↗7,014
  • redcanaryco/atomic-red-teamredcanaryco 的头像

    redcanaryco/atomic-red-team

    12,089在 GitHub 上查看↗

    Atomic Red Team is an adversary simulation tool and detection validation suite designed to emulate attacker behaviors. It functions as a security control testing framework that uses a library of portable tests to verify if security monitoring and alerting systems correctly identify specific malicious techniques. The project serves as a MITRE ATT&CK emulation framework, mapping individual test executions to a standardized industry taxonomy of adversary behaviors. This mapping allows for the validation of security controls against the MITRE ATT&CK matrix to identify gaps in detection and respon

    Atomic Red Team is a comprehensive adversary emulation framework that maps directly to MITRE ATT&CK techniques to validate security controls, serving as a foundational tool for testing detection capabilities against simulated attacks.

    CAdversary Emulation FrameworksAdversary EmulationAdversary Emulation
    在 GitHub 上查看↗12,089
  • datadog/stratus-red-teamDataDog 的头像

    DataDog/stratus-red-team

    2,264在 GitHub 上查看↗

    This tool provides a framework for executing targeted, cloud-native adversary emulation scenarios that map directly to the MITRE ATT&CK framework, making it a specialized solution for validating security controls in cloud environments.

    GoAdversary EmulationAdversary Emulation Tools
    在 GitHub 上查看↗2,264
  • endgameinc/rtaendgameinc 的头像

    endgameinc/RTA

    1,096在 GitHub 上查看↗

    RTA provides a framework of scripts designed to allow blue teams to test their detection capabilities against malicious tradecraft, modeled after MITRE ATT&CK.

    This framework provides a collection of scripts for executing adversary emulation scenarios mapped to MITRE ATT&CK, allowing security teams to validate their detection capabilities against specific malicious tradecraft.

    PythonAdversary EmulationAdversary Emulation
    在 GitHub 上查看↗1,096
  • nextronsystems/aptsimulatorNextronSystems 的头像

    NextronSystems/APTSimulator

    2,750在 GitHub 上查看↗

    A toolset to make a system look as if it was the victim of an APT attack

    This toolset simulates the artifacts and behaviors of an APT attack to test security detection capabilities, serving as a practical utility for adversary emulation and security posture validation.

    BatchfileAdversary EmulationAdversary Emulation
    在 GitHub 上查看↗2,750
  • uber-common/mettauber-common 的头像

    uber-common/metta

    1,140在 GitHub 上查看↗

    An information security preparedness tool to do adversarial simulation.

    Metta is an adversary emulation framework that allows you to define and execute automated attack scenarios to test security controls, fitting the core requirements of a breach and attack simulation tool.

    PythonAdversary EmulationAdversary Emulation
    在 GitHub 上查看↗1,140
  • funnywolf/viperFunnyWolf 的头像

    FunnyWolf/Viper

    4,964在 GitHub 上查看↗

    Viper is a command and control infrastructure manager and post-exploitation framework designed for adversary attack simulation and security assessment. It functions as an orchestrator for penetration testing, combining a system for managing compromised hosts across multiple operating systems with tools for security workflow automation. The platform is distinguished by its use of large language model agents to coordinate red team tasks, automate data processing, and provide intelligent decision support. It includes a network pivot visualizer that uses directional graphs to map relationships an

    Viper is a post-exploitation and command-and-control framework that facilitates adversary simulation and red team operations, serving as a functional tool for testing security posture through automated attack workflows.

    Attack SimulationsRed Team Workflow Automations
    在 GitHub 上查看↗4,964
  • fsecurelabs/leonidasfsecurelabs 的头像

    fsecurelabs/leonidas

    616在 GitHub 上查看↗

    Automated Attack Simulation in the Cloud, complete with detection use cases.

    Leonidas is an automated adversary emulation tool designed to simulate cloud-based attack scenarios and validate detection capabilities, fitting the core requirements of a breach and attack simulation platform.

    PythonAdversary Emulation Tools
    在 GitHub 上查看↗616
  • bishopfox/sliverBishopFox 的头像

    BishopFox/sliver

    10,707在 GitHub 上查看↗

    Sliver is a command and control framework designed for adversary emulation and security assessment operations. It provides a centralized platform for managing remote systems, enabling security professionals to coordinate multi-operator sessions and maintain persistent, secure communication channels across diverse network environments. The framework distinguishes itself through its focus on stealth and infrastructure flexibility. It utilizes dynamic payload obfuscation to generate unique binaries and supports in-memory execution to minimize disk artifacts. Communication is secured through mutu

    Sliver is a command-and-control framework designed for adversary emulation and red team engagements, providing the core infrastructure for executing attack scenarios and testing security posture.

    GoAdversary Emulation Frameworks
    在 GitHub 上查看↗10,707
  • splunk/attack_rangesplunk 的头像

    splunk/attack_range

    2,507在 GitHub 上查看↗

    Attack Range is a cybersecurity breach simulation framework designed to orchestrate the lifecycle of security labs and execute controlled attack scenarios. It functions as a security simulation infrastructure orchestrator, enabling the deployment of instrumented cloud and local environments to validate defensive capabilities and generate security telemetry. The platform distinguishes itself through configuration-driven automation and infrastructure-as-code orchestration, which allow for the repeatable provisioning of vulnerable environments. It manages the entire simulation lifecycle, from th

    This framework provides the infrastructure orchestration and automated attack execution necessary to simulate cyberattacks and validate security controls, making it a functional tool for testing security posture.

    PythonAttack Simulations
    在 GitHub 上查看↗2,507
  • aquasecurity/kube-hunteraquasecurity 的头像

    aquasecurity/kube-hunter

    5,064在 GitHub 上查看↗

    Kube-hunter is a security scanner and vulnerability hunter for Kubernetes clusters. It operates as a cloud-native penetration tool designed to identify security weaknesses, infrastructure misconfigurations, and exploitable gaps by simulating attacker techniques. The tool distinguishes itself through a dual-mode scanning engine that executes both remote external probes and internal network scans. It features identity-based impersonation, allowing it to use service account tokens and pod identities to simulate security access from specific cluster roles and determine the potential blast radius

    Kube-hunter is a specialized penetration testing tool that simulates attacker techniques within Kubernetes environments to validate security posture, fitting the category by actively testing infrastructure against known vulnerabilities and misconfigurations.

    PythonKubernetes Vulnerability HuntersPenetration Testing FrameworksAccount Impersonation
    在 GitHub 上查看↗5,064
  • rapid7/metasploit-frameworkrapid7 的头像

    rapid7/metasploit-framework

    38,415在 GitHub 上查看↗

    The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures. The platform distinguishes itself through a modular architecture that supports reflective payload injection, allowing for the execution of code directly in memory without writing to disk. It utilizes an asynchronous event loop to

    This is a comprehensive penetration testing framework that provides the core capabilities for executing security exploits and validating vulnerabilities, though it focuses more on manual and semi-automated testing than the continuous, automated simulation typical of a dedicated BAS platform.

    RubyPenetration Testing PlatformsExploit FrameworksExploitation Frameworks
    在 GitHub 上查看↗38,415
一览前 10 名对比
仓库Star 数语言许可证最后推送
mitre/caldera7KPythonApache-2.02026年6月17日
guardicore/monkey7KPythonGPL-3.02025年5月1日
redcanaryco/atomic-red-team12.1KCMIT2026年6月15日
datadog/stratus-red-team2.3KGoapache-2.02026年2月13日
endgameinc/rta1.1KPythonNOASSERTION2019年5月1日
nextronsystems/aptsimulator2.8KBatchfileMIT2025年9月23日
uber-common/metta1.1KPythonMIT2019年4月1日
funnywolf/viper5K——2026年1月18日
fsecurelabs/leonidas616PythonMIT2024年11月28日
bishopfox/sliver10.7KGogpl-3.02026年2月20日

Related searches

  • a professional certification for network security
  • an open source toolkit for penetration testing
  • a professional certification for API design
  • 网络安全技能实战平台
  • 对手模拟工具包
  • 自动化渗透测试框架
  • 钓鱼模拟平台
  • 用于练习的故意存在漏洞的云环境