Skip to content

Attack Simulation

Adversary emulation and BAS — generate the telemetry your detections are supposed to catch.

CALDERA

C2 / BAS

MITRE's automated adversary emulation platform. Full offline pip cache, so it never needs the internet.

Splunk Attack Range — Local

lab

Vagrant+Ansible lab builder — Windows DC/Server, Splunk Server, Kali, CALDERA/Phantom servers, on VirtualBox. Added via the local-tools pipeline.

Splunk Attack Range — Cloud

lab / aws

Same lab concept as the Local variant, provisioned as real AWS infrastructure via Terraform instead. Added via the local-tools pipeline.

Atomic Red Team

tests

RedCanary's library of small, atomic ATT&CK technique tests.

Invoke-AtomicRedTeam

module

The PowerShell runner for Atomic Red Team. Auto-imported in every pwsh session.

powershell-yaml

module

YAML parser module Invoke-AtomicRedTeam depends on to read atomic test definitions.

PurpleSharp

.net src

C#/PowerShell adversary simulation, normally compiled fresh per engagement.

Infection Monkey

manual

Guardicore's automated breach-and-attack-simulation platform.

Stratus Red Team

binary

DataDog's granular attack-technique emulation for AWS/Azure/GCP/K8s.

Metasploit Framework

system

Installed system-wide via Rapid7's own installer, fully baked in.

Prelude Operator

n/a

Commercial BAS tool — free tier requires a Prelude account, so it isn't pre-bundled.

Leonidas

redcloudos NEW

Automated cloud attack simulation with matching detection use cases, deployed as an AWS Lambda pipeline.

msInvader

redcloudos NEW

Simulates post-compromise M365/Entra ID adversary techniques (mailbox rules, forwarding, delegation) via Graph/EWS/REST.

Vulnerable cloud/K8s/CI-CD labs (RedCloudOS "goat" set)

lab / billable NEW

11 intentionally-vulnerable environments cloned as editable source: AzureGoat, AWSGoat, GCPGoat, EntraGoat, CloudGoat, CloudFoxable, Kubernetes Goat, EKS Goat, TerraGoat, CI/CD Goat, GitHub Actions Goat.