Attack Simulation¶
Adversary emulation and BAS — generate the telemetry your detections are supposed to catch.
CALDERA¶
C2 / BAS
MITRE's automated adversary emulation platform. Full offline pip cache, so it never needs the internet.
Splunk Attack Range — Local¶
lab
Vagrant+Ansible lab builder — Windows DC/Server, Splunk Server, Kali, CALDERA/Phantom servers, on VirtualBox. Added via the local-tools pipeline.
Splunk Attack Range — Cloud¶
lab / aws
Same lab concept as the Local variant, provisioned as real AWS infrastructure via Terraform instead. Added via the local-tools pipeline.
Invoke-AtomicRedTeam¶
module
The PowerShell runner for Atomic Red Team. Auto-imported in every pwsh session.
powershell-yaml¶
module
YAML parser module Invoke-AtomicRedTeam depends on to read atomic test definitions.
Prelude Operator¶
n/a
Commercial BAS tool — free tier requires a Prelude account, so it isn't pre-bundled.
Leonidas¶
redcloudos NEW
Automated cloud attack simulation with matching detection use cases, deployed as an AWS Lambda pipeline.
msInvader¶
redcloudos NEW
Simulates post-compromise M365/Entra ID adversary techniques (mailbox rules, forwarding, delegation) via Graph/EWS/REST.
Vulnerable cloud/K8s/CI-CD labs (RedCloudOS "goat" set)¶
lab / billable NEW
11 intentionally-vulnerable environments cloned as editable source: AzureGoat, AWSGoat, GCPGoat, EntraGoat, CloudGoat, CloudFoxable, Kubernetes Goat, EKS Goat, TerraGoat, CI/CD Goat, GitHub Actions Goat.