Curated List of SaaS Products & Open-Source GitHub Projects for Attack Simulation
Focused on Breach & Attack Simulation (BAS), Adversary Emulation, Continuous Security Validation & MITRE ATT&CK Mapping
Welcome to the Awesome Attack Simulation Platform directory โ the definitive, community-driven resource for cybersecurity professionals, purple teams, detection engineers, and red teamers.
This repository tracks top-tier SaaS enterprise platforms and open-source security tools designed for Breach and Attack Simulation (BAS), Adversary Emulation, Autonomous Penetration Testing, and Continuous Security Posture Validation. These platforms enable security operations centers (SOCs) to simulate real-world cyberattacks, test EDR/SIEM telemetry, validate defensive controls against MITRE ATT&CK techniques, and measure vulnerability remediation efficacy in production environments.
- ๐ข SaaS & Hosted Enterprise Platforms
- ๐ Open-Source GitHub Projects
- โ๏ธ Attack Simulation Frameworks & Architectures
- ๐ค How to Contribute
- ๐ Star History
- ๐ Support & Sponsorship
โ ๏ธ Disclaimer
Market Size & Sector Overview: The global Breach and Attack Simulation (BAS) & Continuous Security Validation market is estimated at $550Mโ$1.0B in 2025/2026 (projected to reach $3.6Bโ$16B by 2033 at a CAGR of ~22โ40%). The sector is moderately fragmented, featuring specialized category leaders alongside emerging AI-native platforms evolving towards broader exposure management consolidation.
| Platform | Description | Company Size (Valuation / Revenue) | Starting Price | Free Tier / Trial Limit |
|---|---|---|---|---|
| ๐ Horizon3.ai | Autonomous penetration testing platform (NodeZero) discovering exploitable vulnerabilities and validating attack paths with proof-of-exploit. | >$2.0B Valuation ($250M Series E, 120% YoY ARR growth) | ~$99/target for ad-hoc NodeZero pentest runs | 30-day Free Trial (up to 1 free internal/external node run upon credential verification) |
| ๐ก๏ธ Pentera | Automated penetration testing platform simulating full attack chains from external and internal perspectives with actionable remediation. | >$1.0B Valuation ($117M ARR, Series D) | ~$35,000/year base annual subscription | No free trial (1-on-1 personalized live environment demo available) |
| ๐ XM Cyber | Hybrid cloud exposure management platform simulating attack paths to critical assets, identifying and prioritizing remediation. | $700M Acquisition Value ($10Mโ$20M ARR) | ~$24/unit/year (ยฃ18/unit/year) enterprise tier | Custom-scoped 14-day Free Trial available via sales demo consultation |
| ๐ Cymulate | Extended security posture management platform with BAS, automated red teaming, and attack surface validation across email, web, and endpoint vectors. | $141M Total Funding (~$30M+ ARR) | ~$7,000/year starting modular tier | 14-day Free Trial with access to core validation modules |
| ๐ฅ Red Canary | Managed continuous security validation platform with commercial orchestration built around Atomic Red Team. | $130M Total Funding ($100M+ ARR) | ~$120/endpoint/year starting managed subscription tier | No free trial for hosted SaaS platform (free open-source YAML library available) |
| โ๏ธ SafeBreach | Continuous security validation platform with 20,000+ attack methods simulating known threat actor behaviors across the kill chain. | $106M Total Funding (~$21M ARR) | ~$25,000/year starting subscription tier (4 customizable tiers) | No free trial (guided proof-of-concept / sandbox demo on request) |
| ๐ฏ Picus Security | Security validation platform combining BAS with threat intelligence, measuring detection and prevention effectiveness across security stack. | $77M Total Funding (~$15Mโ$20M ARR) | ~$10,000/year starting subscription | 14-day Free Trial for Security Validation Platform |
| ๐ AttackIQ | Breach and attack simulation platform built on MITRE ATT&CK, enabling continuous validation of security controls with automated attack scenarios. | $73M Total Funding (~$15M ARR) | ~$15,000/year starting Flex testing package tier | AttackIQ Flex free tier (free access to basic ATT&CK testing packages & research) |
| ๐ก๏ธ Scythe | Adversary emulation platform with threat intelligence-driven attack scenarios, purple team collaboration, and detection validation. | ~$15,000/year practitioner starting license | No free trial (guided interactive sandbox demo on request) | |
| ๐ฎ ThreatGen | Cyber range and attack simulation platform with gamified red team/blue team exercises for training and validation. | Early-Stage / Bootstrapped (~$1Mโ$3M ARR) | $75/year for Individual Pro; $1,500/year for Business tier | No free trial (free interactive video demo and sample scenarios on request) |
Below is a curated collection of active open-source projects for self-hosted Breach and Attack Simulation, adversary emulation, command-and-control (C2), and detection engineering labs. Sorted by GitHub Stars_Count (descending):
-
โ๏ธ Atomic Red Team
The industry-standard library of simple, testable YAML files mapped directly to MITRE ATT&CK techniques. Designed for rapid execution and blue team detection validation across Windows, Linux, and macOS environments. -
๐ก๏ธ Sliver C2 Framework
Cross-platform, open-source adversary emulation and Command & Control (C2) framework developed by Bishop Fox. Features mTLS/WireGuard/HTTP/DNS C2 channels, dynamic code injection, and multi-operator red team campaign orchestration. -
๐ MITRE Caldera
The leading automated adversary emulation system created by MITRE. Built on lightweight cross-platform agents (Sandcat) paired with a central C2 orchestrator that executes ATT&CK-mapped abilities and adversary playbooks for red/purple teaming. -
๐งช Splunk Attack Range
Automation framework using Terraform and Ansible to deploy instrumented cloud environments (Splunk, Active Directory, Kali, Zeek). Integrates with Atomic Red Team to generate realistic attack telemetry for detection development. -
โก OpenBAS
ISO 22398-compliant Breach and Attack Simulation platform created by Filigran. Simulates technical attacks and organizational crisis scenarios (executive inquiries, media leaks) with AI scenario generation and OpenCTI threat intelligence integration. -
๐ Infection Monkey
Open-source, agent-based adversary emulation tool by Akamai/Guardicore. Features a central web control server ("Monkey Island") and self-propagating agents ("Monkeys") to test lateral movement and Zero Trust network boundaries. -
๐ค Red Team Automation (RTA)
Framework of python scripts designed by Endgame to execute malicious behaviors mapped to MITRE ATT&CK tactics, helping detection engineers verify EDR alerting rules. -
โ๏ธ Stratus Red Team
Known as "Atomic Red Team for the Cloud", this tool by Datadog provides granular, actionable attack techniques specifically targeting AWS, Azure, GCP, and Kubernetes environments. -
๐ฃ PurpleSharp
C#-based adversary simulation tool for Windows Active Directory environments. Automates complex attack paths remotely over SMB/RPC to measure Active Directory defense metrics. -
๐ VECTR
Open-source purple team tracking, reporting, and posture assessment tool developed by Security Risk Advisors for measuring detection coverage across purple team exercises. -
๐ Attack Flow
Language and visualization schema created by the MITRE Engenuity Center for Threat-Informed Defense to describe and map complex, multi-stage attack chains and threat actor behaviors. -
๐ฅ DumpsterFire
Modular event-driven adversary simulation rule-engine for building custom attack scenarios and delay-based cyber incident simulations (preserved for historical context).
Building a enterprise-grade, vendor-independent continuous attack simulation program requires combining complementary open-source components:
- Core Adversary Emulation Engine: Deploy MITRE Caldera for central orchestration, automated agent execution, and ATT&CK playbook scheduling.
- Granular Test Case Library: Integrate Atomic Red Team as raw atomic test primitives to validate specific SIEM/EDR rule triggers.
- Cloud & Container Validation: Use Stratus Red Team for AWS, Azure, GCP, and Kubernetes attack techniques.
- Incident Response & Crisis Simulation: Utilize OpenBAS paired with OpenCTI to model non-technical communication flows alongside technical attack vectors.
- Telemetry & Detection Lab Infrastructure: Spin up Splunk Attack Range to analyze log ingestion and detection fidelity under real attack scenarios.
Contributions are warmly welcomed! Help keep this cybersecurity repository complete and up to date:
- Fork the repository.
- Add or edit entries in
README.mdmaintaining the existing tabular/list format. - Ensure added projects include: Name, Link, GitHub Stars_Badge (for open source), 1โ2 sentence factual description, and category.
- Submit a Pull Request with a clear explanation of your additions.
Please review our curated resources at Awesome-Awesome-Awesome.
Thank you for exploring the Awesome Attack Simulation Platform ecosystem! ๐ If this project helps your security team, purple teaming exercises, or research, please consider showing support:
- โญ Star this repository to increase visibility for security researchers.
- ๐ Fork it to keep your own reference copy and submit contributions.
- ๐ข Share this list with colleagues, red/blue teams, and security communities.
- โ Sponsor / Buy me a coffee: Support ongoing open-source curation via the GitHub Sponsor Dashboard.
- This list is community-curated for educational, defensive security research, and security validation purposes.
- All attack simulation tools must be operated exclusively within authorized environments with proper legal authorization and explicit written scope.
- Self-hosted open-source software requires infrastructure security hardening and ongoing maintenance.