Skip to content

Latest commit

ย 

History

10 Commits

Folders and files

NameName
Last commit message
Last commit date
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

Awesome Attack Simulation Platform

๐Ÿ›ก๏ธ Awesome Attack Simulation Platform

Awesome Discord Stars Forks License GitHub followers

Curated List of SaaS Products & Open-Source GitHub Projects for Attack Simulation
Focused on Breach & Attack Simulation (BAS), Adversary Emulation, Continuous Security Validation & MITRE ATT&CK Mapping


๐Ÿ“Œ Overview & SEO Intro

Welcome to the Awesome Attack Simulation Platform directory โ€” the definitive, community-driven resource for cybersecurity professionals, purple teams, detection engineers, and red teamers.

This repository tracks top-tier SaaS enterprise platforms and open-source security tools designed for Breach and Attack Simulation (BAS), Adversary Emulation, Autonomous Penetration Testing, and Continuous Security Posture Validation. These platforms enable security operations centers (SOCs) to simulate real-world cyberattacks, test EDR/SIEM telemetry, validate defensive controls against MITRE ATT&CK techniques, and measure vulnerability remediation efficacy in production environments.


๐Ÿ“‘ Table of Contents


๐Ÿข SaaS & Hosted Enterprise Platforms

Market Size & Sector Overview: The global Breach and Attack Simulation (BAS) & Continuous Security Validation market is estimated at $550Mโ€“$1.0B in 2025/2026 (projected to reach $3.6Bโ€“$16B by 2033 at a CAGR of ~22โ€“40%). The sector is moderately fragmented, featuring specialized category leaders alongside emerging AI-native platforms evolving towards broader exposure management consolidation.

Platform Description Company Size (Valuation / Revenue) Starting Price Free Tier / Trial Limit
๐Ÿš€ Horizon3.ai Autonomous penetration testing platform (NodeZero) discovering exploitable vulnerabilities and validating attack paths with proof-of-exploit. >$2.0B Valuation ($250M Series E, 120% YoY ARR growth) ~$99/target for ad-hoc NodeZero pentest runs 30-day Free Trial (up to 1 free internal/external node run upon credential verification)
๐Ÿ›ก๏ธ Pentera Automated penetration testing platform simulating full attack chains from external and internal perspectives with actionable remediation. >$1.0B Valuation ($117M ARR, Series D) ~$35,000/year base annual subscription No free trial (1-on-1 personalized live environment demo available)
๐ŸŒ XM Cyber Hybrid cloud exposure management platform simulating attack paths to critical assets, identifying and prioritizing remediation. $700M Acquisition Value ($10Mโ€“$20M ARR) ~$24/unit/year (ยฃ18/unit/year) enterprise tier Custom-scoped 14-day Free Trial available via sales demo consultation
๐Ÿ”„ Cymulate Extended security posture management platform with BAS, automated red teaming, and attack surface validation across email, web, and endpoint vectors. $141M Total Funding (~$30M+ ARR) ~$7,000/year starting modular tier 14-day Free Trial with access to core validation modules
๐Ÿฅ Red Canary Managed continuous security validation platform with commercial orchestration built around Atomic Red Team. $130M Total Funding ($100M+ ARR) ~$120/endpoint/year starting managed subscription tier No free trial for hosted SaaS platform (free open-source YAML library available)
โš”๏ธ SafeBreach Continuous security validation platform with 20,000+ attack methods simulating known threat actor behaviors across the kill chain. $106M Total Funding (~$21M ARR) ~$25,000/year starting subscription tier (4 customizable tiers) No free trial (guided proof-of-concept / sandbox demo on request)
๐ŸŽฏ Picus Security Security validation platform combining BAS with threat intelligence, measuring detection and prevention effectiveness across security stack. $77M Total Funding (~$15Mโ€“$20M ARR) ~$10,000/year starting subscription 14-day Free Trial for Security Validation Platform
๐Ÿ“Š AttackIQ Breach and attack simulation platform built on MITRE ATT&CK, enabling continuous validation of security controls with automated attack scenarios. $73M Total Funding (~$15M ARR) ~$15,000/year starting Flex testing package tier AttackIQ Flex free tier (free access to basic ATT&CK testing packages & research)
๐Ÿ—ก๏ธ Scythe Adversary emulation platform with threat intelligence-driven attack scenarios, purple team collaboration, and detection validation. $15M Funding ($5Mโ€“$10M ARR) ~$15,000/year practitioner starting license No free trial (guided interactive sandbox demo on request)
๐ŸŽฎ ThreatGen Cyber range and attack simulation platform with gamified red team/blue team exercises for training and validation. Early-Stage / Bootstrapped (~$1Mโ€“$3M ARR) $75/year for Individual Pro; $1,500/year for Business tier No free trial (free interactive video demo and sample scenarios on request)

๐Ÿ”“ Open-Source GitHub Projects

Below is a curated collection of active open-source projects for self-hosted Breach and Attack Simulation, adversary emulation, command-and-control (C2), and detection engineering labs. Sorted by GitHub Stars_Count (descending):

  1. โš›๏ธ Atomic Red Team Atomic Red Team Stars
    The industry-standard library of simple, testable YAML files mapped directly to MITRE ATT&CK techniques. Designed for rapid execution and blue team detection validation across Windows, Linux, and macOS environments.

  2. ๐Ÿ—ก๏ธ Sliver C2 Framework Sliver Stars
    Cross-platform, open-source adversary emulation and Command & Control (C2) framework developed by Bishop Fox. Features mTLS/WireGuard/HTTP/DNS C2 channels, dynamic code injection, and multi-operator red team campaign orchestration.

  3. ๐ŸŒ‹ MITRE Caldera Caldera Stars
    The leading automated adversary emulation system created by MITRE. Built on lightweight cross-platform agents (Sandcat) paired with a central C2 orchestrator that executes ATT&CK-mapped abilities and adversary playbooks for red/purple teaming.

  4. ๐Ÿงช Splunk Attack Range Attack Range Stars
    Automation framework using Terraform and Ansible to deploy instrumented cloud environments (Splunk, Active Directory, Kali, Zeek). Integrates with Atomic Red Team to generate realistic attack telemetry for detection development.

  5. โšก OpenBAS OpenBAS Stars
    ISO 22398-compliant Breach and Attack Simulation platform created by Filigran. Simulates technical attacks and organizational crisis scenarios (executive inquiries, media leaks) with AI scenario generation and OpenCTI threat intelligence integration.

  6. ๐Ÿ’ Infection Monkey Infection Monkey Stars
    Open-source, agent-based adversary emulation tool by Akamai/Guardicore. Features a central web control server ("Monkey Island") and self-propagating agents ("Monkeys") to test lateral movement and Zero Trust network boundaries.

  7. ๐Ÿค– Red Team Automation (RTA) RTA Stars
    Framework of python scripts designed by Endgame to execute malicious behaviors mapped to MITRE ATT&CK tactics, helping detection engineers verify EDR alerting rules.

  8. โ˜๏ธ Stratus Red Team Stratus Red Team Stars
    Known as "Atomic Red Team for the Cloud", this tool by Datadog provides granular, actionable attack techniques specifically targeting AWS, Azure, GCP, and Kubernetes environments.

  9. ๐ŸŸฃ PurpleSharp PurpleSharp Stars
    C#-based adversary simulation tool for Windows Active Directory environments. Automates complex attack paths remotely over SMB/RPC to measure Active Directory defense metrics.

  10. ๐Ÿ“ˆ VECTR VECTR Stars
    Open-source purple team tracking, reporting, and posture assessment tool developed by Security Risk Advisors for measuring detection coverage across purple team exercises.

  11. ๐ŸŒŠ Attack Flow Attack Flow Stars
    Language and visualization schema created by the MITRE Engenuity Center for Threat-Informed Defense to describe and map complex, multi-stage attack chains and threat actor behaviors.

  12. ๐Ÿ’ฅ DumpsterFire DumpsterFire Stars
    Modular event-driven adversary simulation rule-engine for building custom attack scenarios and delay-based cyber incident simulations (preserved for historical context).


โš™๏ธ Attack Simulation Frameworks & Architectures

Building a enterprise-grade, vendor-independent continuous attack simulation program requires combining complementary open-source components:

  • Core Adversary Emulation Engine: Deploy MITRE Caldera for central orchestration, automated agent execution, and ATT&CK playbook scheduling.
  • Granular Test Case Library: Integrate Atomic Red Team as raw atomic test primitives to validate specific SIEM/EDR rule triggers.
  • Cloud & Container Validation: Use Stratus Red Team for AWS, Azure, GCP, and Kubernetes attack techniques.
  • Incident Response & Crisis Simulation: Utilize OpenBAS paired with OpenCTI to model non-technical communication flows alongside technical attack vectors.
  • Telemetry & Detection Lab Infrastructure: Spin up Splunk Attack Range to analyze log ingestion and detection fidelity under real attack scenarios.

๐Ÿค How to Contribute

Contributions are warmly welcomed! Help keep this cybersecurity repository complete and up to date:

  1. Fork the repository.
  2. Add or edit entries in README.md maintaining the existing tabular/list format.
  3. Ensure added projects include: Name, Link, GitHub Stars_Badge (for open source), 1โ€“2 sentence factual description, and category.
  4. Submit a Pull Request with a clear explanation of your additions.

Please review our curated resources at Awesome-Awesome-Awesome.


๐Ÿ“ˆ Star History

Star History Chart


๐Ÿ’– Support & Sponsorship

Thank you for exploring the Awesome Attack Simulation Platform ecosystem! ๐Ÿš€ If this project helps your security team, purple teaming exercises, or research, please consider showing support:

  • โญ Star this repository to increase visibility for security researchers.
  • ๐Ÿ”€ Fork it to keep your own reference copy and submit contributions.
  • ๐Ÿ“ข Share this list with colleagues, red/blue teams, and security communities.
  • โ˜• Sponsor / Buy me a coffee: Support ongoing open-source curation via the GitHub Sponsor Dashboard.

โš ๏ธ Disclaimer

  • This list is community-curated for educational, defensive security research, and security validation purposes.
  • All attack simulation tools must be operated exclusively within authorized environments with proper legal authorization and explicit written scope.
  • Self-hosted open-source software requires infrastructure security hardening and ongoing maintenance.

Star History

Star History Chart

About

Top Attack Simulation Platform (Opensource) ๐ŸŒŸ Star if you like it! ๐ŸŒŸ

Topics

Resources

Stars

5 stars

Watchers

0 watching

Forks

Releases

Sponsor this project

Packages

Contributors