MAD ATT&CK Defender: ATT&CK Adversary Emulation Repository
☆131Apr 24, 2023Updated 3 years ago
Alternatives and similar repositories for AdversaryEmulation
Users that are interested in AdversaryEmulation are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.☆2,156May 28, 2025Updated last year
- A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework☆357Nov 3, 2020Updated 5 years ago
- ☆11Jun 5, 2022Updated 4 years ago
- Community content for LogRhythm Axon. Includes Dashboards, searches, analytics rules, processing policies and more.☆10Jul 26, 2024Updated 2 years ago
- Creates an ATT&CK Navigator map of an Adversary Emulation Plan☆17Sep 4, 2021Updated 4 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Actionable analytics designed to combat threats☆1,010May 25, 2022Updated 4 years ago
- Cloud Detection & Response GOAT is a scenario-driven, intentionally vulnerable framework designed to help defenders validate detection pi…☆21Aug 18, 2026Updated last week
- An automated Adversary Emulation lab with terraform and MCP server. Build Caldera techniques and operations assisted with LLMs. Built f…☆220Nov 23, 2025Updated 9 months ago
- ☆23Jun 1, 2022Updated 4 years ago
- Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detection…☆870Jan 20, 2022Updated 4 years ago
- Purple Team Resources for Enterprise Purple Teaming: An Exploratory Qualitative Study by Xena Olsen.☆678Jun 14, 2023Updated 3 years ago
- TRAM is an open-source platform designed to advance research into automating the mapping of cyber threat intelligence reports to MITRE AT…☆578May 6, 2025Updated last year
- Granular, Actionable Adversary Emulation for the Cloud☆2,379Updated this week
- A CALDERA plugin☆83Apr 30, 2026Updated 4 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).☆825Aug 14, 2026Updated 2 weeks ago
- Attack Flow helps executives, SOC managers, and defenders easily understand how attackers compose ATT&CK techniques into attacks by devel…☆769Aug 13, 2026Updated 2 weeks ago
- A Canary which fires when uninstalled☆34Mar 16, 2021Updated 5 years ago
- Cheat sheets for threat hunting, detection and other stuff.☆35Oct 7, 2022Updated 3 years ago
- Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.☆215Jul 21, 2022Updated 4 years ago
- Detection Ideas & Rules repository.☆179Sep 10, 2021Updated 4 years ago
- ☆50Aug 10, 2026Updated 2 weeks ago
- Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders☆1,078Oct 5, 2023Updated 2 years ago
- ☆12Mar 24, 2018Updated 8 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Automated Adversary Emulation Platform☆7,222Updated this week
- impersonate trustedinstaller by fiddling with tokens☆13Aug 30, 2021Updated 5 years ago
- This content is analysis and research of the data sources currently listed in ATT&CK.☆412Sep 13, 2023Updated 2 years ago
- 2021 SANS DFIR Summit: Greppin' Logs☆20Oct 30, 2025Updated 10 months ago
- ☆24Jan 2, 2023Updated 3 years ago
- Interface LLMs from within MISP to extract TTPs and threat intel from CTI reports☆18Nov 13, 2023Updated 2 years ago
- A collection of scripts used to support an OffSecOps pipeline.☆15Jan 31, 2021Updated 5 years ago
- Simulates a compromise in a cloud and container environment☆35Dec 18, 2024Updated last year
- Threat Modeling with ATT&CK defines how to integreate MITRE ATT&CK® into your organization’s existing threat modeling methodology.☆15May 28, 2025Updated last year
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- powershell script i wrote that can suspend an arbitrary process (with limits)☆22Mar 26, 2023Updated 3 years ago
- Domain Response is a tool that is designed to help you automate the investigation for a domain. This tool is specificly designed to autom…☆53Jan 1, 2026Updated 7 months ago
- Active C&C Detector☆156Oct 5, 2023Updated 2 years ago
- Reference sheet for Threat Hunting Professional Course☆26Mar 10, 2019Updated 7 years ago
- A set of Zeek scripts to detect ATT&CK techniques.☆622Jun 26, 2024Updated 2 years ago
- Collects a listing of MITRE ATT&CK Techniques, then discovers Splunk ESCU detections for each technique☆70Mar 17, 2024Updated 2 years ago
- Purple Team Exercise Framework☆818Apr 9, 2026Updated 4 months ago