atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.

  • 所有者: redcanaryco/atomic-red-team
  • 平台:
  • 许可证: MIT License
  • 分类:
  • 主题:
  • 喜欢:
    0
      比较:

Github星跟踪图

Atomic Red Team

CircleCI

Atomic Red Team allows every security team to test their controls by executing simple
"atomic tests" that exercise the same techniques used by adversaries (all mapped to
Mitre's ATT&CK).

Philosophy

Atomic Red Team is a library of simple tests that every security team can execute to test their controls. Tests are
focused, have few dependencies, and are defined in a structured format that be used by automation frameworks.

Three key beliefs made up the Atomic Red Team charter:

  • Teams need to be able to test everything from specific technical controls to outcomes.
    Our security teams do not want to operate with a “hopes and prayers” attitude toward detection. We need to know
    what our controls and program can detect, and what it cannot. We don’t have to detect every adversary, but we
    do believe in knowing our blind spots.

  • We should be able to run a test in less than five minutes.
    Most security tests and automation tools take a tremendous amount of time to install, configure, and execute.
    We coined the term "atomic tests" because we felt there was a simple way to decompose tests so most could be
    run in a few minutes.

    The best test is the one you actually run.

  • We need to keep learning how adversaries are operating.
    Most security teams don’t have the benefit of seeing a wide variety of adversary types and techniques crossing
    their desk every day. Even we at Red Canary only come across a fraction of the possible techniques being used,
    which makes the community working together essential to making us all better.

See: https://atomicredteam.io

Having trouble?

Join the community on Slack at https://atomicredteam.slack.com

Getting Started

Code of Conduct

In order to have a more open and welcoming community, Atomic Red Team adheres to a
code of conduct.

License

See the LICENSE file.

主要指标

概览
名称与所有者redcanaryco/atomic-red-team
主编程语言C
编程语言C# (语言数: 24)
平台
许可证MIT License
所有者活动
创建于2017-10-11 17:23:32
推送于2025-09-15 14:10:49
最后一次提交2025-09-08 13:40:04
发布数0
用户参与
星数11k
关注者数354
派生数3k
提交数6.5k
已启用问题?
问题数291
打开的问题数2
拉请求数2526
打开的拉请求数9
关闭的拉请求数350
项目设置
已启用Wiki?
已存档?
是复刻?
已锁定?
是镜像?
是私有?