GithubHelp home page GithubHelp logo

hartl3y94 / atomic-red-team Goto Github PK

View Code? Open in Web Editor NEW

This project forked from redcanaryco/atomic-red-team

0.0 0.0 0.0 55.68 MB

Small and highly portable detection tests based on MITRE's ATT&CK.

License: MIT License

C# 20.99% Batchfile 3.58% PowerShell 24.68% C++ 4.71% Shell 4.02% C 5.68% JavaScript 0.34% Ruby 8.56% HTML 0.96% XSLT 0.29% Python 0.40% Java 16.56% sed 0.19% VBA 0.32% VBScript 7.33% Makefile 0.07% Perl 1.02% ASP.NET 0.29%

atomic-red-team's Introduction

Atomic Red Team

CircleCI

Atomic Red Team allows every security team to test their controls by executing simple "atomic tests" that exercise the same techniques used by adversaries (all mapped to Mitre's ATT&CK).

Philosophy

Atomic Red Team is a library of simple tests that every security team can execute to test their controls. Tests are focused, have few dependencies, and are defined in a structured format that can be used by automation frameworks.

Three key beliefs made up the Atomic Red Team charter:

  • Teams need to be able to test everything from specific technical controls to outcomes. Our security teams do not want to operate with a “hopes and prayers” attitude toward detection. We need to know what our controls and program can detect, and what it cannot. We don’t have to detect every adversary, but we do believe in knowing our blind spots.

  • We should be able to run a test in less than five minutes. Most security tests and automation tools take a tremendous amount of time to install, configure, and execute. We coined the term "atomic tests" because we felt there was a simple way to decompose tests so most could be run in a few minutes.

    The best test is the one you actually run.

  • We need to keep learning how adversaries are operating. Most security teams don’t have the benefit of seeing a wide variety of adversary types and techniques crossing their desk every day. Even we at Red Canary only come across a fraction of the possible techniques being used, which makes the community working together essential to making us all better.

See: https://atomicredteam.io

Having trouble?

Join the community on Slack at https://atomicredteam.slack.com

Getting Started

Code of Conduct

In order to have a more open and welcoming community, Atomic Red Team adheres to a code of conduct.

License

See the LICENSE file.

atomic-red-team's People

Contributors

andras32 avatar apbeers avatar bnt1006 avatar brianebeyer avatar cherokeejb avatar clr2of8 avatar cnotin avatar cyberbuff avatar danbourke avatar dwhite9 avatar forensicitguy avatar hypnoticpattern avatar jeremyngalloway avatar jimmyastle avatar jmaas avatar jroroneequals1 avatar keithmccammon avatar mgraeber-rc avatar mhaggis avatar morgansec avatar mr-b0b avatar mroroneequals1 avatar p4t12ick avatar san-gwea avatar swelcher avatar timfrazier1 avatar tlor89 avatar tsora-pop avatar yeyintminthuhtut avatar zacbrown avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.