caldera_pathfinder
Starkiller
caldera_pathfinder | Starkiller | |
---|---|---|
3 | 2 | |
113 | 1,264 | |
0.0% | 2.5% | |
0.0 | 8.1 | |
over 1 year ago | 2 months ago | |
Python | Vue | |
Apache License 2.0 | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
caldera_pathfinder
- Attack simulation tool based on CVE
-
Attack Chain/Exploitation Path Diagram Generation Tools?
There's also a plugin for Caldera (https://github.com/mitre/caldera) called Pathfinder (https://github.com/center-for-threat-informed-defense/caldera_pathfinder and https://www.youtube.com/watch?v=gQRWkHFRG-s) that can help.
-
Guidance on certs in Cybersecurity Field
Pathfinder: https://github.com/center-for-threat-informed-defense/caldera_pathfinder
Starkiller
-
Guidance on certs in Cybersecurity Field
StarKiller: https://github.com/BC-SECURITY/Starkiller
- Releases · BC-SECURITY/Starkiller
What are some alternatives?
Covenant - Covenant is a collaborative .NET C2 framework for red teamers.
caldera - Automated Adversary Emulation Platform
Empire - Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.
attack-flow - Attack Flow helps executives, SOC managers, and defenders easily understand how attackers compose ATT&CK techniques into attacks by developing a representation of attack flows, modeling attack flows for a small corpus of incidents, and creating visualization tools to display attack flows.
Awesome-Red-Teaming - List of Awesome Red Teaming Resources
tram - TRAM is an open-source platform designed to advance research into automating the mapping of cyber threat intelligence reports to MITRE ATT&CK®.
Empire - Empire is a PowerShell and Python post-exploitation agent.
Automata - Automatic detection engineering technical state compliance
empire - A PaaS built on top of Amazon EC2 Container Service (ECS)
bzar - A set of Zeek scripts to detect ATT&CK techniques.
merlin - Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.