Leonidas
A framework for executing cloud attacker tactics, techniques, and procedures (TTPs) that can generate APIs, Sigma detection rules, and documentation from YAML-based definitions.

Leonidas
A framework for executing cloud attacker tactics, techniques, and procedures (TTPs) that can generate APIs, Sigma detection rules, and documentation from YAML-based definitions.
Go Beyond the Directory. Track the Entire Market.
Monitor competitor funding, hiring signals, product launches, and market movements across the whole industry.
Leonidas Description
Leonidas is a framework designed for executing attacker actions in cloud environments. The tool provides a YAML-based format for defining cloud attacker tactics, techniques, and procedures (TTPs) along with their associated detection properties. The framework can compile these definitions into multiple outputs including a web API that exposes each test case as an individual endpoint, Sigma rules for detection purposes, and documentation. The API deployment utilizes an AWS-native CI/CD pipeline and requires API key authentication for access. The tool includes a local generator component that can be installed to create Sigma rules and documentation from the defined test cases. This allows security teams to both simulate cloud-based attacks and develop corresponding detection capabilities.
Leonidas FAQ
Common questions about Leonidas including features, pricing, alternatives, and user reviews.
Leonidas is A framework for executing cloud attacker tactics, techniques, and procedures (TTPs) that can generate APIs, Sigma detection rules, and documentation from YAML-based definitions.. It is a Security Operations solution designed to help security teams with Red Team, MITRE Attack, Cloud Security.
FEATURED
Fix-first AppSec powered by agentic remediation, covering SCA, SAST & secrets.
Cybercrime intelligence tools for searching compromised credentials from infostealers
Password manager with end-to-end encryption and identity protection features
Fractional CISO services for B2B companies to build security programs
POPULAR
Real-time OSINT monitoring for leaked credentials, data, and infrastructure
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
AI security assurance platform for red-teaming, guardrails & compliance
TRENDING CATEGORIES
Stay Updated with Mandos Brief
Get strategic cybersecurity insights in your inbox