Leonidas
A framework for executing cloud attacker tactics, techniques, and procedures (TTPs) that can generate APIs, Sigma detection rules, and documentation from YAML-based definitions.

Leonidas
A framework for executing cloud attacker tactics, techniques, and procedures (TTPs) that can generate APIs, Sigma detection rules, and documentation from YAML-based definitions.
Leonidas Description
Leonidas is a framework designed for executing attacker actions in cloud environments. The tool provides a YAML-based format for defining cloud attacker tactics, techniques, and procedures (TTPs) along with their associated detection properties. The framework can compile these definitions into multiple outputs including a web API that exposes each test case as an individual endpoint, Sigma rules for detection purposes, and documentation. The API deployment utilizes an AWS-native CI/CD pipeline and requires API key authentication for access. The tool includes a local generator component that can be installed to create Sigma rules and documentation from the defined test cases. This allows security teams to both simulate cloud-based attacks and develop corresponding detection capabilities.
Leonidas FAQ
Common questions about Leonidas including features, pricing, alternatives, and user reviews.
Leonidas is A framework for executing cloud attacker tactics, techniques, and procedures (TTPs) that can generate APIs, Sigma detection rules, and documentation from YAML-based definitions.. It is a Threat Management solution designed to help security teams with Red Team, MITRE Attack, AWS.
ALTERNATIVES
Human-led adversary emulation service testing detection & response capabilities
Validates detective security controls through attack simulations and testing
Cloud attack emulation platform for validating AWS security controls
Exposure validation platform combining BAS and attack path validation (CART)
POPULAR
TRENDING CATEGORIES
Stay Updated with Mandos Brief
Get strategic cybersecurity insights in your inbox