
A framework for executing cloud attacker tactics, techniques, and procedures (TTPs) that can generate APIs, Sigma detection rules, and documentation from YAML-based definitions.

A framework for executing cloud attacker tactics, techniques, and procedures (TTPs) that can generate APIs, Sigma detection rules, and documentation from YAML-based definitions.
Leonidas is a framework designed for executing attacker actions in cloud environments. The tool provides a YAML-based format for defining cloud attacker tactics, techniques, and procedures (TTPs) along with their associated detection properties. The framework can compile these definitions into multiple outputs including a web API that exposes each test case as an individual endpoint, Sigma rules for detection purposes, and documentation. The API deployment utilizes an AWS-native CI/CD pipeline and requires API key authentication for access. The tool includes a local generator component that can be installed to create Sigma rules and documentation from the defined test cases. This allows security teams to both simulate cloud-based attacks and develop corresponding detection capabilities.
Common questions about Leonidas including features, pricing, alternatives, and user reviews.
Leonidas is A framework for executing cloud attacker tactics, techniques, and procedures (TTPs) that can generate APIs, Sigma detection rules, and documentation from YAML-based definitions. It is a Threat Management solution designed to help security teams with Red Team, MITRE Attack, AWS.
Human-led adversary emulation service testing detection & response capabilities
Validates detective security controls through attack simulations and testing
Cloud attack emulation platform for validating AWS security controls
Exposure validation platform combining BAS and attack path validation (CART)