Red Team Automation (RTA) Logo

Red Team Automation (RTA)

A Python-based framework that generates evidence of MITRE ATT&CK tactics to help blue teams test their detection capabilities against simulated malicious activities.

1,085
Security Operations
Free
Visit website
0

Red Team Automation (RTA) Description

Red Team Automation (RTA) is a framework of Python scripts designed to help blue teams test their detection capabilities against malicious tradecraft modeled after MITRE ATT&CK tactics. The framework consists of Python scripts that generate evidence of over 50 different ATT&CK tactics, along with a compiled binary application that performs activities such as file timestopping, process injections, and beacon simulation. RTA attempts to perform actual malicious activities where possible, while emulating all or parts of activities in other cases. For lateral movement testing, the framework defaults to targeting localhost but supports parameters for multi-host testing scenarios. The tool includes capabilities for renaming executables such as cmd.exe or python.exe to simulate scenarios where Windows binaries appear to be performing non-standard activities. Installation requires Python 2.7 and involves downloading the repository from GitHub, extracting contents to a designated folder, and optionally downloading additional files to the bin subdirectory for enhanced functionality.

FEATURED

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Stay Updated with Mandos Brief

Get the latest cybersecurity updates in your inbox

POPULAR

RoboShadow Logo

A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.

10
TestSavantAI Logo

Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.

5
Cybersec Feeds Logo

A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.

5
Fabric Platform by BlackStork Logo

Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.

5
Mandos Brief Newsletter Logo

A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

5
View Popular Tools →