The Splunk Attack Range is an open-source project maintained by the Splunk Threat Research Team. It builds instrumented cloud and local environments, simulates attacks, and forwards the data into a Splunk instance. This environment can then be used to develop and test the effectiveness of detections. Purpose 🛡 The Attack Range is a detection development platform, which solves three main challenges in detection engineering: The user is able to quickly build a small lab infrastructure as close as possible to a production environment. The Attack Range performs attack simulation using different engines such as Atomic Red Team or Caldera in order to generate real attack data. It integrates seamlessly into any Continuous Integration / Continuous Delivery (CI/CD) pipeline to automate the detection rule testing process. Docs The Attack Range Documentation can be found here. Installation 🏗 Using Docker Attack Range in AWS: docker pull splunk/attack_range docker run -it splunk/attack_range aws configure python attack_range.py configure To install directly on Linux, or MacOS follow these instructions. Architecture 🏯 The deployment of Attack Range consists of: Windows
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A collection of Python scripts for password spraying attacks against Lync/S4B & OWA, featuring Atomizer, Vaporizer, Aerosol, and Spindrift tools.
Generates randomized C2 profiles for Cobalt Strike to evade detection.
Advanced command and control tool for red teaming and adversary simulation with extensive features and evasion capabilities.
SharpEDRChecker scans system components to detect security products and tools.
C3 is a framework for creating custom C2 channels, integrating with existing offensive toolkits.
BeEF is a specialized penetration testing tool for exploiting web browser vulnerabilities to assess security.
Explore the top million websites, ranked by referring subnets, and gain insights into online influence and popularity.
A command that builds and executes command lines from standard input, allowing for the execution of commands with multiple arguments.
Interactive online malware sandbox for real-time analysis and threat intelligence
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.