Splunk Attack Range Logo

Splunk Attack Range

0
Free
Visit Website

The Splunk Attack Range is an open-source project maintained by the Splunk Threat Research Team. It builds instrumented cloud and local environments, simulates attacks, and forwards the data into a Splunk instance. This environment can then be used to develop and test the effectiveness of detections. Purpose 🛡 The Attack Range is a detection development platform, which solves three main challenges in detection engineering: The user is able to quickly build a small lab infrastructure as close as possible to a production environment. The Attack Range performs attack simulation using different engines such as Atomic Red Team or Caldera in order to generate real attack data. It integrates seamlessly into any Continuous Integration / Continuous Delivery (CI/CD) pipeline to automate the detection rule testing process. Docs The Attack Range Documentation can be found here. Installation 🏗 Using Docker Attack Range in AWS: docker pull splunk/attack_range docker run -it splunk/attack_range aws configure python attack_range.py configure To install directly on Linux, or MacOS follow these instructions. Architecture 🏯 The deployment of Attack Range consists of: Windows

FEATURES

ALTERNATIVES

Darkarmour is a Windows AV evasion tool that helps bypass antivirus software, allowing for the creation of undetectable malware.

A lightweight, first-stage C2 implant written in Nim for remote access and control.

Using Apache mod_rewrite as a redirector to filter C2 traffic for Cobalt Strike servers.

A tool for interacting with the MSBuild API, enabling malicious activities and evading detection.

Participation in the Red Team for Pacific Rim CCDC 2017 with insights on infrastructure design and competition tips.

CrackMapExec (CME) - A tool for querying internal database for host and credential information in cybersecurity.

A post-exploitation framework for attacking running AWS infrastructure

A project for demonstrating AWS attack techniques with a focus on ethical hacking practices.

PINNED