The Splunk Attack Range is an open-source project maintained by the Splunk Threat Research Team. It builds instrumented cloud and local environments, simulates attacks, and forwards the data into a Splunk instance. This environment can then be used to develop and test the effectiveness of detections. Purpose 🛡 The Attack Range is a detection development platform, which solves three main challenges in detection engineering: The user is able to quickly build a small lab infrastructure as close as possible to a production environment. The Attack Range performs attack simulation using different engines such as Atomic Red Team or Caldera in order to generate real attack data. It integrates seamlessly into any Continuous Integration / Continuous Delivery (CI/CD) pipeline to automate the detection rule testing process. Docs The Attack Range Documentation can be found here. Installation 🏗 Using Docker Attack Range in AWS: docker pull splunk/attack_range docker run -it splunk/attack_range aws configure python attack_range.py configure To install directly on Linux, or MacOS follow these instructions. Architecture 🏯 The deployment of Attack Range consists of: Windows
FEATURES
ALTERNATIVES
Repository of tools for testing iPhone messaging by Project Zero
A powerful tool for extracting passwords and performing various Windows security operations.
Open-source Java application for creating proxies for traffic analysis & modification.
A specification/framework for extending default C2 communication channels in Cobalt Strike
Ivy is a payload creation framework for executing arbitrary VBA source code directly in memory, utilizing programmatical access to load, decrypt, and execute shellcode.
A collaborative, multi-platform, red teaming framework for simulating attacks and testing defenses.
Python utility for testing the existence of domain names under different TLDs to find malicious subdomains.
A C#-based Command and Control Framework for remote access and control of compromised systems.
PINNED
InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
System Two Security
An AI-powered platform that automates threat hunting and analysis by processing cyber threat intelligence and generating customized hunt packages for SOC teams.
Aikido Security
Aikido is an all-in-one security platform that combines multiple security scanning and management functions for cloud-native applications and infrastructure.
Permiso
Permiso is an Identity Threat Detection and Response platform that provides comprehensive visibility and protection for identities across multiple cloud environments.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.