Splunk Attack Range Logo

Splunk Attack Range

0
Free
Updated 11 March 2025
Visit Website

The Splunk Attack Range is an open-source project maintained by the Splunk Threat Research Team. It builds instrumented cloud and local environments, simulates attacks, and forwards the data into a Splunk instance. This environment can then be used to develop and test the effectiveness of detections. Purpose 🛡 The Attack Range is a detection development platform, which solves three main challenges in detection engineering: The user is able to quickly build a small lab infrastructure as close as possible to a production environment. The Attack Range performs attack simulation using different engines such as Atomic Red Team or Caldera in order to generate real attack data. It integrates seamlessly into any Continuous Integration / Continuous Delivery (CI/CD) pipeline to automate the detection rule testing process. Docs The Attack Range Documentation can be found here. Installation 🏗 Using Docker Attack Range in AWS: docker pull splunk/attack_range docker run -it splunk/attack_range aws configure python attack_range.py configure To install directly on Linux, or MacOS follow these instructions. Architecture 🏯 The deployment of Attack Range consists of: Windows

FEATURES

SIMILAR TOOLS

A Linux-based environment for penetration testing and vulnerability exploitation

SharpEDRChecker scans system components to detect security products and tools.

A Python utility to takeover domains vulnerable to AWS NS Takeover

A C2 profile generator for Cobalt Strike designed to enhance evasion.

A suite of tools for Wi-Fi network security assessment and penetration testing.

Utilizes dirtyc0w kernel exploit for privilege escalation in a Docker container.

Local pentest lab using docker compose to spin up victim and attacker services.

A specification/framework for extending default C2 communication channels in Cobalt Strike

A C2 front flow control tool designed to evade detection by Blue Teams, AVs, and EDRs.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Operated by:

Mandos Cyber • KVK: 97994448

Netherlands • contact@mandos.io

VAT: NL005301434B12

Copyright © 2025 - All rights reserved