Stratus Red Team is Datadog's open-source command-line tool for emulating documented adversary techniques in cloud and identity environments. Its catalog includes AWS, Azure, Google Cloud, Microsoft Entra ID, and Kubernetes scenarios mapped to MITRE ATT&CK, with commands to prepare, detonate, inspect, revert, and clean up resources. It helps detection engineers produce known telemetry and validate alerts without building every simulation manually. Techniques perform real actions, may create costs or destructive effects, and must run only in authorized, isolated environments with reviewed permissions and cleanup plans.
Detailed assessment
Description
Stratus Red Team is Datadog's open-source command-line tool for emulating documented adversary techniques in cloud and identity environments. Its catalog includes AWS, Azure, Google Cloud, Microsoft Entra ID, and Kubernetes scenarios mapped to MITRE ATT&CK, with commands to prepare, detonate, inspect, revert, and clean up resources. It helps detection engineers produce known telemetry and validate alerts without building every simulation manually. Techniques perform real actions, may create costs or destructive effects, and must run only in authorized, isolated environments with reviewed permissions and cleanup plans. A detection team can choose a technique, inspect prerequisites and source code, provision the required state, execute it at a set time, and trace resulting control-plane or workload telemetry through collection, rule logic, alerting, and response. Reversion aids repeatability, but operators must verify every resource and side effect. The project is free and versioned; pin the binary and technique definition because cloud APIs, ATT&CK mappings, and behavior change. Use disposable accounts or subscriptions, least-privileged test credentials, budgets, approvals, and independent cleanup checks. A successful emulation validates only the tested path and conditions, not comprehensive detection coverage or safe behavior in production.
Strengths
- Packages cloud attack behaviors into repeatable, documented, and reversible emulation workflows.
- Maps scenarios to ATT&CK and exposes exact cloud actions useful for detection validation.
- Supports multiple major cloud platforms and programmatic execution.
Limitations
- Scenarios execute real API actions and can create cost, exposure, or disruption if poorly scoped.
- Technique coverage is selective and successful emulation does not validate the full response process.
Best for
- cloud detection validation
- purple-team exercises
- security control testing
- telemetry generation
Quality dimensions
- Authority 4.5/5
- Originality 5/5
- Maintenance 5/5
- Practical_value 4.7/5
- Transparency 5/5
Packages cloud attack behaviors into repeatable, documented, and reversible emulation workflows; principal limitation: Scenarios execute real API actions and can create cost, exposure, or disruption if poorly scoped.
Audience
- cloud detection engineers
- purple teams
- cloud security engineers
- incident responders
Formats
- open-source software
- command-line tool
- technique catalog
- documentation
- attack mappings
Keywords
- cloud-security
- adversary-emulation
- detection-validation
- purple-team
- mitre-attack
- security-testing
- cloud-telemetry
- identity-security
- kubernetes
Link validation: Reachable · checked 2026-09-07 · HTTP 200