Atomic Red Team is an open-source library of small, portable tests mapped to MITRE ATT&CK techniques. Defenders use the tests to generate controlled endpoint, cloud, container, or command-line activity, confirm telemetry, exercise analytics, and document detection gaps. Each atomic defines execution metadata and commands and may also define inputs, prerequisites, and cleanup steps. Coverage and safety vary by test; an ATT&CK mapping does not prove realistic adversary behavior, and every atomic requires review before execution because some actions can alter systems or trigger security controls.
Detailed assessment
Description
Atomic Red Team, maintained by Red Canary and community contributors, is an open-source catalog of small security tests mapped to MITRE ATT&CK techniques. Individual atomics describe supported platforms, inputs, prerequisites, execution commands, and, where available, cleanup actions. Detection engineers and purple teams commonly select a behavior, run the corresponding test on an authorized lab or representative endpoint, confirm that expected telemetry reaches the SIEM or EDR, evaluate an analytic, and record gaps for remediation. The library pairs naturally with ATT&CK for behavioral context, Sigma or vendor rule repositories for candidate detections, and orchestration platforms such as Caldera when a team later needs chained scenarios. Its strength is repeatability at the level of one technique or observable action, not realism across a complete intrusion. Mappings, commands, prerequisites, and cleanup quality vary between contributions, and successful execution does not prove that a control detected or prevented the behavior. Every test is dual-use: review the source, scope affected systems, obtain authorization, protect credentials, monitor side effects, and restore the environment before treating results as evidence.
Strengths
- Portable tests with explicit ATT&CK mappings and repeatable inputs
- Useful for validating telemetry and individual analytic assumptions
- Large community-maintained library with transparent test definitions
Limitations
- Atomic actions do not reproduce full intrusion context or chained tradecraft
- Tests are dual-use and may disrupt systems without review, isolation, and authorization
Best for
- detection validation
- purple-team exercises
- telemetry verification
- analyst training labs
Quality dimensions
- Authority 4.5/5
- Originality 5/5
- Maintenance 5/5
- Practical_value 4.6/5
- Transparency 5/5
Portable tests with explicit ATT&CK mappings and repeatable inputs; principal limitation: Atomic actions do not reproduce full intrusion context or chained tradecraft.
Audience
- detection engineers
- purple teams
- SOC analysts
- security testers
Formats
- github repository
- yaml tests
- command examples
- wiki documentation
Keywords
- adversary-emulation
- mitre-attack
- detection-validation
- purple-team
- endpoint-telemetry
- security-testing
- dual-use
- cloud-security
- container-security
Link validation: Reachable · checked 2026-09-07 · HTTP 200