atomic-red-team
Here are 76 public repositories matching this topic...
Interactive PowerShell framework for testing WMI, COM, LOLBAS, and persistence techniques
-
Updated
Dec 28, 2025 - PowerShell
BasicEventViewer4 (BEV v4.0), this code will useful for All Blue/Purple Teams , RealTime Monitoring Sysmon Events , Mitre Attack Detections via yaml files
-
Updated
Jun 22, 2023 - C#
A tool to run and validate telemetry for Atomic Red Team tests
-
Updated
Mar 21, 2024 - Go
A library of post-exploitation MacOS scripts based on threat emulation, LOObins, CTI, and MITRE ATT&CK.
-
Updated
May 21, 2026 - Shell
This project sets up an Active Directory environment and configures Splunk to ingest events from a Windows Server and a target machine. We perform a brute force attack using Kali Linux to observe telemetry and use Atomic Red Team for additional testing. Goals: enhance IT administration skills, event monitoring, and threat detection.
-
Updated
Jun 15, 2024
-
Updated
Feb 28, 2022 - PowerShell
Slides, notes and more related to Atomics on a Friday
-
Updated
Sep 26, 2025 - PowerShell
A shrimple guide to deploying the Elastic Stack to create your own local SIEM setup for shrimple Windows event log shipping and analysis; for simulations and more, plus mock DFIR simulations using Atomic Red Team!
-
Updated
Sep 21, 2025
The lab involves setting up a virtualized environment with Oracle VM VirtualBox, creating Windows 10, Kali Linux, Windows Server, and Ubuntu Server VMs. Tools like Splunk, Sysmon, and Crowbar are used for security testing. Participants configure networks, join Windows to Active Directory, and practice PowerShell scripting.
-
Updated
Apr 4, 2024
Simulated SOC environment using Splunk, Sysmon & Atomic Red Team
-
Updated
Jun 21, 2025
A Kathara Framework Cyber Lab, for attack and defense emulation
-
Updated
Mar 16, 2025 - Lua
Project for Project 1 course of SoICT - HUST
-
Updated
Jul 8, 2023 - Java
Homelab SOC construit sur ELK 8.19.16, MISP 2.4, Sysmon et Atomic Red Team : documentation, configurations et guides de déploiement pour une stack full open source.
-
Updated
Jun 16, 2026
Hands-on SOC lab showcasing AD attack detection and endpoint hardening using Atomic Red Team, Wazuh, and CIS compliance frameworks.
-
Updated
Jul 18, 2025 - Python
Evidence-driven purple team pipeline for SANS SEC598 — extracts ATT&CK techniques from threat reports, executes adversary emulations (Caldera + Atomic Red Team), validates detections (LimaCharlie), and produces coverage reports with per-technique proof chains
-
Updated
Jun 18, 2026 - Python
Detection engineering pipeline: 140 Sigma rules for Windows, Linux, and M365/Azure with automated CI/CD validation, Splunk conversion, and Atomic Red Team regression testing. MITRE ATT&CK mapped.
-
Updated
Jun 8, 2026 - Python
GitHub Action for local execution of Atomic Red Team tests using Invoke-Atomic
-
Updated
Jan 4, 2025 - PowerShell
Create a complete Active Directory lab environment, configure Windows servers, and test security using tools like Kali Linux, Splunk, and Atomic Red Team.
-
Updated
Nov 7, 2024
Adversary emulation scenarios using Atomic Red Team — credential dumping, lateral movement, persistence
-
Updated
Mar 22, 2026
Improve this page
Add a description, image, and links to the atomic-red-team topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the atomic-red-team topic, visit your repo's landing page and select "manage topics."