Atomic Red Team

No phone app

  • Recognised40% of the score33
  • Phone app26% of the score0
  • Documented20% of the score91
  • Free plan14% of the score100
Free plan
Yes
Runs on
api, Linux, Mac, Windows

Summary

Atomic Red Team is a free library of security tests that teams can use to examine visibility, detection coverage, and defenses against adversary behaviors. Its tests are mapped to the MITRE ATT&CK matrix, use few dependencies, and follow a structured format suitable for automation frameworks. Invoke-AtomicRedTeam is a PowerShell module for running tests against security controls, either locally or on remote machines through PowerShell Remoting. Atomic Runner can run a configurable test list unattended, weekly by default. A Ruby API supports test validation and documentation generation, and the project obtains ATT&CK data in STIX format. Listed integrations include Microsoft Defender for Endpoint, AttackIQ, Datadog Workload Security Evaluator, OpenBAS, Splunk Attack Range, and Tidal Cyber. Coverage includes Windows, Linux, macOS, cloud infrastructure, containers, SaaS, Azure AD, Google Workspace, Office 365, and IaaS providers. Tests can be chained manually, but there is no automated way to emulate an entire specific attack group. Obtain permission from the environment owner before running a test.

Who it is for

It suits security teams seeking mapped tests to assess detection coverage and validate visibility. Teams should have permission to test the environment and may need to chain tests manually for a broader scenario.

What is good

  • Free open-source project.
  • Tests map to the MITRE ATT&CK matrix.
  • Runs tests locally or remotely through PowerShell Remoting.
  • Atomic Runner supports unattended scheduled runs.
  • Includes tests for cloud infrastructure and other attack surfaces.

What to know first

  • No automated emulation of a specific attack group as a whole.
  • Users need environment-owner permission before executing tests.

Verdict

Atomic Red Team offers a structured library of mapped tests, plus tools for local, remote, and unattended execution. It does not automate emulation of a whole specific attack group, and testing requires permission from the environment owner.

Atomic Red Team plans and pricing

All plans
Open-source project Free tests run in five minutes or less · minimal setup · community developed atomicredteam.io · 2 Oct 2026

Compared on breach and attack simulation software

Free plan
Yesatomicredteam.io
Included attack surfaces
Windows, Linux, macOS, cloud infrastructure, containers, SaaS, Azure AD, Google Workspace, Office 365, and IaaS providersatomicredteam.io
MITRE ATT&CK mapping
Yesatomicredteam.io
Custom attack scenarios
Yesatomicredteam.io
Continuous scheduling
Yesatomicredteam.io
Deployment model
on-premisesatomicredteam.io

Facts

Purpose
Atomic Red Team is a library of simple tests that security teams can execute to test their controls.atomicredteam.io · 2 Oct 2026
Detection validation
The project supports validating visibility, testing detection coverage, and emulating adversary behaviors.atomicredteam.io · 2 Oct 2026
ATT&CK mapping
Atomic tests are mapped to the MITRE ATT&CK matrix.atomicredteam.io · 2 Oct 2026
Test format
Tests have few dependencies and are defined in a structured format usable by automation frameworks.atomicredteam.io · 2 Oct 2026
Execution framework
Invoke-AtomicRedTeam is a PowerShell module for testing security controls and defenses against attack techniques.atomicredteam.io · 2 Oct 2026
Remote execution
Invoke-AtomicTest can run tests locally or on remote machines through PowerShell Remoting.atomicredteam.io · 2 Oct 2026
Continuous testing
Atomic Runner runs a configurable list of atomic tests unattended, once per week by default.atomicredteam.io · 2 Oct 2026
Ruby API
Atomic Red Team includes a Ruby API used to validate tests and generate documentation.atomicredteam.io · 2 Oct 2026
ATT&CK data API
The project pulls MITRE ATT&CK data using the STIX representation of ATT&CK.atomicredteam.io · 2 Oct 2026
Integrations
The project page lists integrations and products including Microsoft Defender for Endpoint, AttackIQ, Datadog Workload Security Evaluator, OpenBAS, Splunk Attack Range, and Tidal Cyber.atomicredteam.io · 2 Oct 2026
Cloud coverage
Atomic Red Team covers cloud infrastructure attacks through tests marked with iaas as a supported platform.atomicredteam.io · 2 Oct 2026
Operational limit
There is no automated solution for emulating a specific attack group as a whole; tests can be chained manually.atomicredteam.io · 2 Oct 2026
Security use requirement
Users are instructed to obtain permission from the environment owner before executing an atomic test.atomicredteam.io · 2 Oct 2026
Community support
The public Atomic Red Team Slack Workspace has an #atomic-git channel that posts notifications about new contributions.atomicredteam.io · 2 Oct 2026

Best Atomic Red Team alternatives

See all 17

Where it ranks on Samsung Mobile US Press

Is Atomic Red Team yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources