
Atomic Red Team
Summary
Atomic Red Team is a free library of security tests for checking whether security controls provide visibility and detect adversary behaviors. Its tests map to the MITRE ATT&CK matrix and use a structured format with few dependencies, making them usable with automation frameworks. The project includes Invoke-AtomicRedTeam, a PowerShell module that can run tests locally or on remote machines through PowerShell Remoting, and Atomic Runner, which can run a configurable list unattended once per week by default. A Ruby API helps validate tests and generate documentation, while an API pulls ATT&CK data in STIX format. Tests cover Windows, Linux, macOS, and cloud infrastructure, among other listed attack surfaces, and the project lists integrations such as Microsoft Defender for Endpoint, Splunk Attack Range, and AttackIQ. It is an on-premises project with a free plan. There is no automated way to emulate a particular attack group as a whole, though tests can be chained manually. Users should obtain permission from the environment owner before running tests.
Who it is for
It suits security teams that want to check detection coverage against ATT&CK techniques using structured tests. Teams seeking a complete automated emulation of a specific attack group should note that this is not provided.
What is good
- Free plan for the open-source project
- Tests mapped to the MITRE ATT&CK matrix
- Runs tests locally or through PowerShell Remoting
- Atomic Runner supports unattended scheduled testing
- Tests cover cloud infrastructure and multiple platforms
What to know first
- No automated whole-group attack emulation
- Permission from the environment owner is required
Everything Xiaomi review
Atomic Red Team: the full review
Atomic Red Team provides a free, ATT&CK-mapped library for testing security controls, with local and remote execution options. It supports repeatable testing, but does not automate emulation of an entire specific attack group.
Overview
Atomic Red Team is a collection of small security tests intended to help teams check what their defenses can see and whether detection coverage exists. Each test represents an adversary behavior and is mapped to the MITRE ATT&CK matrix, so teams can exercise controls against individual techniques.
The project combines the test library with utilities for executing, validating, and documenting tests. Its tests have few dependencies and use a structured format that automation frameworks can consume. Atomic Red Team does not automatically recreate a specific threat group’s full operation; teams can chain tests manually when they need a broader sequence.
Execution requires authorization: users are instructed to obtain permission from the owner of the environment before running a test.
Key features
- ATT&CK mapping: Tests align with the MITRE ATT&CK matrix and cover Windows, Linux, macOS, cloud infrastructure, containers, SaaS, Azure AD, Google Workspace, Office 365, and IaaS providers. Cloud infrastructure tests are marked with iaas as a supported platform.
- Automation-friendly tests: Tests use a structured format and have few dependencies, making them usable with automation frameworks.
- PowerShell execution: Invoke-AtomicRedTeam is a PowerShell module for testing security controls against attack techniques. Invoke-AtomicTest can execute tests locally or on remote machines through PowerShell Remoting.
- Scheduled runs: Atomic Runner executes a configurable list of tests unattended, with weekly runs as its default schedule.
- Ruby API and ATT&CK data: The Ruby API helps validate tests and generate documentation. The project obtains ATT&CK data in STIX representation.
- Integrations: Listed products include Microsoft Defender for Endpoint, AttackIQ, Datadog Workload Security Evaluator, OpenBAS, Splunk Attack Range, and Tidal Cyber.
- Community updates: The public Slack Workspace’s #atomic-git channel posts notifications about new contributions.
Custom attack scenarios are supported, but group-level emulation is not automated. A team seeking to represent a sequence of behaviors must assemble the tests itself.
Pricing
Atomic Red Team is an open-source project with a free plan priced at 0.00 USD per free. The listed plan includes tests that run in five minutes or less, minimal setup, and community development.
Platforms
Listed platforms are API, Linux, macOS, and Windows. The project also lists cloud infrastructure, containers, SaaS, Azure AD, Google Workspace, Office 365, and IaaS providers among its covered attack surfaces. Its deployment model is on-premises.
Who it's for
Atomic Red Team is suited to security teams that want to validate visibility, exercise detection coverage, or emulate individual adversary techniques. Its ATT&CK mapping and automation-friendly test format support structured control checks, while Invoke-AtomicTest offers local and remote execution options. Teams should be prepared to manage permissions and assemble multi-test scenarios manually.
Pros and cons
- Pros: Free access; tests mapped to MITRE ATT&CK; broad listed attack-surface coverage; support for scheduled execution; and tests designed for automation.
- Cons: It does not automatically emulate a whole specific attack group, and test execution requires permission from the environment owner.
Alternatives
For more options, browse Breach and Attack Simulation Software. Other listed alternatives include OpenAEV, Keysight Eggplant Test, Infection Monkey, Picus Security Platform, SCYTHE, BlackNoise BAS, Cymulate Platform, and PurpleSharp.
Verdict
Atomic Red Team offers a free, ATT&CK-mapped set of tests with execution and scheduling tools for teams checking their defensive visibility and detection coverage. Its scope is individual behaviors rather than automated, end-to-end emulation of a particular attack group. Teams that need that broader scenario must chain tests themselves and should establish authorization before execution.
Atomic Red Team plans and pricing
All plansCompared on breach and attack simulation software
- Free plan
- Yesatomicredteam.io
- Included attack surfaces
- Windows, Linux, macOS, cloud infrastructure, containers, SaaS, Azure AD, Google Workspace, Office 365, and IaaS providersatomicredteam.io
- MITRE ATT&CK mapping
- Yesatomicredteam.io
- Custom attack scenarios
- Yesatomicredteam.io
- Continuous scheduling
- Yesatomicredteam.io
- Deployment model
- on-premisesatomicredteam.io
Facts
- Purpose
- Atomic Red Team is a library of simple tests that security teams can execute to test their controls.atomicredteam.io · 2 Oct 2026
- Detection validation
- The project supports validating visibility, testing detection coverage, and emulating adversary behaviors.atomicredteam.io · 2 Oct 2026
- ATT&CK mapping
- Atomic tests are mapped to the MITRE ATT&CK matrix.atomicredteam.io · 2 Oct 2026
- Test format
- Tests have few dependencies and are defined in a structured format usable by automation frameworks.atomicredteam.io · 2 Oct 2026
- Execution framework
- Invoke-AtomicRedTeam is a PowerShell module for testing security controls and defenses against attack techniques.atomicredteam.io · 2 Oct 2026
- Remote execution
- Invoke-AtomicTest can run tests locally or on remote machines through PowerShell Remoting.atomicredteam.io · 2 Oct 2026
- Continuous testing
- Atomic Runner runs a configurable list of atomic tests unattended, once per week by default.atomicredteam.io · 2 Oct 2026
- Ruby API
- Atomic Red Team includes a Ruby API used to validate tests and generate documentation.atomicredteam.io · 2 Oct 2026
- ATT&CK data API
- The project pulls MITRE ATT&CK data using the STIX representation of ATT&CK.atomicredteam.io · 2 Oct 2026
- Integrations
- The project page lists integrations and products including Microsoft Defender for Endpoint, AttackIQ, Datadog Workload Security Evaluator, OpenBAS, Splunk Attack Range, and Tidal Cyber.atomicredteam.io · 2 Oct 2026
- Cloud coverage
- Atomic Red Team covers cloud infrastructure attacks through tests marked with iaas as a supported platform.atomicredteam.io · 2 Oct 2026
- Operational limit
- There is no automated solution for emulating a specific attack group as a whole; tests can be chained manually.atomicredteam.io · 2 Oct 2026
- Security use requirement
- Users are instructed to obtain permission from the environment owner before executing an atomic test.atomicredteam.io · 2 Oct 2026
- Community support
- The public Atomic Red Team Slack Workspace has an #atomic-git channel that posts notifications about new contributions.atomicredteam.io · 2 Oct 2026
Best Atomic Red Team alternatives
See all 12Where it ranks on Everything Xiaomi
Is Atomic Red Team yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- atomicredteam.io/docs/atomic-red-team/faq· checked 2 Oct 2026
- atomicredteam.io/atomic-red-team· checked 2 Oct 2026
- atomicredteam.io/docs/invoke-atomicredteam/getting-start· checked 2 Oct 2026
- atomicredteam.io/docs/invoke-atomicredteam/execute-tests· checked 2 Oct 2026
- atomicredteam.io/docs/invoke-atomicredteam/continuous-at· checked 2 Oct 2026
- atomicredteam.io/docs/atomic-red-team/api· checked 2 Oct 2026
- atomicredteam.io/built-on-atomic· checked 2 Oct 2026
- atomicredteam.io/docs/atomic-red-team· checked 2 Oct 2026



