The OpenAEV homepage
Score7.0
Rank#1 of 31
PriceFree
Free planYes
Free trialYes
Runs onAPI, Linux, Self-hosted, Web

Summary

OpenAEV is an Adversarial Exposure Validation platform for cybersecurity and crisis-management teams. It supports breach and attack simulations informed by cyber threat intelligence, with scenarios mapped to MITRE ATT&CK and ATLAS. Attack Chaining links actions into attack paths based on findings, either manually or through dedicated agents. Teams can also run tabletop exercises to assess readiness, escalation, coordination, communication, and response. Adversarial Exposure Scoring tracks posture over time and maps coverage to MITRE ATT&CK and domain-based controls. The product lists more than 30 integrations, including connections to OpenCTI, threat feeds, EDR/XDR, SIEM, and SOC playbooks. Deployment options include cloud, on-premise, and multi-tenant setups; Enterprise Edition also lists air-gapped and bring-your-own-cloud options. Community Edition is free forever for on-premise core simulations and tabletop exercises, with community support. Enterprise pricing is quote-based and its SaaS trial lasts 30 days. Components are available as Docker images or manual installation packages, with Kubernetes recommended for production. Community Edition includes prepackaged scenarios, scoring, atomic testing, CVE findings, alert fetching, RBAC, and more.

Who it is for

OpenAEV suits cybersecurity and crisis-management teams planning attack simulations, exposure tracking, or tabletop exercises. Community Edition is an option for teams seeking an on-premise platform with core functions and community support.

What is good

  • Maps simulations to MITRE ATT&CK and ATLAS.
  • Supports tabletop exercises and exposure scoring.
  • Community Edition is free forever.
  • Deployment options include cloud and on-premise.
  • Lists more than 30 integrations.

What to know first

  • Enterprise Edition pricing is quote-based.
  • Enterprise SaaS trial lasts 30 days.
  • Community Edition support is community-based.

Everything Xiaomi review

OpenAEV: the full review

OpenAEV combines adversarial simulations, tabletop exercises, and exposure scoring, with a free on-premise edition and a quote-based Enterprise option. Teams should choose based on required deployment, governance, and support needs.

Overview

OpenAEV combines security testing with crisis-readiness exercises for cybersecurity and crisis management teams. It suits organizations that want to connect threat scenarios to measurable exposure and coordinated response work. Its breadth is compelling, but the best fit depends on whether an organization can run the on-premise Community Edition or justify Enterprise Edition’s custom pricing.

Filigran, founded in 2022 and headquartered in Paris, develops OpenAEV. The company lists SOC 2 Type 2, ISO 27001:2022, and GDPR trust items.

Key features

Threat-led simulations and attack paths

OpenAEV builds breach and attack simulations around cyber threat intelligence and maps scenarios to MITRE ATT&CK and ATLAS. Teams can create custom scenarios and link actions into attack paths based on findings, with manual orchestration or autonomous operation using dedicated agents. Continuous scheduling, indicator enrichment, STIX/TAXII support, reporting, workflow automation, and case management support ongoing exercises rather than one-off tests.

Its attack surfaces extend from endpoints, asset groups, teams, and network hosts to email, phishing landing pages, SMS, phone-based social engineering, and media pressure. That range gives security teams room to exercise both technical controls and human response, though it also makes OpenAEV a more involved choice than a narrowly focused simulation tool.

Tabletop exercises and exposure scoring

Structured tabletop exercises assess readiness across escalation, coordination, communication, and response. Adversarial Exposure Scoring tracks posture over time and maps coverage to MITRE ATT&CK and domain-based controls. Together, these functions make the platform relevant to teams trying to connect exercise outcomes with a continuing view of exposure.

Integrations and deployment

OpenAEV has 30+ integrations, including connections to OpenCTI, threat feeds, EDR/XDR, SIEM, and SOC playbooks. It supports cloud, on-premise, and multi-tenant deployment, with or without an endpoint agent; Enterprise Edition also offers air-gapped and bring-your-own-cloud options. Components are available as Docker images and manual installation packages, with Kubernetes recommended for production. This deployment range suits organizations with varied infrastructure needs, but production installation and governance can require more operational capacity than a hosted-only tool.

Community Edition includes OpenCTI security coverage integration, prepackaged scenarios, Threat Arsenal, atomic testing, tabletop exercises, scoring, CVE findings, alert fetching, and RBAC. Enterprise Edition adds SSO, full audit logging, data segregation, and advanced role-based access controls. Those governance features matter for organizations managing sensitive environments or distinct user groups.

Pricing

Community Edition: 0.00 USD per free, billed Free forever. It is on-premise and includes core attack simulation and tabletop exercises with community support. This is the clear starting point for teams able to operate their own deployment and comfortable relying on community support; it gives up Enterprise’s advanced integrations, AI features, vendor SLAs, and listed governance controls.

Enterprise Edition: custom pricing, based on number of instances, instance size, and support services. It is available as SaaS or on-premise and includes advanced integrations, AI features, and vendor support with SLAs. A 30-day SaaS trial lets teams explore the platform. Enterprise is the fit for organizations that need those capabilities, but custom pricing means buyers must weigh the deployment and support package against their requirements.

Filigran offers standard 8×5 and premium 24×7 support options. No seat or quota caps are stated for either plan.

Platforms

OpenAEV supports API, Linux, self-hosted, and web. Its deployment choices include cloud, on-premise, and multi-tenant setups, while Enterprise adds air-gapped and bring-your-own-cloud options.

Who it's for

OpenAEV is best suited to cybersecurity and crisis management teams that need to exercise technical defenses and organizational response in the same program. Community Edition makes sense for teams that can self-host and accept community support. Organizations needing SaaS, stronger governance, advanced integrations, or vendor SLAs should consider Enterprise. It is a less natural fit for buyers seeking a simple, narrowly scoped threat-intelligence feed rather than simulation and readiness workflows.

Pros and cons

  • Pro: Threat-led simulations, tabletop exercises, and exposure scoring sit in one platform, helping teams connect attack testing with crisis readiness and posture tracking.
  • Pro: Broad attack surfaces and 30+ integrations support exercises spanning technical assets, people, and operational response.
  • Pro: Community Edition is free forever and includes substantial simulation and tabletop capabilities for on-premise teams.
  • Con: Community Edition relies on community support and lacks Enterprise’s listed governance features, advanced integrations, AI features, and vendor SLAs.
  • Con: Enterprise pricing depends on instance count, size, and support services, so the cost is not a fixed plan price.

Alternatives

For teams comparing adjacent tools, the Threat Intelligence Platforms and Breach and Attack Simulation Software categories provide broader options.

  • SOCRadar Extended Threat Intelligence Platform offers freemium access, with monthly Advanced Dark Web Monitoring plans at 600.00 USD per month for 1 domain and 1 seat, or 1145.00 USD per month for its Business plan; consider it when those plans match your needs.
  • IBM X-Force Exchange has a free Freemium plan with limited portal access and no X-Force API access, a more limited free option than OpenAEV’s core simulation and tabletop offering.
  • ThreatForge offers a free open-source Community Edition under AGPL-3.0-or-later and a commercial Enterprise Edition with a 90-day trial; consider it if that licensing and trial structure suits your team.
  • Security Vision TIP uses individually calculated pricing through sales; consider it if you prefer that pricing approach.
  • Kaspersky Threat Intelligence Portal has a free plan and runs on web.
  • Anomali Platform is a paid API and web platform with pricing by request.
  • Flashpoint Ignite is a paid API and web platform with pricing by request.
  • Open Threat Exchange is free and web-based.

Verdict

Choose OpenAEV if your team wants threat-led simulations, tabletop response exercises, and exposure tracking in one environment, especially when on-premise Community Edition meets your support needs. Look elsewhere if you need a predictable Enterprise price or a narrower tool rather than a broad validation and crisis-readiness platform.

OpenAEV plans and pricing

All plans
Community Edition Free Free forever On-premise · core attack simulation and tabletop exercises · community support filigran.io · 29 Sept 2026
Enterprise Edition Not published Quote based on number of instances, instance size and support services SaaS or on-premise · advanced integrations · AI features · vendor support with SLAs filigran.io · 29 Sept 2026

Compared on threat intelligence platforms

Free plan
Yesfiligran.io
Attack simulation modes
hybridfiligran.io
Included attack surfaces
endpoints, asset groups, people, teams, network hosts, email, phishing landing pages, SMS, phone-based social engineering, media pressure, tabletop exercisesfiligran.io
MITRE ATT&CK mapping
Yesfiligran.io
Custom attack scenarios
Yesfiligran.io
Continuous scheduling
Yesfiligran.io
Deployment model
hybridfiligran.io

Facts

Purpose
OpenAEV is an Adversarial Exposure Validation platform for creating attack simulations, stress tests, and crisis management exercises.filigran.io · 29 Sept 2026
Threat-led simulations
Its breach and attack simulations use cyber threat intelligence and map scenarios to MITRE ATT&CK and ATLAS.filigran.io · 29 Sept 2026
Autonomous attack chaining
Attack Chaining links actions into attack paths based on findings and can be orchestrated manually or autonomously with dedicated agents.filigran.io · 29 Sept 2026
Crisis exercises
The platform supports structured tabletop exercises to evaluate team readiness, escalation, coordination, communication, and response.filigran.io · 29 Sept 2026
Exposure scoring
Adversarial Exposure Scoring tracks posture over time and maps coverage against MITRE ATT&CK and domain-based controls.filigran.io · 29 Sept 2026
Integrations
The product page states that OpenAEV has 30+ integrations and describes connecting OpenCTI, threat feeds, EDR/XDR, SIEM, and SOC playbooks.filigran.io · 29 Sept 2026
Deployment
OpenAEV supports cloud, on-premise, and multi-tenant deployments, with or without an endpoint agent; Enterprise Edition also lists air-gapped and bring-your-own-cloud options.filigran.io · 29 Sept 2026
Community features
Community Edition includes OpenCTI security coverage integration, prepackaged scenarios, Threat Arsenal, atomic testing, tabletop exercises, scoring, CVE findings, alert fetching, and RBAC.filigran.io · 29 Sept 2026
Enterprise governance
Enterprise Edition lists SSO, full audit logging, data segregation, and advanced role-based access controls.filigran.io · 29 Sept 2026
Trial
The Enterprise Edition SaaS trial provides 30 days to explore the platform.filigran.io · 29 Sept 2026
Support
Enterprise Edition includes a customer support portal and dedicated Customer Success Manager; Filigran lists standard 8×5 and premium 24×7 support options.filigran.io · 29 Sept 2026
Install options
The documentation says OpenAEV components are available as Docker images and manual installation packages, with Kubernetes also recommended for production deployments.docs.openaev.io · 29 Sept 2026
Intended users
Filigran describes OpenAEV as serving cybersecurity and crisis management teams, and says its Enterprise Edition is trusted by governments, financial institutions, and enterprises.filigran.io · 29 Sept 2026
Company security attestations
Filigran lists SOC 2 Type 2, ISO 27001:2022, and GDPR trust items on its site.filigran.io · 29 Sept 2026

Company

Founded
2022filigran.io · 28 Sept 2026
Headquarters
Paris, Francefiligran.io · 28 Sept 2026

Best OpenAEV alternatives

See all 12

Where it ranks on Everything Xiaomi

Is OpenAEV yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources