Atomic Red Team

7.2easy start · #2 of 19
in Breach and Attack Simulation Software
  • Free to practise onyes
  • Free trialnot on record
  • Well documentedyes
  • Runs where you workyes

Runs on api, Linux, Mac, Windows.

Atomic Red Team is a free library of security tests for checking whether controls can see and detect adversary behavior. Its tests are mapped to the MITRE ATT&CK matrix and use a structured format with few dependencies, so automation frameworks can use them. The Invoke-AtomicRedTeam PowerShell module runs tests locally or on remote machines through PowerShell Remoting; Atomic Runner can run a configurable list unattended, weekly by default. A Ruby API helps validate tests and produce documentation, and the project obtains ATT&CK data in STIX form. Coverage includes Windows, Linux, macOS, cloud infrastructure, containers, SaaS, Azure AD, Google Workspace, Office 365 and IaaS providers. Tests can be chained manually, but there is no automated way to emulate a specific attack group as a whole. Before running a test, users are instructed to get permission from the environment owner.

Who it is for

It suits security teams that want to validate detection coverage across supported environments or schedule recurring tests. Teams should be able to obtain permission and manage any manual chaining needed for group-specific scenarios.

What is good

  • Free plan with minimal setup.
  • Tests map to the MITRE ATT&CK matrix.
  • PowerShell module supports local and remote runs.
  • Atomic Runner can schedule unattended tests.
  • Covers cloud infrastructure and listed attack surfaces.

What to know first

  • No automated emulation of a whole attack group.
  • Permission from the environment owner is required.

Verdict

Atomic Red Team provides a free set of mapped tests and tools for running them locally, remotely, or on a schedule. Group-level emulation requires manual chaining, and execution requires owner permission.

Atomic Red Team plans and pricing

All plans
Open-source project Free tests run in five minutes or less · minimal setup · community developed atomicredteam.io · 2 Oct 2026

Compared on breach and attack simulation software

Free plan
Yes
Included attack surfaces
Windows, Linux, macOS, cloud infrastructure, containers, SaaS, Azure AD, Google Workspace, Office 365, and IaaS providers
MITRE ATT&CK mapping
Yes
Custom attack scenarios
Yes
Continuous scheduling
Yes
Deployment model
on-premises

Best Atomic Red Team alternatives

See all 12