OpenAEV

7.7easy start · #1 of 31
in Threat Intelligence Platforms
  • Free to practise onyes
  • Free trialyes
  • Well documentedyes
  • Runs where you worknot on record

Runs on api, Linux, self-hosted, Web.

OpenAEV is an Adversarial Exposure Validation platform for cybersecurity and crisis-management teams. It supports attack simulations informed by cyber threat intelligence, with scenarios mapped to MITRE ATT&CK and ATLAS. Attack Chaining can connect actions into paths based on findings, either through manual orchestration or dedicated agents. Teams can also run structured tabletop exercises covering readiness, escalation, coordination, communication, and response. Adversarial Exposure Scoring tracks posture over time and maps coverage to MITRE ATT&CK and domain-based controls. The product lists more than 30 integrations and connections to OpenCTI, threat feeds, EDR/XDR, SIEM, and SOC playbooks. Deployment options include cloud, on-premise, and multi-tenant environments; Enterprise Edition also lists air-gapped and bring-your-own-cloud choices. Community Edition is free forever for on-premise core simulations and tabletop exercises, with community support. Enterprise Edition pricing is quote-based, and its SaaS trial lasts 30 days. Components are available as Docker images or manual installation packages; Kubernetes is recommended for production deployments.

Who it is for

OpenAEV suits cybersecurity and crisis-management teams that need to run attack simulations, assess exposure, or practice response through tabletop exercises. Community Edition provides on-premise core simulation and tabletop capabilities.

What is good

  • Maps simulations to MITRE ATT&CK and ATLAS.
  • Supports manual or agent-orchestrated attack paths.
  • Tracks exposure posture over time.
  • Community Edition includes core simulations and tabletop exercises.
  • Supports cloud, on-premise, and multi-tenant deployments.

What to know first

  • Enterprise pricing is quote-based.
  • Community Edition is on-premise.
  • The Enterprise SaaS trial lasts 30 days.

The Geeks Club review

OpenAEV: the full review

OpenAEV combines adversarial simulations, exposure scoring, and crisis exercises, with a free on-premise Community Edition and a quote-based Enterprise Edition. Check the required deployment model and enterprise governance or support needs when choosing between them.

OpenAEV is a platform for validating security exposure through attack simulations and crisis exercises. It is best suited to cybersecurity and crisis teams that want to connect threat-led testing with response readiness. Its broad scope is a strength, but Community Edition requires on-premise deployment and Enterprise Edition uses custom pricing.

Overview

OpenAEV combines adversarial testing with structured exercises for evaluating how teams coordinate, communicate, escalate, and respond. Its simulations draw on cyber threat intelligence, while exposure scoring tracks posture over time against MITRE ATT&CK and domain-based controls. That makes it more than a tool for running isolated attack tests: it can also help organizations connect exercise results to a continuing view of coverage.

Filigran, the company behind OpenAEV, was founded in 2022 and is headquartered in Paris. It lists SOC 2 Type 2, ISO 27001:2022, and GDPR trust items.

Key features

Threat-led simulations and attack paths

OpenAEV maps breach and attack scenarios to MITRE ATT&CK and ATLAS, and supports custom scenarios and continuous scheduling. Attack Chaining connects actions into paths based on findings; teams can orchestrate them manually or use dedicated agents for autonomous operation. Indicator enrichment, STIX/TAXII support, reporting, workflow automation, and case management support a repeatable validation program rather than one-off exercises.

Coverage ranges from endpoints, asset groups, people, teams, and network hosts to email, phishing landing pages, SMS, phone-based social engineering, and media pressure. That breadth lets teams consider technical and human-facing attack surfaces together, but organizations seeking only a narrow technical test may not need the full scope.

Exercises, scoring, and integrations

Structured tabletop exercises assess readiness across escalation, coordination, communication, and response. Adversarial Exposure Scoring provides a way to follow posture over time and compare coverage with ATT&CK and domain-based controls. The product has 30+ integrations and connects OpenCTI, threat feeds, EDR/XDR, SIEM, and SOC playbooks, which can help teams relate simulations to existing intelligence and security operations.

Community Edition includes OpenCTI security coverage integration, prepackaged scenarios, Threat Arsenal, atomic testing, tabletop exercises, scoring, CVE findings, alert fetching, and RBAC. Enterprise adds advanced integrations and AI features, alongside governance options including SSO, full audit logging, data segregation, and advanced role-based access controls. Those enterprise controls matter for organizations with stricter access and oversight requirements; smaller teams may find the free edition sufficient if its deployment and support terms fit.

Pricing

OpenAEV uses a freemium model, with a free plan and a 30-day Enterprise Edition SaaS trial.

PlanPriceWhat it includesBest fit
Community Edition0.00 USD per free; billed Free foreverOn-premise core attack simulation and tabletop exercises; community supportTeams able to manage an on-premise deployment and work without vendor support
Enterprise EditionCustom pricing, based on number of instances, instance size, and support servicesSaaS or on-premise, advanced integrations, AI features, and vendor support with SLAsOrganizations needing enterprise deployment choices, governance, and supported service

The Community Edition avoids a subscription charge but trades away SaaS delivery and vendor support. Enterprise includes a customer support portal and dedicated Customer Success Manager; Filigran offers standard 8×5 and premium 24×7 support options. The trial gives teams 30 days to explore the SaaS edition before deciding whether a custom-priced plan fits.

Platforms

OpenAEV supports API, Linux, self-hosted, and web environments. Deployment options include cloud, on-premise, and multi-tenant setups, with or without an endpoint agent; Enterprise also offers air-gapped and bring-your-own-cloud options. Components are available as Docker images and manual installation packages, and Kubernetes is recommended for production deployments. This flexibility suits teams with varied infrastructure requirements, though Community Edition is on-premise only.

Who it's for

OpenAEV is aimed at cybersecurity and crisis management teams that need to exercise both defenses and organizational response. Its mix of attack chaining, scoring, tabletop work, and integrations will be most useful where teams can turn exercise results into ongoing security and readiness work. Filigran says Enterprise Edition is trusted by governments, financial institutions, and enterprises. A team looking for a quick, single-purpose test or one without the capacity for deployment and exercise planning may prefer a narrower tool.

Pros and cons

  • Broad exercise coverage: technical attack surfaces, social engineering, media pressure, and tabletop scenarios can be addressed in one platform.
  • Useful continuity: continuous scheduling and exposure scoring support tracking posture over time instead of treating each simulation as a standalone event.
  • Flexible enterprise deployment: cloud, on-premise, multi-tenant, air-gapped, and bring-your-own-cloud options accommodate varied operating environments.
  • Free edition has meaningful limits: Community is on-premise and comes with community support, while vendor support and SLAs are part of Enterprise.
  • Enterprise costs require scoping: custom pricing depends on instances, instance size, and support services, so buyers must establish the required footprint before budgeting.

Alternatives

For a broader category comparison, see Breach and Attack Simulation Software and Threat Intelligence Platforms.

  • Atomic Red Team is a free, community-developed project for tests that run in five minutes or less with minimal setup; choose it for lightweight testing rather than OpenAEV's combined simulation and crisis-exercise scope.
  • Keysight Eggplant Test is paid enterprise software with a quote-based plan and a free trial.
  • Cymulate Platform is a paid web platform with a free trial and subscription pricing tailored to the organization, package, assets, and scenarios.
  • Picus Security Platform is a paid option with a free trial; its 14-day free trial is limited to one simulation agent and a ransomware-only threat library.
  • SCYTHE is a paid platform with a free trial and custom-quoted Foundation plan based on environment scope.
  • Valitrix BAS Platform is a paid platform with a free trial; its Professional plan is capped at four agents and three users.
  • Skyhawk Security BAS is a paid web platform with a free trial.
  • BlackNoise BAS is a paid platform available self-hosted or on the web.

Verdict

OpenAEV is a strong fit for organizations that want a sustained validation program spanning threat-informed attack simulations, exposure tracking, and crisis exercises. Its most compelling reason to choose is that those security and readiness workflows sit together, with flexible Enterprise deployment options. Look elsewhere if you need a lightweight test tool, cannot operate the free on-premise edition, or need predictable Enterprise pricing before scoping instances and support.

OpenAEV plans and pricing

All plans
Community Edition Free Free forever On-premise · core attack simulation and tabletop exercises · community support filigran.io · 29 Sept 2026
Enterprise Edition Not published Quote based on number of instances, instance size and support services SaaS or on-premise · advanced integrations · AI features · vendor support with SLAs filigran.io · 29 Sept 2026

Compared on threat intelligence platforms

Free plan
Yes
Attack simulation modes
hybrid
Included attack surfaces
endpoints, asset groups, people, teams, network hosts, email, phishing landing pages, SMS, phone-based social engineering, media pressure, tabletop exercises
MITRE ATT&CK mapping
Yes
Custom attack scenarios
Yes
Continuous scheduling
Yes
Deployment model
hybrid

Best OpenAEV alternatives

See all 20