Atomic Red Team is a free library of small tests security teams can run to check their controls. Tests help validate visibility, examine detection coverage, and emulate adversary behaviors, with mappings to the MITRE ATT&CK matrix. They use a structured format and have few dependencies, so automation frameworks can use them. Invoke-AtomicRedTeam is a PowerShell module for running tests locally or on remote machines through PowerShell Remoting. Atomic Runner can run a configurable list unattended, weekly by default. The project also includes a Ruby API for checking tests and producing documentation, and obtains ATT&CK data in STIX form. Listed integrations include Microsoft Defender for Endpoint, AttackIQ, Datadog Workload Security Evaluator, OpenBAS, Splunk Attack Range, and Tidal Cyber. Test coverage includes Windows, Linux, macOS, cloud infrastructure, containers, SaaS, and other listed environments. There is no automated method to emulate a whole specific attack group, though tests may be chained manually. Users are instructed to obtain permission from the environment owner before running tests.
Who it is for
Atomic Red Team suits security teams seeking to validate control visibility and detection coverage with ATT&CK-mapped tests. It is an on-premises project with listed support for desktop operating systems and cloud infrastructure.
What is good
- Free open-source project.
- Tests map to MITRE ATT&CK.
- Can run tests on remote machines.
- Atomic Runner supports unattended scheduled runs.
- Tests use a structured format with few dependencies.
What to know first
- No automated emulation for a whole specific attack group.
- Permission from the environment owner is required before tests.
- Attack-group scenarios require manual test chaining.
Freedom251 review
Atomic Red Team: the full review
Atomic Red Team offers a free collection of mapped tests and tools for running them locally, remotely, or on a schedule. It does not automate emulation of a full attack group, and users need the environment owner's permission before execution.
Atomic Red Team is a library of ATT&CK-mapped security tests for checking detection coverage and visibility. It suits security teams that want to run individual adversary techniques across varied environments, especially where automation or integration with existing tools matters. Its main strength is focused, repeatable tests; it is not a turnkey simulation of a complete threat group.
Overview
The project pairs a collection of tests with tools for running, validating, and documenting them. Because tests have few dependencies and use a structured format, teams can incorporate them into automation frameworks rather than treating each exercise as a one-off. The ATT&CK mapping gives the tests a useful frame for examining which behaviors defenses can detect.
That focus on individual techniques is also a boundary: there is no automated way to emulate a specific attack group end to end. Teams can chain tests manually, but that takes planning and does not provide an automated group-level scenario. Execution also requires permission from the owner of the environment.
Key features
- ATT&CK-mapped coverage: Tests span Windows, Linux, macOS, cloud infrastructure, containers, SaaS, Azure AD, Google Workspace, Office 365, and IaaS providers. This broad surface gives teams a way to exercise controls beyond conventional endpoints, while still requiring them to choose and run relevant tests.
- PowerShell execution: Invoke-AtomicRedTeam is a PowerShell module for testing controls against attack techniques. Invoke-AtomicTest can run tests locally or on remote machines through PowerShell Remoting, which suits teams managing Windows environments across multiple hosts.
- Scheduled runs: Atomic Runner executes a configurable list of tests unattended, weekly by default. This can support recurring checks without a person launching each test, though the schedule and test list need to fit the environment.
- Validation and data tools: A Ruby API supports test validation and documentation generation, and the project retrieves ATT&CK data in STIX format. These components make the library more useful in workflows that maintain or automate tests.
- Integrations and community: The project lists integrations including Microsoft Defender for Endpoint, AttackIQ, Datadog Workload Security Evaluator, OpenBAS, Splunk Attack Range, and Tidal Cyber. Its public Slack workspace has an #atomic-git channel for new-contribution notifications.
Pricing
Open-source project — 0.00 USD per free. The free plan includes tests that run in five minutes or less, require minimal setup, and are community-developed. It covers the listed attack surfaces, supports custom attack scenarios and continuous scheduling, and is deployed on-premises. There are no paid tiers or seat and quota terms in this plan; its practical trade-off is the short test-duration limit and the need for teams to select, authorize, and operate the tests themselves.
Platforms
Atomic Red Team supports API, Linux, macOS, and Windows. Its attack-surface coverage also includes cloud infrastructure, containers, SaaS, Azure AD, Google Workspace, Office 365, and IaaS providers. The deployment model is on-premises, making it a fit for teams that want tests run within their own environments rather than through a hosted service.
Who it's for
It is a strong fit for security teams validating visibility and detection coverage against specific ATT&CK techniques, particularly those able to use PowerShell, schedule recurring runs, or connect the tests to automation and security products. It is less suitable for teams seeking an automated, full-operation adversary simulation or a managed testing service; Atomic Red Team supplies tests and execution tools, not a complete attack-group campaign.
Pros and cons
- Pros: Free access, broad platform and workload coverage, ATT&CK mapping, and a structured low-dependency test format support repeatable control checks across varied environments.
- Pros: Local and remote execution plus weekly unattended scheduling can make recurring validation practical for teams with the right operational setup.
- Cons: The five-minute test limit rules out longer-running tests under the free plan.
- Cons: Full attack-group emulation is not automated, so broader scenarios require manual chaining.
- Cons: Tests must not be run without the environment owner's permission, which makes authorization an essential operational prerequisite.
Alternatives
For a broader starting point, browse Breach and Attack Simulation Software.
- OpenAEV is worth considering when a freemium option with a free-forever on-premise Community Edition, core attack simulation, tabletop exercises, and community support better matches the need.
- Infection Monkey is another free option for teams looking at a web, Windows, and Linux platform.
- PurpleSharp is a free alternative focused on Windows.
- BlackNoise BAS is a paid alternative for teams seeking a self-hosted or web option.
- Cymulate Platform is a paid web option with a free trial and subscription pricing tailored to the organization.
- Keysight Eggplant Test is a paid enterprise option with a free trial and a broad platform range.
- Stratus Red Team is another free option for Windows, macOS, and Linux.
- MITRE Caldera is a free alternative for web, Linux, and macOS.
Verdict
Choose Atomic Red Team if you want a free, ATT&CK-mapped library for recurring, targeted validation across endpoints and cloud workloads. Its combination of structured tests, local or remote execution, and scheduling is compelling for teams prepared to manage their own exercises. Look elsewhere if you need a system that automatically reproduces a full threat group's operation.
Atomic Red Team plans and pricing
All plansCompared on breach and attack simulation software
- Free plan
- Yes
- Included attack surfaces
- Windows, Linux, macOS, cloud infrastructure, containers, SaaS, Azure AD, Google Workspace, Office 365, and IaaS providers
- MITRE ATT&CK mapping
- Yes
- Custom attack scenarios
- Yes
- Continuous scheduling
- Yes
- Deployment model
- on-premises



