OpenAEV

Web · Linux · Self-hosted · API

Freedom report

Two barsScore 6.5

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely2 of 6 device platforms
  • DocumentedPlans, terms and facts published

OpenAEV is an Adversarial Exposure Validation platform for cybersecurity and crisis management teams. It creates breach and attack simulations informed by cyber threat intelligence, mapping scenarios to MITRE ATT&CK and ATLAS. Attack Chaining can connect actions into paths based on findings, either through manual orchestration or dedicated agents. Teams can also conduct structured tabletop exercises to assess readiness, escalation, coordination, communication, and response. Adversarial Exposure Scoring tracks posture over time and maps coverage to MITRE ATT&CK and domain-based controls. The product lists 30+ integrations, including connections to OpenCTI, threat feeds, EDR/XDR, SIEM, and SOC playbooks. Deployment options include cloud, on-premise, and multi-tenant setups; Enterprise Edition also lists air-gapped and bring-your-own-cloud choices. Community Edition is free forever for on-premise core simulations and tabletop exercises, with community support. Enterprise Edition pricing is quote-based, and its SaaS trial lasts 30 days. Components are available as Docker images or manual installation packages; Kubernetes is recommended for production deployments.

Who it is for

OpenAEV suits cybersecurity teams validating exposure and response, and crisis management teams running tabletop exercises. Enterprise Edition is also positioned for governments, financial institutions, and enterprises.

What is good

  • Maps simulations to MITRE ATT&CK and ATLAS.
  • Supports manual or agent-orchestrated attack paths.
  • Community Edition is free forever.
  • Offers cloud, on-premise, and multi-tenant deployments.
  • Lists 30+ integrations.

What to know first

  • Enterprise Edition pricing is quote-based.
  • Community support is listed for Community Edition.
  • Kubernetes is recommended for production deployments.

Freedom251 review

OpenAEV: the full review

OpenAEV combines attack simulation, exposure tracking, and crisis exercises, with a free on-premise Community Edition and a quote-based Enterprise Edition. Teams should compare the edition’s deployment and support provisions with their needs before choosing.

Overview

OpenAEV brings adversary simulations and crisis exercises together for security and response teams that need to test both controls and coordination. Its unusual breadth is a strength; the trade-off is that Enterprise pricing is custom, while the free edition is on-premise.

Filigran, founded in 2022 and headquartered in Paris, develops the platform. The company lists SOC 2 Type 2, ISO 27001:2022, and GDPR trust items.

Key features

Threat-led simulations and attack paths

OpenAEV uses cyber threat intelligence to shape breach and attack simulations, with scenarios mapped to MITRE ATT&CK and ATLAS. Teams can build custom scenarios and link actions into attack paths based on findings; chains can be run manually or autonomously with dedicated agents. Continuous scheduling, indicator enrichment, STIX/TAXII support, reporting, workflow automation, and case management make it suited to recurring validation rather than isolated demonstrations.

The attack surfaces span endpoints, asset groups, people, teams, network hosts, email, phishing pages, SMS, phone-based social engineering, and media pressure. That range lets teams exercise technical and human responses in one platform, but organizations seeking only a narrow technical simulator may not need so much scope.

Exercises, scoring, and integrations

Structured tabletop exercises assess readiness across escalation, coordination, communication, and response. Adversarial Exposure Scoring tracks posture over time and maps coverage to MITRE ATT&CK and domain-based controls, giving teams a way to follow exposure across exercises.

Filigran describes 30+ integrations, including connections to OpenCTI, threat feeds, EDR/XDR, SIEM, and SOC playbooks. Community Edition includes OpenCTI security coverage integration, prepackaged scenarios, Threat Arsenal, atomic testing, tabletop exercises, scoring, CVE findings, alert fetching, and RBAC. Enterprise adds advanced integrations and AI features, along with SSO, full audit logging, data segregation, and advanced role-based access controls.

Pricing

Community Edition

0.00 USD per free, billed Free forever. This on-premise edition includes core attack simulation and tabletop exercises, with community support. It is a practical starting point for teams able to operate their own deployment and accept community rather than vendor support. There is no seat or usage cap stated in the plan terms.

Enterprise Edition

Custom pricing, based on number of instances, instance size, and support services. It is offered as SaaS or on-premise and includes advanced integrations, AI features, and vendor support with SLAs. Enterprise is the relevant option for organizations needing its governance controls or formal support; the 30-day SaaS trial allows teams to explore the platform before committing. Filigran offers standard 8×5 and premium 24×7 support, and includes a customer support portal and dedicated Customer Success Manager.

Platforms

OpenAEV supports API, Linux, self-hosted, and web use. Deployments can be cloud, on-premise, or multi-tenant, with or without an endpoint agent; Enterprise also offers air-gapped and bring-your-own-cloud options. Components are available as Docker images and manual installation packages, with Kubernetes recommended for production. This flexibility serves organizations with varied infrastructure requirements, though the free edition is specifically on-premise.

Who it's for

OpenAEV suits cybersecurity and crisis management teams that want to connect threat-informed technical testing with tabletop response work and ongoing exposure tracking. It is especially compelling where teams need broad attack surfaces, integrations, and governance in one environment. Smaller teams wanting a hosted free tier, or organizations seeking only a focused point tool, may find the on-premise free plan or Enterprise cost structure a poor fit. Filigran says its Enterprise Edition is trusted by governments, financial institutions, and enterprises.

Pros and cons

  • Broad exercise coverage: Technical attack paths and human-facing scenarios, from phishing to media pressure, can be exercised alongside tabletop response.
  • Ongoing posture view: Scoring maps coverage to MITRE ATT&CK and domain-based controls over time, rather than leaving teams with only exercise-by-exercise results.
  • Useful free foundation: Community Edition is free forever and includes core simulations, tabletop exercises, and a substantial set of community capabilities.
  • Deployment flexibility: Cloud, on-premise, multi-tenant, air-gapped, and bring-your-own-cloud options address varied infrastructure needs, but add choices teams must align with their operations.
  • Enterprise cost uncertainty: Custom pricing is tied to instances, size, and support, so buyers need a quote to judge fit; the free edition also requires on-premise deployment and relies on community support.

Alternatives

For threat intelligence rather than combined simulation and crisis exercises, compare Threat Intelligence Platforms. For a closer focus on adversary testing, see Breach and Attack Simulation Software.

IBM X-Force Exchange has a free plan with limited portal access but no X-Force API access, so it is a better fit for basic threat intelligence portal use than for OpenAEV’s exercises. SOCRadar Extended Threat Intelligence Platform offers paid dark web monitoring tiers, including a $600.00 USD per month plan for one domain and one seat; choose it when that monitoring scope matters more than simulation and crisis exercises.

ThreatForge offers a free open-source Community Edition and an Enterprise Edition, while Kaspersky Threat Intelligence Portal, Open Threat Exchange, Threat Intelligence Platform, Yeti, and MISP are alternatives to compare.

Verdict

Choose OpenAEV if your security and crisis teams need threat-led attack validation, tabletop exercises, and exposure tracking in a single platform, and can support an on-premise community deployment or obtain an Enterprise quote. Look elsewhere if you need a free hosted option or a narrowly focused tool with simpler pricing.

OpenAEV plans and pricing

All plans
Community Edition Free Free forever On-premise · core attack simulation and tabletop exercises · community support filigran.io · 29 Sept 2026
Enterprise Edition Not published Quote based on number of instances, instance size and support services SaaS or on-premise · advanced integrations · AI features · vendor support with SLAs filigran.io · 29 Sept 2026

Compared on threat intelligence platforms

Free plan
Yes
Attack simulation modes
hybrid
Included attack surfaces
endpoints, asset groups, people, teams, network hosts, email, phishing landing pages, SMS, phone-based social engineering, media pressure, tabletop exercises
MITRE ATT&CK mapping
Yes
Custom attack scenarios
Yes
Continuous scheduling
Yes
Deployment model
hybrid

Best OpenAEV alternatives

See all 12