Verified tool intelligence

    Adversary Emulation Security Tools

    Curated adversary emulation security tools with verified sources, capabilities, limitations, safe lab examples, and professional assessment guidance. Every profile separates official facts, editorial analysis, safe validation, and operational limitations.

    $ catalog --status
    18
    profiles
    9
    clusters
    last editorial pass: 2026-07-20

    category briefing

    How Adversary Emulation tools fit into professional testing

    Adversary-emulation tools reproduce defined techniques to validate prevention, telemetry, and response under controlled conditions. They require explicit objectives, stopping conditions, cleanup steps, and coordination with system owners.

    Selection criteria: Compare technique coverage, safety controls, auditability, cleanup support, agent trust, and how clearly actions map to defensive outcomes.

    common_use_cases[]

    • 01Detection-control validation
    • 02Known vulnerability reproduction
    • 03Purple-team exercises

    Verified sources

    Profiles lead with official projects, repositories, and documentation rather than copied release descriptions.

    Professional context

    Capabilities are balanced with limitations, evidence requirements, and defensive interpretation.

    Authorized research

    Examples use local labs, reserved addresses, or non-operational documentation commands.