Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 763

MITRE Caldera

Was ist MITRE Caldera?

MITRE CalderaAn open-source adversary emulation platform from MITRE that automates the execution of ATT&CK techniques against a target environment via lightweight agents, supporting red-team operations and detection-engineering exercises.


MITRE Caldera is an open-source automated adversary emulation framework first released by MITRE in 2017. It pairs lightweight agents (Sandcat for Windows/macOS/Linux, plus protocol-specific implants) with a central server that schedules and orchestrates ATT&CK-mapped techniques as 'abilities' grouped into 'adversaries' (playbooks). Operators can launch a known threat profile — for example an APT29 emulation, a ransomware-precursor chain, or a custom plan — and watch ATT&CK techniques execute against agents in a lab or production environment, with results scored and exported. Caldera plug-ins extend it with Atomic Red Team integration, training plug-ins, and specific-OS modules. Compared to commercial breach-and-attack-simulation platforms, Caldera is free, ATT&CK-native, and scriptable, making it the default open-source choice for purple-team exercises, SIEM detection validation, and EDR coverage testing. The project ships ready-made adversary profiles that map to specific ATT&CK techniques and procedures, so defenders can verify detections against a documented threat model.

Beispiele

  1. 01

    A purple team runs a Caldera 'APT29 emulation' plan against a staging environment and verifies that the SIEM raises alerts on the expected ATT&CK techniques.

  2. 02

    A detection engineer uses Caldera abilities to repeatedly fire `T1059.001 PowerShell` variations and confirms the EDR rule catches each one.

Häufige Fragen

Was ist MITRE Caldera?

An open-source adversary emulation platform from MITRE that automates the execution of ATT&CK techniques against a target environment via lightweight agents, supporting red-team operations and detection-engineering exercises. Es gehört zur Kategorie Verteidigung und Betrieb der Cybersicherheit.

Was bedeutet MITRE Caldera?

An open-source adversary emulation platform from MITRE that automates the execution of ATT&CK techniques against a target environment via lightweight agents, supporting red-team operations and detection-engineering exercises.

Wie funktioniert MITRE Caldera?

MITRE Caldera is an open-source automated adversary emulation framework first released by MITRE in 2017. It pairs lightweight agents (Sandcat for Windows/macOS/Linux, plus protocol-specific implants) with a central server that schedules and orchestrates ATT&CK-mapped techniques as 'abilities' grouped into 'adversaries' (playbooks). Operators can launch a known threat profile — for example an APT29 emulation, a ransomware-precursor chain, or a custom plan — and watch ATT&CK techniques execute against agents in a lab or production environment, with results scored and exported. Caldera plug-ins extend it with Atomic Red Team integration, training plug-ins, and specific-OS modules. Compared to commercial breach-and-attack-simulation platforms, Caldera is free, ATT&CK-native, and scriptable, making it the default open-source choice for purple-team exercises, SIEM detection validation, and EDR coverage testing. The project ships ready-made adversary profiles that map to specific ATT&CK techniques and procedures, so defenders can verify detections against a documented threat model.

Wie schützt man sich gegen MITRE Caldera?

Schutzmaßnahmen gegen MITRE Caldera kombinieren typischerweise technische Kontrollen und operative Praktiken, wie in der Definition oben beschrieben.

Welche anderen Bezeichnungen gibt es für MITRE Caldera?

Übliche alternative Bezeichnungen: MITRE Caldera, Caldera framework.

Verwandte Begriffe