MITRE Caldera
What is MITRE Caldera?
MITRE CalderaAn open-source adversary emulation platform from MITRE that automates the execution of ATT&CK techniques against a target environment via lightweight agents, supporting red-team operations and detection-engineering exercises.
MITRE Caldera is an open-source automated adversary emulation framework first released by MITRE in 2017. It pairs lightweight agents (Sandcat for Windows/macOS/Linux, plus protocol-specific implants) with a central server that schedules and orchestrates ATT&CK-mapped techniques as 'abilities' grouped into 'adversaries' (playbooks). Operators can launch a known threat profile — for example an APT29 emulation, a ransomware-precursor chain, or a custom plan — and watch ATT&CK techniques execute against agents in a lab or production environment, with results scored and exported. Caldera plug-ins extend it with Atomic Red Team integration, training plug-ins, and specific-OS modules. Compared to commercial breach-and-attack-simulation platforms, Caldera is free, ATT&CK-native, and scriptable, making it the default open-source choice for purple-team exercises, SIEM detection validation, and EDR coverage testing. The project ships ready-made adversary profiles that map to specific ATT&CK techniques and procedures, so defenders can verify detections against a documented threat model.
● Examples
- 01
A purple team runs a Caldera 'APT29 emulation' plan against a staging environment and verifies that the SIEM raises alerts on the expected ATT&CK techniques.
- 02
A detection engineer uses Caldera abilities to repeatedly fire `T1059.001 PowerShell` variations and confirms the EDR rule catches each one.
● Frequently asked questions
What is MITRE Caldera?
An open-source adversary emulation platform from MITRE that automates the execution of ATT&CK techniques against a target environment via lightweight agents, supporting red-team operations and detection-engineering exercises. It belongs to the Defense & Operations category of cybersecurity.
What does MITRE Caldera mean?
An open-source adversary emulation platform from MITRE that automates the execution of ATT&CK techniques against a target environment via lightweight agents, supporting red-team operations and detection-engineering exercises.
How does MITRE Caldera work?
MITRE Caldera is an open-source automated adversary emulation framework first released by MITRE in 2017. It pairs lightweight agents (Sandcat for Windows/macOS/Linux, plus protocol-specific implants) with a central server that schedules and orchestrates ATT&CK-mapped techniques as 'abilities' grouped into 'adversaries' (playbooks). Operators can launch a known threat profile — for example an APT29 emulation, a ransomware-precursor chain, or a custom plan — and watch ATT&CK techniques execute against agents in a lab or production environment, with results scored and exported. Caldera plug-ins extend it with Atomic Red Team integration, training plug-ins, and specific-OS modules. Compared to commercial breach-and-attack-simulation platforms, Caldera is free, ATT&CK-native, and scriptable, making it the default open-source choice for purple-team exercises, SIEM detection validation, and EDR coverage testing. The project ships ready-made adversary profiles that map to specific ATT&CK techniques and procedures, so defenders can verify detections against a documented threat model.
How do you defend against MITRE Caldera?
Defences for MITRE Caldera typically combine technical controls and operational practices, as detailed in the full definition above.
What are other names for MITRE Caldera?
Common alternative names include: MITRE Caldera, Caldera framework.
● Related terms
- compliance№ 762
MITRE ATT&CK
A globally accessible knowledge base of adversary tactics and techniques observed in real-world attacks, maintained by MITRE.
- compliance№ 080
Atomic Red Team
An open-source library of small, focused tests created by Red Canary that emulates individual MITRE ATT&CK techniques to validate detections and security controls.
- defense-ops№ 985
Purple Team
A collaborative engagement model in which red and blue teams work openly together to improve detection and response in near real time.
- defense-ops№ 1013
Red Team
An offensive security group that emulates real adversaries end-to-end to test how an organization detects, contains, and responds to attacks.
- defense-ops№ 338
Detection Engineering
The discipline of designing, testing, deploying, and maintaining security detections as code, with measurable coverage of adversary techniques.
- defense-ops№ 1267
Threat Hunting
Proactive, hypothesis-driven search through telemetry to uncover threats that have evaded existing detections.