Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 763

MITRE Caldera

Qu'est-ce que MITRE Caldera ?

MITRE CalderaAn open-source adversary emulation platform from MITRE that automates the execution of ATT&CK techniques against a target environment via lightweight agents, supporting red-team operations and detection-engineering exercises.


MITRE Caldera is an open-source automated adversary emulation framework first released by MITRE in 2017. It pairs lightweight agents (Sandcat for Windows/macOS/Linux, plus protocol-specific implants) with a central server that schedules and orchestrates ATT&CK-mapped techniques as 'abilities' grouped into 'adversaries' (playbooks). Operators can launch a known threat profile — for example an APT29 emulation, a ransomware-precursor chain, or a custom plan — and watch ATT&CK techniques execute against agents in a lab or production environment, with results scored and exported. Caldera plug-ins extend it with Atomic Red Team integration, training plug-ins, and specific-OS modules. Compared to commercial breach-and-attack-simulation platforms, Caldera is free, ATT&CK-native, and scriptable, making it the default open-source choice for purple-team exercises, SIEM detection validation, and EDR coverage testing. The project ships ready-made adversary profiles that map to specific ATT&CK techniques and procedures, so defenders can verify detections against a documented threat model.

Exemples

  1. 01

    A purple team runs a Caldera 'APT29 emulation' plan against a staging environment and verifies that the SIEM raises alerts on the expected ATT&CK techniques.

  2. 02

    A detection engineer uses Caldera abilities to repeatedly fire `T1059.001 PowerShell` variations and confirms the EDR rule catches each one.

Questions fréquentes

Qu'est-ce que MITRE Caldera ?

An open-source adversary emulation platform from MITRE that automates the execution of ATT&CK techniques against a target environment via lightweight agents, supporting red-team operations and detection-engineering exercises. Cette notion relève de la catégorie Défense et opérations en cybersécurité.

Que signifie MITRE Caldera ?

An open-source adversary emulation platform from MITRE that automates the execution of ATT&CK techniques against a target environment via lightweight agents, supporting red-team operations and detection-engineering exercises.

Comment fonctionne MITRE Caldera ?

MITRE Caldera is an open-source automated adversary emulation framework first released by MITRE in 2017. It pairs lightweight agents (Sandcat for Windows/macOS/Linux, plus protocol-specific implants) with a central server that schedules and orchestrates ATT&CK-mapped techniques as 'abilities' grouped into 'adversaries' (playbooks). Operators can launch a known threat profile — for example an APT29 emulation, a ransomware-precursor chain, or a custom plan — and watch ATT&CK techniques execute against agents in a lab or production environment, with results scored and exported. Caldera plug-ins extend it with Atomic Red Team integration, training plug-ins, and specific-OS modules. Compared to commercial breach-and-attack-simulation platforms, Caldera is free, ATT&CK-native, and scriptable, making it the default open-source choice for purple-team exercises, SIEM detection validation, and EDR coverage testing. The project ships ready-made adversary profiles that map to specific ATT&CK techniques and procedures, so defenders can verify detections against a documented threat model.

Comment se défendre contre MITRE Caldera ?

Les défenses contre MITRE Caldera combinent habituellement des contrôles techniques et des pratiques opérationnelles, comme détaillé dans la définition ci-dessus.

Quels sont les autres noms de MITRE Caldera ?

Noms alternatifs courants : MITRE Caldera, Caldera framework.

Termes liés