MITRE Caldera
MITRE Caldera 是什么?
MITRE CalderaAn open-source adversary emulation platform from MITRE that automates the execution of ATT&CK techniques against a target environment via lightweight agents, supporting red-team operations and detection-engineering exercises.
MITRE Caldera is an open-source automated adversary emulation framework first released by MITRE in 2017. It pairs lightweight agents (Sandcat for Windows/macOS/Linux, plus protocol-specific implants) with a central server that schedules and orchestrates ATT&CK-mapped techniques as 'abilities' grouped into 'adversaries' (playbooks). Operators can launch a known threat profile — for example an APT29 emulation, a ransomware-precursor chain, or a custom plan — and watch ATT&CK techniques execute against agents in a lab or production environment, with results scored and exported. Caldera plug-ins extend it with Atomic Red Team integration, training plug-ins, and specific-OS modules. Compared to commercial breach-and-attack-simulation platforms, Caldera is free, ATT&CK-native, and scriptable, making it the default open-source choice for purple-team exercises, SIEM detection validation, and EDR coverage testing. The project ships ready-made adversary profiles that map to specific ATT&CK techniques and procedures, so defenders can verify detections against a documented threat model.
● 示例
- 01
A purple team runs a Caldera 'APT29 emulation' plan against a staging environment and verifies that the SIEM raises alerts on the expected ATT&CK techniques.
- 02
A detection engineer uses Caldera abilities to repeatedly fire `T1059.001 PowerShell` variations and confirms the EDR rule catches each one.
● 常见问题
MITRE Caldera 是什么?
An open-source adversary emulation platform from MITRE that automates the execution of ATT&CK techniques against a target environment via lightweight agents, supporting red-team operations and detection-engineering exercises. 它属于网络安全的 防御与运营 分类。
MITRE Caldera 是什么意思?
An open-source adversary emulation platform from MITRE that automates the execution of ATT&CK techniques against a target environment via lightweight agents, supporting red-team operations and detection-engineering exercises.
MITRE Caldera 是如何工作的?
MITRE Caldera is an open-source automated adversary emulation framework first released by MITRE in 2017. It pairs lightweight agents (Sandcat for Windows/macOS/Linux, plus protocol-specific implants) with a central server that schedules and orchestrates ATT&CK-mapped techniques as 'abilities' grouped into 'adversaries' (playbooks). Operators can launch a known threat profile — for example an APT29 emulation, a ransomware-precursor chain, or a custom plan — and watch ATT&CK techniques execute against agents in a lab or production environment, with results scored and exported. Caldera plug-ins extend it with Atomic Red Team integration, training plug-ins, and specific-OS modules. Compared to commercial breach-and-attack-simulation platforms, Caldera is free, ATT&CK-native, and scriptable, making it the default open-source choice for purple-team exercises, SIEM detection validation, and EDR coverage testing. The project ships ready-made adversary profiles that map to specific ATT&CK techniques and procedures, so defenders can verify detections against a documented threat model.
如何防御 MITRE Caldera?
针对 MITRE Caldera 的防御通常结合技术控制与运营实践,详见上方完整定义。
MITRE Caldera 还有哪些其他名称?
常见的别称包括: MITRE Caldera, Caldera framework。
● 相关术语
- compliance№ 762
MITRE ATT&CK
由 MITRE 维护、面向全球开放的对手战术与技术知识库,基于真实攻击观察持续更新。
- compliance№ 080
Atomic Red Team
Red Canary 推出的开源测试库,提供细粒度、聚焦的测试用例,模拟单个 MITRE ATT&CK 技术,用以验证检测能力和安全控制。
- defense-ops№ 985
紫队
红蓝公开协作的演练模式,目标是近乎实时地改进检测与响应能力。
- defense-ops№ 1013
红队
进攻方安全团队,通过端到端模拟真实对手来评估组织的检测、遏制和响应能力。
- defense-ops№ 338
检测工程
以代码方式设计、测试、部署并维护安全检测的学科,可对对手技术实现可度量的覆盖率。
- defense-ops№ 1267
威胁狩猎
基于假设的主动搜索,深入遥测数据,发现绕过现有检测的威胁。