
Web-based adversary emulation platform that orchestrates Atomic Red Team tests across Windows endpoints via Go agents, with MITRE ATT&CK mapping, APT emulation plans, and detection rule correlation.
The UI You've Always Wanted for Atomic Red Team
A Web Based Adversary Emulation Platform and Atomic Red Team Test Orchestration.
RedTeamSimmer is an open-source, web based adversary emulation platform providing a modern UI for orchestrating Atomic Red Team tests across enterprise Windows environments. It was initially created for 'Mastering Breach and Adversarial Attack Simulation' training at DEF CON Trainings. Traditional atomic tests execution demands memorizing PowerShell syntax, manually managing prerequisites per endpoint, and collecting scattered results with no centralized visibility. RedTeamSimmer solves this with a Flask server, lightweight Golang agents, and a real-time web interface enabling security teams to execute MITRE ATT&CK mapped techniques in few clicks. Operators deploy agents to multiple endpoints, browse the full ATT&CK catalog, run tests with automatic prerequisite handling, and monitor live color-coded output from a single dashboard.
RedTeamSimmer bridges the gap between complex adversary emulation tooling and practical usability - giving you the power of Atomic Red Team with a clean, intuitive interface.
It also ships with adversary emulation plans modelled using Atomic Red Team for real threat actors including APT28, APT3, APT41, FIN7, Lazarus Group, and Wizard Spider for multi-stage attack simulations. Detection rule mappings for Sigma, Splunk, and Elastic Security help blue teams identify coverage gaps and validate alerting. A full operations history provides a complete audit trail for compliance. Designed for red teamers, blue teamers, purple team exercises, EDR/AV testing, and training.
RedTeamSimmer is created and maintained by the BreachSimRange team. The original RedTeamSimmer was created by @abhijithbr.
RedTeamSimmer was first publicly presented at DEF CON Singapore Demo Labs 2026. The Demo Labs showcase was used to demonstrate the platform's adversary emulation capabilities, live atomic test execution to the security community.
RedTeamSimmer organizes all atomic tests by MITRE ATT&CK tactics, making it easy to navigate and select techniques for execution.
Deploy lightweight agents on target systems and orchestrate test execution remotely from the central server.
Note: Currently only Windows agents are fully supported. Linux/macOS agent support is planned for future releases.
Test output streams in real time as the agent executes, not after completion, so you can watch prerequisites run, the main command fire, and cleanup trigger as it happens. Output types - stdout, stderr, and agent messages - can be toggled independently to cut noise. Each test phase is separated by decorative log banners, timed individually, and the exit code surfaces immediately on completion.
Atomic tests often need tools or files in place before they execute. RedTeamSimmer parses the YAML test definition, runs the prereq_command to check whether dependencies are already satisfied, and if not, runs get_prereq_command to install them. A re-verification step confirms the prerequisites are in place before the main command fires. If you want to skip this - for example when you have already staged the target - the UI exposes a manual override to run the test directly.
RedTeamSimmer ships with pre-built emulation plans modelled on real-world APT tradecraft. Each plan chains together Atomic Red Team tests mapped to the techniques documented in the corresponding MITRE ATT&CK group profile, so you execute the actor's kill chain in sequence rather than running isolated techniques. Plans are JSON-defined, fully editable, and extensible - you can modify ordering, add or remove techniques, or build your own from scratch using the custom plan builder.
Included Plans:
| Threat Actor | Origin | Focus |
|---|---|---|
| APT28 (Fancy Bear) | Russia - GRU Unit 26165 | Government espionage, election interference, credential harvesting |
| APT3 (Gothic Panda) | China - MSS | Aerospace, defence, and telecom targeting |
| APT41 (Wicked Panda) | China - dual-use | Hybrid espionage and financially motivated intrusions |
| FIN7 (Carbanak) | Financially motivated (eCrime) | POS malware, retail and hospitality breach patterns |
| Lazarus Group | North Korea - RGB | Financial theft, destructive attacks, cryptocurrency operations |
| Wizard Spider | Financially motivated (eCrime) | Ryuk/Conti ransomware kill chains, credential access, lateral movement |