Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
RedTeamSimmer — Web-based adversary emulation platform that orchestrates Atomic Red Team tests across Windows endpoints via Go agents, with MITRE ATT&CK mapping, APT emulation plans, and detection rule correlation. | Kitploit
Tools/GitHubGitHub/breachsimrange/redteamsimmer
Defensive ToolsPenetration Testing FrameworksScripting & AutomationPenetration TestingCommand and ControlThreat IntelligenceLearning & EducationRed TeamingAdversarial Attack

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Labs & Practice
GitHubbreachsimrange/redteamsimmer

RedTeamSimmer

Web-based adversary emulation platform that orchestrates Atomic Red Team tests across Windows endpoints via Go agents, with MITRE ATT&CK mapping, APT emulation plans, and detection rule correlation.

View Repository
811327 days agoNot yet reviewed
Share

RedTeamSimmer Logo

RedTeamSimmer

The UI You've Always Wanted for Atomic Red Team
A Web Based Adversary Emulation Platform and Atomic Red Team Test Orchestration.

Version License MITRE ATT&CK v19.1 Python 3.9+ Go 1.19+ Stars X


Overview

RedTeamSimmer is an open-source, web based adversary emulation platform providing a modern UI for orchestrating Atomic Red Team tests across enterprise Windows environments. It was initially created for 'Mastering Breach and Adversarial Attack Simulation' training at DEF CON Trainings. Traditional atomic tests execution demands memorizing PowerShell syntax, manually managing prerequisites per endpoint, and collecting scattered results with no centralized visibility. RedTeamSimmer solves this with a Flask server, lightweight Golang agents, and a real-time web interface enabling security teams to execute MITRE ATT&CK mapped techniques in few clicks. Operators deploy agents to multiple endpoints, browse the full ATT&CK catalog, run tests with automatic prerequisite handling, and monitor live color-coded output from a single dashboard.

RedTeamSimmer bridges the gap between complex adversary emulation tooling and practical usability - giving you the power of Atomic Red Team with a clean, intuitive interface.

It also ships with adversary emulation plans modelled using Atomic Red Team for real threat actors including APT28, APT3, APT41, FIN7, Lazarus Group, and Wizard Spider for multi-stage attack simulations. Detection rule mappings for Sigma, Splunk, and Elastic Security help blue teams identify coverage gaps and validate alerting. A full operations history provides a complete audit trail for compliance. Designed for red teamers, blue teamers, purple team exercises, EDR/AV testing, and training.

RedTeamSimmer is created and maintained by the BreachSimRange team. The original RedTeamSimmer was created by @abhijithbr.


DEF CON Singapore Demo Labs 2026

RedTeamSimmer was first publicly presented at DEF CON Singapore Demo Labs 2026. The Demo Labs showcase was used to demonstrate the platform's adversary emulation capabilities, live atomic test execution to the security community.


Features

MITRE ATT&CK Integration

RedTeamSimmer organizes all atomic tests by MITRE ATT&CK tactics, making it easy to navigate and select techniques for execution.

  • Tactic-Based Navigation - Tests are grouped under their respective MITRE ATT&CK v19 tactics (Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Defense Impairment, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, Impact). v19 (April 2026) split the legacy Defense Evasion tactic into Stealth (TA0005) and Defense Impairment (TA0112) - see docs/UPDATES.md for the full migration notes.
  • Technique Details - View full technique descriptions, supported platforms, executor types, and elevation requirements before execution
  • Sub-Technique Support - Properly handles sub-techniques (e.g., T1059.001 PowerShell under T1059 Command and Scripting Interpreter)
  • ATT&CK Links - Direct links to MITRE ATT&CK documentation for each technique

Multi-Agent Architecture

Deploy lightweight agents on target systems and orchestrate test execution remotely from the central server.

  • Go-Based Agent - Compiled, standalone binary with no external dependencies
  • Agent Registration - Agents automatically register with the server and report system information (hostname, username, OS, architecture)
  • AV Detection - Agents detect 60+ antivirus/EDR products including CrowdStrike, SentinelOne, Carbon Black, Defender, and more
  • Configurable Polling - Adjustable poll intervals and jitter timing for stealth
  • Startup Persistence - Optional persistence via registry, scheduled tasks, or startup folder
  • Remote Shutdown - Clean agent removal with full artifact cleanup

Note: Currently only Windows agents are fully supported. Linux/macOS agent support is planned for future releases.

Live Execution Output

Test output streams in real time as the agent executes, not after completion, so you can watch prerequisites run, the main command fire, and cleanup trigger as it happens. Output types - stdout, stderr, and agent messages - can be toggled independently to cut noise. Each test phase is separated by decorative log banners, timed individually, and the exit code surfaces immediately on completion.

Prerequisite Management

Atomic tests often need tools or files in place before they execute. RedTeamSimmer parses the YAML test definition, runs the prereq_command to check whether dependencies are already satisfied, and if not, runs get_prereq_command to install them. A re-verification step confirms the prerequisites are in place before the main command fires. If you want to skip this - for example when you have already staged the target - the UI exposes a manual override to run the test directly.

Threat Actor Emulation Plans

RedTeamSimmer ships with pre-built emulation plans modelled on real-world APT tradecraft. Each plan chains together Atomic Red Team tests mapped to the techniques documented in the corresponding MITRE ATT&CK group profile, so you execute the actor's kill chain in sequence rather than running isolated techniques. Plans are JSON-defined, fully editable, and extensible - you can modify ordering, add or remove techniques, or build your own from scratch using the custom plan builder.

Included Plans:

Threat ActorOriginFocus
APT28 (Fancy Bear)Russia - GRU Unit 26165Government espionage, election interference, credential harvesting
APT3 (Gothic Panda)China - MSSAerospace, defence, and telecom targeting
APT41 (Wicked Panda)China - dual-useHybrid espionage and financially motivated intrusions
FIN7 (Carbanak)Financially motivated (eCrime)POS malware, retail and hospitality breach patterns
Lazarus GroupNorth Korea - RGBFinancial theft, destructive attacks, cryptocurrency operations
Wizard SpiderFinancially motivated (eCrime)Ryuk/Conti ransomware kill chains, credential access, lateral movement
Download Tool