Zur Hauptnavigation wechseln Zur Suche wechseln Zum Hauptinhalt wechseln

Red Team Redemption: A Structured Comparison of Open-Source Tools for Adversary Emulation

    Publikation: Beitrag in Buch oder TagungsbandVortrag mit Beitrag in TagungsbandBegutachtung

    Abstract

    Red teams simulate adversaries and conduct sophisticated attacks against defenders without informing them about used tactics in advance. These interactive cyber exercises are highly beneficial to assess and improve the security posture of organizations, detect vulnerabilities, and train employees. Unfortunately, they are also time-consuming and expensive, which often limits their scale or prevents them entirely. To address this situation, adversary emulation tools partially automate attacker behavior and enable fast, continuous, and repeatable security testing even when involved personnel lacks red teaming experience. Currently, a wide range of tools designed for specific use-cases and requirements exist. To obtain an overview of these solutions, we conduct a review and structured comparison of nine open-source adversary emulation tools. To this end, we assemble a questionnaire with 80 questions addressing relevant aspects, including setup, support, documentation, usability, and technical features. In addition, we conduct a user study with domain experts to investigate the importance of these aspects for distinct user roles. Based on the evaluation and user feedback, we rank the tools and find MITRE Caldera, Metasploit, and Atomic Red Team on top.
    OriginalspracheEnglisch
    TitelProceedings of the 2024 IEEE 23rd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)
    Seiten117-128
    Seitenumfang12
    ISBN (elektronisch)979-8-3315-0620-9
    DOIs
    PublikationsstatusVeröffentlicht - 4 Apr. 2025
    Veranstaltung2024 IEEE 23rd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) - Sanya, Sanya, China
    Dauer: 17 Dez. 202421 Dez. 2024

    Publikationsreihe

    NameIeee International Conference On Trust Security And Privacy In Computing And Communications

    Konferenz

    Konferenz2024 IEEE 23rd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)
    KurztitelTrustCom- 2024
    Land/GebietChina
    StadtSanya
    Zeitraum17/12/2421/12/24

    Research Field

    • Cyber Security

    Fingerprint

    Untersuchen Sie die Forschungsthemen von „Red Team Redemption: A Structured Comparison of Open-Source Tools for Adversary Emulation“. Zusammen bilden sie einen einzigartigen Fingerprint.

    Diese Publikation zitieren