Our take
Activeregular commits- Activity
- 35
- Community
- 92
- Issues
- 39
- Pull requests
- 65
- More contributors than 77% of the projects we track
Caldera is an actively maintained, extensible choice for teams that need ATT&CK-based emulation, though its security guidance makes deployment in a trusted environment essential.
Good fit if
- Your team needs adversary emulation or red-team automation organized around MITRE ATT&CK.
- You can run and administer a Python-based server and select plugins for the capabilities you need.
- You value an active project with regular commits, contributions from at least 100 contributors, and recent pull request merges.
Look elsewhere if
- You need a hardened platform intended to be exposed directly to the public internet.
- You need a recently released version: the project has had no release in over a year.
- You need a turnkey tool without plugin selection or server setup.
All health signals
| Last commit | 2026-08-27 (2 months ago) |
|---|---|
| Commits, last 90 days | 10 |
| Releases, last 12 months | 0 (latest 5.3.0, 2025-04-24) |
| Contributors | 100+ (top contributor: 18% of commits) |
| Issues closed, last 90 days | 3 (typically closed in 50 days) |
| Pull requests merged, last 90 days | 9 (typically merged in 0 days) |
| Project age | 8 years |
Checked on 2026-10-11 with the GitHub API.
Overview
Caldera helps security teams automate adversary emulation, support manual red-team exercises, and automate incident response. Built around the MITRE ATT&CK framework, its core provides an asynchronous command-and-control server, REST API, and web interface.
Plugins add capabilities such as endpoint agents, ATT&CK technique collections, payload building, reporting, and response workflows. This makes Caldera a platform to assemble for a team's testing needs, rather than a single-purpose scanner.
Key Features
- Model emulation activities around MITRE ATT&CK techniques.
- Coordinate operations through an asynchronous command-and-control server.
- Manage the platform through a REST API and web interface.
- Extend the core with plugins for agents, TTP collections, reporting, and incident response.
- Use supported plugins such as Sandcat, Stockpile, Atomic, and Response.
- Run locally from source or in Docker.
Use Cases
- Red teams can automate repeatable adversary-emulation exercises and use manual operations where needed.
- Security validation teams can test defenses against ATT&CK-aligned techniques in a controlled environment.
- Incident response teams can use the platform's response capabilities to support automated workflows.
- Training teams can use the included training plugin and its capture-the-flag-style course to introduce operators to Caldera.
What you need
Detected in the repository
- Node.js (from package.json)
- Python (from requirements.txt)
- A Dockerfile, so it can run in a container; a Compose file sets up the related services
- A test suite and automated checks on GitHub Actions
License in plain words
Apache-2.0permissive
- Commercial use: yes
- Modify and redistribute: yes
- You must keep: the license, the NOTICE file and a note of your changes
- Share your changes: no
- Includes an explicit patent grant from the contributors:
A summary, not legal advice: the LICENSE file is what applies.
Getting Started
The README recommends a Python virtual environment. For a concise setup, clone with submodules, install requirements, and start the server:
git clone https://github.com/apache/caldera.git --recursive
cd caldera
pip3 install -r requirements.txt
python3 server.py --insecure --build
See the README for full installation, Docker, plugin, and training instructions.
Alternatives
- openaev: OpenAEV focuses on planning and coordinating simulation campaigns, while Caldera emphasizes ATT&CK-based emulation through an extensible command-and-control platform.
| Project | Language | License | Stars | Status |
|---|---|---|---|---|
| caldera | Python | Apache-2.0 | 7.4k | Active |
| openaev | Java | Other | 1.8k | Active |
Considerations
The project warns against exposing Caldera to the internet: its web interface has basic authentication and security features, and is not described as hardened or thoroughly penetration-tested. The quick-start command uses --insecure, so follow the project's security recommendations before deployment. The latest release is over a year old despite ongoing commits, and the core's capabilities depend on plugins. Running the UI build requires Node.js, and the README recommends at least Python 3.10; dynamically compiling Go-based agents additionally requires Go. Docker data is ephemeral by default, and the Builder plugin does not work in Docker.
Found this useful?
Share it with someone who would like caldera.