{"name":"caldera: Automate Adversary Emulation and Red-Team Operations","description":"Caldera is a self-hosted platform for emulating adversary behavior using the MITRE ATT&CK framework. It combines a command-and-control server, web interface, and extensible plugins for security testing and incident response.","github":"https://github.com/apache/caldera","url":"https://osrepos.com/repo/apache-caldera","source":"osrepos.com","sourceDescription":"This repository profile is provided by osrepos.com, an open source repository discovery platform.","repositoryProfile":"https://osrepos.com/repo/apache-caldera","generatedFor":"open source discovery and AI-assisted research","markdown":"https://osrepos.com/repo/apache-caldera.md","json":"https://osrepos.com/repo/apache-caldera.json","topics":["python","cybersecurity","security","automation","adversary-emulation","mitre-attack","red-team"],"keywords":["python","cybersecurity","security","automation","adversary-emulation","mitre-attack","red-team"],"stars":null,"summary":"Caldera is a self-hosted platform for emulating adversary behavior using the MITRE ATT&CK framework. It combines a command-and-control server, web interface, and extensible plugins for security testing and incident response.","content":"## Overview\n\nCaldera helps security teams automate adversary emulation, support manual red-team exercises, and automate incident response. Built around the MITRE ATT&CK framework, its core provides an asynchronous command-and-control server, REST API, and web interface.\n\nPlugins add capabilities such as endpoint agents, ATT&CK technique collections, payload building, reporting, and response workflows. This makes Caldera a platform to assemble for a team's testing needs, rather than a single-purpose scanner.\n\n## Key Features\n\n- Model emulation activities around MITRE ATT&CK techniques.\n- Coordinate operations through an asynchronous command-and-control server.\n- Manage the platform through a REST API and web interface.\n- Extend the core with plugins for agents, TTP collections, reporting, and incident response.\n- Use supported plugins such as Sandcat, Stockpile, Atomic, and Response.\n- Run locally from source or in Docker.\n\n## Use Cases\n\n- Red teams can automate repeatable adversary-emulation exercises and use manual operations where needed.\n- Security validation teams can test defenses against ATT&CK-aligned techniques in a controlled environment.\n- Incident response teams can use the platform's response capabilities to support automated workflows.\n- Training teams can use the included training plugin and its capture-the-flag-style course to introduce operators to Caldera.\n\n## Our Take\n\nCaldera is an actively maintained, extensible choice for teams that need ATT&CK-based emulation, though its security guidance makes deployment in a trusted environment essential.\n\n**Good fit if:**\n- Your team needs adversary emulation or red-team automation organized around MITRE ATT&CK.\n- You can run and administer a Python-based server and select plugins for the capabilities you need.\n- You value an active project with regular commits, contributions from at least 100 contributors, and recent pull request merges.\n\n**Look elsewhere if:**\n- You need a hardened platform intended to be exposed directly to the public internet.\n- You need a recently released version: the project has had no release in over a year.\n- You need a turnkey tool without plugin selection or server setup.\n\n## Project Health\n\n| Signal | Value |\n|---|---|\n| Status | **Active**: regular commits |\n| Last commit | 2026-08-27 (2 months ago) |\n| Commits, last 90 days | 10 |\n| Releases, last 12 months | 0 (latest 5.3.0, 2025-04-24) |\n| Contributors | 100+ (top contributor: 18% of commits) |\n| Issues closed, last 90 days | 3 (typically closed in 50 days) |\n| Pull requests merged, last 90 days | 9 (typically merged in 0 days) |\n| Project age | 8 years |\n\nChecked on 2026-10-11 with the GitHub API.\n\n## Project Facts\n\n- Language: Python\n- License: Apache-2.0\n- Stars: 7.4k\n- Forks: 1.4k\n- Topics: adversary-emulation, caldera, cybersecurity, mitre-attack, red-team, security-automation, security-testing\n- Archived: no\n\n## What You Need\n\nDetected in the repository:\n\n- Node.js (from package.json)\n- Python (from requirements.txt)\n- A Dockerfile, so it can run in a container; a Compose file sets up the related services\n- A test suite and automated checks on GitHub Actions\n\n## Getting Started\n\nThe README recommends a Python virtual environment. For a concise setup, clone with submodules, install requirements, and start the server:\n\n```bash\ngit clone https://github.com/apache/caldera.git --recursive\ncd caldera\npip3 install -r requirements.txt\npython3 server.py --insecure --build\n```\n\nSee the [README](https://github.com/apache/caldera#readme) for full installation, Docker, plugin, and training instructions.\n\n## License in Plain Words\n\n**Apache-2.0** (permissive).\n\n- Commercial use: yes\n- Modify and redistribute: yes\n- You must keep: the license, the NOTICE file and a note of your changes\n- Share your changes: no\n- Includes an explicit patent grant from the contributors\n\nA summary, not legal advice: the LICENSE file is what applies.\n\n## Alternatives\n\n- [openaev](https://osrepos.com/repo/openbas-platform-openbas): OpenAEV focuses on planning and coordinating simulation campaigns, while Caldera emphasizes ATT&CK-based emulation through an extensible command-and-control platform.\n\n| Project | Language | License | Stars | Status |\n|---|---|---|---|---|\n| **caldera** | Python | Apache-2.0 | 7.4k | Active |\n| [openaev](https://osrepos.com/repo/openbas-platform-openbas) | Java | NOASSERTION | 1.8k | Active |\n\n## Considerations\n\nThe project warns against exposing Caldera to the internet: its web interface has basic authentication and security features, and is not described as hardened or thoroughly penetration-tested. The quick-start command uses `--insecure`, so follow the project's security recommendations before deployment. The latest release is over a year old despite ongoing commits, and the core's capabilities depend on plugins. Running the UI build requires Node.js, and the README recommends at least Python 3.10; dynamically compiling Go-based agents additionally requires Go. Docker data is ephemeral by default, and the Builder plugin does not work in Docker.","metrics":{"detailViews":1,"githubClicks":0},"dates":{"published":null,"modified":"2026-10-11T12:13:24.000Z"}}