Ad

Attack Range:Simulate attacks & collect Splunk data

Attack Range builds instrumented cloud environments for attack simulation and data collection into Splunk, facilitating detection development and testing. Quickly deploy labs and simulate real-world attack scenarios.
Screenshot of splunk/attack_range homepage

Attack Range builds instrumented cloud environments (AWS, Azure, GCP) to simulate attacks and forward telemetry to Splunk. It allows security professionals to create controlled environments for testing detection rules and analyzing attack patterns. The project primarily leverages Docker, Terraform, and Ansible for environment orchestration and configuration.

Attack Range offers a flexible, modular architecture, supporting various cloud providers and attack simulation frameworks like Atomic Red Team. The project provides a user-friendly Docker Compose interface for easy deployment and management, alongside a comprehensive REST API for automation. It supports a wide array of templates for diverse attack scenarios.

  • Cloud Provider Support: AWS, Azure, and GCP are supported for environment deployment, offering flexibility in testing various cloud security scenarios.
  • Attack Simulation: Integrates with Atomic Red Team for generating realistic attack telemetry, facilitating detection rule validation.
  • API Access: Provides a comprehensive REST API for automation and integration with other security tools and workflows.

Attack Range is an active project with ongoing development and maintenance. The project has a stable release history, regular commits, and an active community. Comprehensive documentation and a robust issue tracker contribute to its reliability and ease of use. The project benefits from a strong support network within the Splunk security community.

Security analysts, developers, and researchers benefit from Attack Range by providing a platform to test and refine Splunk detection rules, validate security controls, and simulate attack scenarios in a safe and controlled environment. It streamlines the process of building and managing attack simulation labs, reducing manual effort and improving detection effectiveness.

Summarize:
Share:
Stars
2,512
Forks
413
Issues
15
Created
7 years ago
Commit
23 days ago
License
APACHE-2.0
Archived
No
Updated 16 days ago

Similar Repositories