License & Deployment Mix: 10 tools – 4 OSS, 6 commercial.

Color: Purple team.

What Is This Category?

Breach & Attack Simulation (BAS) automates the question “if an attacker did X, would we catch it?”. Instead of one-shot pentests, BAS continuously runs ATT&CK-aligned techniques on production systems and feeds the results back into the SOC: a green/red grid across the ATT&CK matrix showing which TTPs are detected, which slip through, and which are blocked outright.

Distinct from neighbouring categories

The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.

Comparison


Capability Matrix

ToolATT&CK LibraryContinuousCloud-SideEndpointChained Attacks
MITRE Calderayespartialyesyes (planner)
Atomic Red Teamyesyes
Infection Monkeypartialyesyes (self-spread)
Stratus Red Teamyesyespartial
Cymulateyesyesyesyespartial
SafeBreachyes (30K)yespartialyespartial
AttackIQyesyespartialyespartial
Picus Securityyesyespartialyespartial
Penterayesyesyesyes (chained-attack engine)
Cobalt Icebergyesyesyespartial

License Comparison

ToolLicenseOSIType
MITRE CalderaApache-2.0yesOSS platform
Atomic Red TeamMITyesOSS test library
Infection MonkeyGPL-3.0-onlyyesOSS breach simulator
Stratus Red TeamApache-2.0yesOSS cloud BAS
CymulateProprietaryCommercial SaaS
SafeBreachProprietaryCommercial SaaS
AttackIQProprietaryCommercial SaaS
Picus SecurityProprietaryCommercial SaaS
PenteraProprietaryCommercial SaaS
Cobalt IcebergProprietaryCommercial SaaS

Composition Patterns

1. OSS-only purple-team practice

MITRE Caldera -- orchestration platform
Atomic Red Team -- test-library content
Stratus Red Team -- cloud-side BAS for AWS / Azure / GCP
Infection Monkey -- holistic lateral-movement testing
+ SIEM under test -- validate detection

Output: full purple-team BAS at zero license cost.

2. Customer-managed commercial BAS

Cymulate (or SafeBreach, AttackIQ, Picus)

Output: managed delivery; continuous-validation heatmaps; per-detection-gap remediation playbooks.

3. Autonomous-pentest tier

Pentera -- chained-attack engine (more pentest than BAS)
+ Caldera/ART -- specific-technique BAS alongside

Output: realistic chained-attack simulation complementing isolated-technique BAS.


Cost Tier

Annual TCO for a 1000-user customer environment.

TierToolingApprox Cost
FreeCaldera + ART + Stratus + Infection Monkey$0 + operator time
MidCymulate / SafeBreach / AttackIQ / Picus$50,000-150,000 / year
HighPentera (autonomous-pentest tier)$100,000-300,000 / year

Tools

10 tools.

Atomic Red Team

Red Canary’s open-source library of small portable ATT&CK-aligned tests; the canonical OSS BAS reference content.

License: MIT (OSS) · Kind: library · Deploy: native, package · SSO: none

Website · Source

AttackIQ

Commercial BAS platform; FlexECT cloud-based scenario engine; one of the three established BAS market leaders.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML

Website

Cobalt Iceberg

Cobalt.io’s continuous-pentest tier; blends PtaaS marketplace with BAS-style scheduled / continuous testing.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML

Website

Cymulate

Commercial BAS / continuous threat-exposure-management platform; Israeli vendor; one of the three established BAS leaders.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML

Website

Infection Monkey

Open-source automated breach-and-attack simulation tool from Akamai (acquired Guardicore); tests lateral-movement defences by spreading through the network.

License: GPL-3.0-only (OSS) · Kind: service · Deploy: docker, native · SSO: OIDC

Website · Source

MITRE Caldera

MITRE’s automated adversary emulation platform; ATT&CK-aligned, plugin-driven, the canonical OSS BAS framework.

License: Apache-2.0 (OSS) · Kind: web · Deploy: docker, native · SSO: OIDC, SAML

Website · Source

Pentera

Israeli commercial autonomous-pentest / BAS platform; chained-attack engine; stronger autonomous-pentest positioning than the Cymulate / SafeBreach trio.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML

Website

Picus Security

Turkish commercial BAS / CTEM platform; broad ATT&CK coverage + remediation playbook depth; growing European presence.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML

Website

SafeBreach

SafeBreach is a commercial breach and attack simulation platform whose Hacker’s Playbook offers 30,000+ curated attack scenarios mapped to MITRE ATT&CK, run via a SaaS console with on-prem simulators.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML

Website

Stratus Red Team

DataDog’s cloud-native attack-emulation library; ATT&CK-aligned techniques executed directly against AWS / Azure / GCP / Kubernetes accounts.

License: Apache-2.0 (OSS) · Kind: cli · Deploy: native, docker, package · SSO: none

Website · Source

ResorsIT Tools Catalog Search