License & Deployment Mix: 10 tools – 4 OSS, 6 commercial.
Color: Purple team.
What Is This Category?
Breach & Attack Simulation (BAS) automates the question “if an attacker did X, would we catch it?”. Instead of one-shot pentests, BAS continuously runs ATT&CK-aligned techniques on production systems and feeds the results back into the SOC: a green/red grid across the ATT&CK matrix showing which TTPs are detected, which slip through, and which are blocked outright.
Distinct from neighbouring categories
- Vulnerability Management – VM finds exposures; BAS tests whether the defensive response would work
- Reconnaissance & Asset Discovery – recon maps assets; BAS exercises defences against assumed-compromise behaviour
- SOAR – SOAR runs response playbooks; BAS tests whether those playbooks fire when they should
- Offensive Frameworks (Exploit / C2) – offensive frameworks are operator-driven against engagement targets; BAS is automated / scheduled / vendor-curated content
The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.
Comparison
Capability Matrix
| Tool | ATT&CK Library | Continuous | Cloud-Side | Endpoint | Chained Attacks |
|---|---|---|---|---|---|
| MITRE Caldera | yes | partial | – | yes | yes (planner) |
| Atomic Red Team | yes | – | – | yes | – |
| Infection Monkey | partial | – | – | yes | yes (self-spread) |
| Stratus Red Team | yes | – | yes | – | partial |
| Cymulate | yes | yes | yes | yes | partial |
| SafeBreach | yes (30K) | yes | partial | yes | partial |
| AttackIQ | yes | yes | partial | yes | partial |
| Picus Security | yes | yes | partial | yes | partial |
| Pentera | yes | yes | – | yes | yes (chained-attack engine) |
| Cobalt Iceberg | yes | yes | yes | partial | – |
License Comparison
| Tool | License | OSI | Type |
|---|---|---|---|
| MITRE Caldera | Apache-2.0 | yes | OSS platform |
| Atomic Red Team | MIT | yes | OSS test library |
| Infection Monkey | GPL-3.0-only | yes | OSS breach simulator |
| Stratus Red Team | Apache-2.0 | yes | OSS cloud BAS |
| Cymulate | Proprietary | – | Commercial SaaS |
| SafeBreach | Proprietary | – | Commercial SaaS |
| AttackIQ | Proprietary | – | Commercial SaaS |
| Picus Security | Proprietary | – | Commercial SaaS |
| Pentera | Proprietary | – | Commercial SaaS |
| Cobalt Iceberg | Proprietary | – | Commercial SaaS |
Composition Patterns
1. OSS-only purple-team practice
MITRE Caldera -- orchestration platform
Atomic Red Team -- test-library content
Stratus Red Team -- cloud-side BAS for AWS / Azure / GCP
Infection Monkey -- holistic lateral-movement testing
+ SIEM under test -- validate detectionOutput: full purple-team BAS at zero license cost.
2. Customer-managed commercial BAS
Cymulate (or SafeBreach, AttackIQ, Picus)
Output: managed delivery; continuous-validation heatmaps; per-detection-gap remediation playbooks.
3. Autonomous-pentest tier
Pentera -- chained-attack engine (more pentest than BAS)
+ Caldera/ART -- specific-technique BAS alongsideOutput: realistic chained-attack simulation complementing isolated-technique BAS.
Cost Tier
Annual TCO for a 1000-user customer environment.
| Tier | Tooling | Approx Cost |
|---|---|---|
| Free | Caldera + ART + Stratus + Infection Monkey | $0 + operator time |
| Mid | Cymulate / SafeBreach / AttackIQ / Picus | $50,000-150,000 / year |
| High | Pentera (autonomous-pentest tier) | $100,000-300,000 / year |
Tools
10 tools.
Atomic Red Team
Red Canary’s open-source library of small portable ATT&CK-aligned tests; the canonical OSS BAS reference content.
License: MIT (OSS) · Kind: library · Deploy: native, package · SSO: none
AttackIQ
Commercial BAS platform; FlexECT cloud-based scenario engine; one of the three established BAS market leaders.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
Cobalt Iceberg
Cobalt.io’s continuous-pentest tier; blends PtaaS marketplace with BAS-style scheduled / continuous testing.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML
Cymulate
Commercial BAS / continuous threat-exposure-management platform; Israeli vendor; one of the three established BAS leaders.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
Infection Monkey
Open-source automated breach-and-attack simulation tool from Akamai (acquired Guardicore); tests lateral-movement defences by spreading through the network.
License: GPL-3.0-only (OSS) · Kind: service · Deploy: docker, native · SSO: OIDC
MITRE Caldera
MITRE’s automated adversary emulation platform; ATT&CK-aligned, plugin-driven, the canonical OSS BAS framework.
License: Apache-2.0 (OSS) · Kind: web · Deploy: docker, native · SSO: OIDC, SAML
Pentera
Israeli commercial autonomous-pentest / BAS platform; chained-attack engine; stronger autonomous-pentest positioning than the Cymulate / SafeBreach trio.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
Picus Security
Turkish commercial BAS / CTEM platform; broad ATT&CK coverage + remediation playbook depth; growing European presence.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
SafeBreach
SafeBreach is a commercial breach and attack simulation platform whose Hacker’s Playbook offers 30,000+ curated attack scenarios mapped to MITRE ATT&CK, run via a SaaS console with on-prem simulators.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
Stratus Red Team
DataDog’s cloud-native attack-emulation library; ATT&CK-aligned techniques executed directly against AWS / Azure / GCP / Kubernetes accounts.
License: Apache-2.0 (OSS) · Kind: cli · Deploy: native, docker, package · SSO: none