Skip to main content

Caldera

Open-source adversary emulation and breach simulation platform built on MITRE ATT&CK with autonomous and manual operation modes.

Technical Architecture & Overview

Caldera is an open-source adversary emulation and breach-and-attack simulation platform. It is built on the MITRE ATT&CK framework and automates the execution of adversary behaviors to test and validate defensive controls. The platform includes a decision engine, an agent called Sandcat, and plugins that support autonomous operations, manual red-team exercises, and automated incident response. It is maintained by the Apache Caldera project and originated at MITRE with support from the National Science Foundation.

Targeted Technical Use Cases

Run autonomous or operator-guided adversary emulation campaigns, validate EDR and SIEM coverage against ATT&CK techniques, and conduct purple-team exercises with repeatable scenarios.

Evaluation & Trade-offs

Core Strengths

  • +ATT&CK-aligned atomic and adversary profiles for structured emulation.
  • +Autonomous operation with a plugin architecture for custom workflows.
  • +Open-source with active community and documentation.

Trade-Offs & Limitations

  • -Server deployment is limited to Linux and macOS.
  • -Requires Python, Node.js, and Go toolchain for some features.
  • -Learning curve for writing custom adversary profiles and plugins.

Defensive Security Application

Simulate known adversary techniques in a controlled manner to test detection logic, tune behavioral rules, and confirm that incident response playbooks trigger as expected.

Frequently Asked Questions

What is Caldera?

Caldera is an open-source adversary emulation and breach-and-attack simulation platform. It is built on the MITRE ATT&CK framework and automates the execution of adversary behaviors to test and validate defensive controls. The platform includes a decision engine, an agent called Sandcat, and plugins that support autonomous operations, manual red-team exercises, and automated incident response. It is maintained by the Apache Caldera project and originated at MITRE with support from the National Science Foundation.

What is Caldera used for?

Run autonomous or operator-guided adversary emulation campaigns, validate EDR and SIEM coverage against ATT&CK techniques, and conduct purple-team exercises with repeatable scenarios.

What are the strengths of Caldera?
  • +ATT&CK-aligned atomic and adversary profiles for structured emulation.
  • +Autonomous operation with a plugin architecture for custom workflows.
  • +Open-source with active community and documentation.
What are the limitations of Caldera?
  • +Server deployment is limited to Linux and macOS.
  • +Requires Python, Node.js, and Go toolchain for some features.
  • +Learning curve for writing custom adversary profiles and plugins.
How is Caldera used defensively?

Simulate known adversary techniques in a controlled manner to test detection logic, tune behavioral rules, and confirm that incident response playbooks trigger as expected.