Purple Team Arsenal Tool List
The following is a complete list of Purple Team tools as posted in my Cyber Security Arsenal Catalog organized in a simple and logical way to make it easier to navigate.
Every Index node will take you the tool section. Every tool will also be linked to another Complete Command Reference post for the given tool, where you can learn how to use it fully.
I hope you enjoy.
Index
Breach & Attack Simulation (BAS)
Adversary emulation
Detection engineering
Collaboration & reporting
Threat intelligence integration
Control validation & continuous testing
Purple Team Complete Tool List
Breach & Attack Simulation (BAS)
- AttackIQ
- AttackSim
- Cymulate
- Cymulate BAS packs
- Infection Monkey
- OpenBAS
- Picus Security
- Prelude Operator
- SafeBreach
- SCYTHE
- Verodin (legacy)
- XM Cyber
Adversary emulation
- APTSimulator
- Atomic Red Team
- ATT&CK Evaluations methodologies
- CALDERA abilities packs
- Covenant adversary profiles
- DumpsterFire
- FlightSim
- Invoke-Adversary
- Invoke-AtomicRedTeam
- Metta
- MITRE Caldera
- Red Canary Atomic Test Harness
- Stratus Red Team
- Uber METL
Detection engineering
- ATT&CK mapping tools
- Chainsaw
- Chronicle YARA-L
- contentctl (Splunk)
- Detection-as-Code repos
- Elastic Detection Rules
- EQL / KQL helpers
- Fleet policies as detection
- Hayabusa
- osquery packs
- Panther
- Sigma / Sigma CLI / pySigma
- Snort rule management
- Splunk ESCU
- Suricata rule management
- Uncoder.io
- Wazuh / OSSEC rulesets
- YARA / YARA Forge
- Zircolite
Collaboration & reporting
- AttackForge
- AttackerKB
- Confluence playbooks
- DefectDojo (findings mgmt)
- Dradis
- Faraday
- Ghostwriter
- Git engagement repos
- Jira / ServiceNow SecOps
- Obsidian / Markdown templates
- PenTest.ws
- PlexTrac
- Reconmap
- Serpico
- SysReptor
- TheHive
- Vectr
- WriteHat
Threat intelligence integration
- ATT&CK Navigator
- ATT&CK Workbench
- MISP automation
- MISP-modules
- n8n / Shuffle enrichment
- OpenCTI connectors
- OpenCTI connectors pack
- STIX2 tooling
- TAXII clients
- TheHive + Cortex
- TIP platforms (Anomali, ThreatConnect)
- Yeti
Control validation & continuous testing
- ATT&CK coverage matrices
- BAS continuous schedules
- Continuous purple-team frameworks
- Control effectiveness scorecards
- Detection coverage dashboards
- Detection gap trackers
- Purple-team playbook libraries
- Tabletop + hybrid exercise tooling