◄ BACKDOCPURPLE TEAM ARSENAL TOOL LIST

Purple Team Arsenal Tool List

The following is a complete list of Purple Team tools as posted in my Cyber Security Arsenal Catalog organized in a simple and logical way to make it easier to navigate.

Every Index node will take you the tool section. Every tool will also be linked to another Complete Command Reference post for the given tool, where you can learn how to use it fully.

I hope you enjoy.

Index

Breach & Attack Simulation (BAS)

Adversary emulation

Detection engineering

Collaboration & reporting

Threat intelligence integration

Control validation & continuous testing

Purple Team Complete Tool List

Breach & Attack Simulation (BAS)

  • AttackIQ
  • AttackSim
  • Cymulate
  • Cymulate BAS packs
  • Infection Monkey
  • OpenBAS
  • Picus Security
  • Prelude Operator
  • SafeBreach
  • SCYTHE
  • Verodin (legacy)
  • XM Cyber

Adversary emulation

  • APTSimulator
  • Atomic Red Team
  • ATT&CK Evaluations methodologies
  • CALDERA abilities packs
  • Covenant adversary profiles
  • DumpsterFire
  • FlightSim
  • Invoke-Adversary
  • Invoke-AtomicRedTeam
  • Metta
  • MITRE Caldera
  • Red Canary Atomic Test Harness
  • Stratus Red Team
  • Uber METL

Detection engineering

  • ATT&CK mapping tools
  • Chainsaw
  • Chronicle YARA-L
  • contentctl (Splunk)
  • Detection-as-Code repos
  • Elastic Detection Rules
  • EQL / KQL helpers
  • Fleet policies as detection
  • Hayabusa
  • osquery packs
  • Panther
  • Sigma / Sigma CLI / pySigma
  • Snort rule management
  • Splunk ESCU
  • Suricata rule management
  • Uncoder.io
  • Wazuh / OSSEC rulesets
  • YARA / YARA Forge
  • Zircolite

Collaboration & reporting

  • AttackForge
  • AttackerKB
  • Confluence playbooks
  • DefectDojo (findings mgmt)
  • Dradis
  • Faraday
  • Ghostwriter
  • Git engagement repos
  • Jira / ServiceNow SecOps
  • Obsidian / Markdown templates
  • PenTest.ws
  • PlexTrac
  • Reconmap
  • Serpico
  • SysReptor
  • TheHive
  • Vectr
  • WriteHat

Threat intelligence integration

  • ATT&CK Navigator
  • ATT&CK Workbench
  • MISP automation
  • MISP-modules
  • n8n / Shuffle enrichment
  • OpenCTI connectors
  • OpenCTI connectors pack
  • STIX2 tooling
  • TAXII clients
  • TheHive + Cortex
  • TIP platforms (Anomali, ThreatConnect)
  • Yeti

Control validation & continuous testing

  • ATT&CK coverage matrices
  • BAS continuous schedules
  • Continuous purple-team frameworks
  • Control effectiveness scorecards
  • Detection coverage dashboards
  • Detection gap trackers
  • Purple-team playbook libraries
  • Tabletop + hybrid exercise tooling