Our founder, Abhijith B R, showcased RedTeamSimmer at the Black Hat USA 2026 Arsenal in Las Vegas, demonstrating how this open-source platform gives Atomic Red Team the modern, browser-based interface it has always needed.
RedTeamSimmer is an open-source, web based adversary emulation platform providing a modern UI for orchestrating Atomic Red Team tests across enterprise Windows environments. It replaces the usual workflow of memorizing PowerShell syntax, managing prerequisites endpoint by endpoint, and stitching together scattered results with no central view. With a Flask server, lightweight Go agents, and a real-time web dashboard, security teams can deploy agents across multiple Windows endpoints, browse the full MITRE ATT&CK catalog, execute techniques with automatic prerequisite handling, and watch live, color-coded output from a single pane. It also fingerprints 60+ AV/EDR products on target systems and keeps a full operations history for audit and compliance.
For defenders, every executed technique is correlated against offline Sigma, Splunk, and Elastic detection rules, making coverage gaps easy to spot and alerting easy to validate. RedTeamSimmer also ships with pre-built adversary emulation plans for real threat actors, including APT28, APT3, APT41, FIN7, Lazarus Group, and Wizard Spider, for multi-stage attack simulations. It was originally built for the “Mastering Breach and Adversarial Attack Simulation” training at DEF CON Trainings.
BreachSimRange runs red teaming, threat-led breach and adversary simulation that mirror how modern threat actors operate, so you find the gaps before they do.
Talk to us about Consulting