Shana Buhaisa, alongside Auria, showcased TESTERPy2 at BSides Kerala 2026, demonstrating how the open-source security testing platform puts EDR and AV detection capabilities to the test against Python-based offensive techniques.
TESTERPy2 focuses exclusively on MITRE ATT&CK technique T1059.006 (Command and Scripting Interpreter: Python). It is built to answer one simple but important question: can the security solutions you rely on actually detect malicious activity when it runs through Python? By narrowing in on a single technique, the platform gives defenders a clear, repeatable way to measure how their tooling holds up against Python-based tradecraft.
Read more about the session on the BSides Kerala 2026 speaker page.
Browse the source, try TESTERPy2 against your own EDR and AV stack, and contribute. Issues, feature ideas, and pull requests are all welcome, and a star helps the project reach more defenders.
View on GitHub
BreachSimRange runs red teaming, threat-led breach and adversary simulation that mirror how modern threat actors operate, so you find the gaps before they do.
Talk to us about Consulting