Receive updates about new features and track development progress.
Your contribution supports infrastructure, server costs, and ongoing development. Get priority beta access. Estimated release: September 2026
DonateOverview of your agents, running campaigns and detection results
Agents built on the fly by binary patching, no compiling needed
Browse APT groups with their techniques, intel sources and references
See which techniques each APT uses and what you've already run
Run real attack chains the way threat intel reported them
Detection coverage mapped onto the ATT&CK matrix
Correlate each run with Splunk, Sentinel, AWS Security Hub or GCP to see what was detected
Cloud TTPs for AWS, Azure and GCP, with audit-log correlation
Kubernetes and Docker techniques: pod escape, RBAC abuse, breakout
The report cover and summary, with the detection rate
Per-technique detail: MITRE mapping, expected events and evidence
Write your own techniques and import TTP packs as YAML
Campaign templates for FIN7, APT29, Lazarus and more, sorted by difficulty
Agent, agentless (WinRM/SSH) and cloud execution
Webhook notifications to outside systems
Schedule campaigns to run on a calendar
Server, agent and audit logs