Mitrecaldera
Emulate Coverage Operate Detect Plugins Report Launch operation
Adversary Emulation Platform DOSSIER · KES-2026

Hunt your
network the way
an adversary would.

Kestrel runs autonomous breach-and-attack simulations built on MITRE ATT&CK — so the gaps in your defenses are found by you, in a test, and not by someone else for real.

coverage · operation "Nightfall" LIVE
Tested Detected Gap Untested
600+
ATT&CK techniques referenced
12
Tactic phases covered
40+
Community plugins
<5 min
To your first operation
§ 01 — WHY EMULATION

Most assessments test your patches. Almost none test your adversary.

A network's real posture is what an attacker can actually do inside it — not a checklist.
Defenders spend their days chasing known indicators. Adversaries spend theirs on behavior.

Patch levels and control coverage tell you what should be safe. They say nothing about what happens when a real intruder is already moving — pivoting between hosts, escalating quietly, exfiltrating on a channel no rule was written for.

Kestrel closes that distance. It represents adversary behavior as a chain of ATT&CK-mapped abilities and runs it end to end inside your own environment, so you watch an intrusion unfold and see, action by action, precisely where it is caught and where it walks straight through.

The result is not a hypothetical score. It is evidence: what your defenses stopped, what they missed, and what to fix first.

§ 03 — OPERATION LIFECYCLE

How a Kestrel operation runs.

A genuine sequence — each phase produces what the next one needs.

PHASE 01

Choose a profile

Start from a curated threat-group profile or assemble your own from a library of ATT&CK-mapped abilities.

PHASE 02

Deploy agents

Lightweight agents check in from your test hosts and wait for tasking over an encrypted channel.

PHASE 03

Run the chain

The decision engine executes techniques in sequence, adapting to what each host actually permits.

PHASE 04

Measure & report

Every action is scored against your detections and rolled into a coverage and gap report.

§ 04 — ATT&CK COVERAGE

The whole framework, on one grid.

Every action Kestrel runs is tagged with its technique and tactic. The blank cells are your backlog; the red cells are what to fix first.

Explore coverage
att&ck navigator · last operationSYNCED
TestedDetected GapUntested
§ 05 — WHO IT'S FOR

One platform, every side of the table.

Red team

Scale your offense

Automate the repeatable parts of an engagement so your operators spend time on the hard, creative problems.

  • Chain full attack paths on demand
  • Reuse and version your TTPs
  • Bounded, authorized execution
Blue team

Prove your detections

Test whether the alert actually fires, the log actually lands, and someone actually responds — with evidence.

  • Per-technique detection verdicts
  • Measure time-to-detect
  • Tune rules and re-test in minutes
Purple team

Close the loop

Put offense and defense on the same scorecard so every operation makes the next one measurably better.

  • Shared, evidence-based results
  • Track coverage over quarters
  • Turn findings into a backlog
§ 06 — FITS YOUR STACK

Open by default.

A documented REST API and agents in three runtimes mean Kestrel drops into the tooling you already run.

Go agent PowerShell agent Python agent REST API SIEM export EDR correlation ATT&CK Navigator 40+ plugins

“You cannot defend against behavior you have never watched happen. So watch it happen — on your terms, in your lab, before it happens for real.”

— The Kestrel operating principle
§ 07 — QUESTIONS

Common questions.

Operations are scoped to the hosts, subnets, and time windows you define, and agents are built to leave a clean, testable trail. Most teams run first in a dedicated lab, then in tightly bounded production windows once they trust the profile.

No. Start from curated adversary profiles and a library of ATT&CK-mapped abilities. When you want something specific, you can compose or author your own and package it as a reusable plugin.

Every emulated action is also a detection test. Kestrel reports whether each technique was detected, partially detected, or missed — and how long it took — so your blue team tunes rules against real behavior instead of guesswork.

A chronological timeline of every action, an ATT&CK coverage matrix of what was tested and caught, and a prioritized gap list — export-ready for both engineers and leadership.

Get started

Run your first operation today.

Stand up a server, deploy an agent, and watch a full attack chain execute against your own environment in minutes.