OpenAEV logo

Threat-Informed, Autonomous Exposure Validation

Prove your resilience with real attack simulation, autonomous pentesting, and tabletop exercises with open-source, CTI-driven Adversarial Exposure Validation.

OpenAEV dashboard
-80%
in crisis simulation planning time
-70%
in threat detection and response times
100%
growth in simulation programs
30+
integrations across your security stack

Prioritize, Test, and Fix — Continuously

Continuously assess, prioritize, validate and remediate exposures across your attack surface – at both human and technical levels – with open-source, threat-led, agentic Adversarial Exposure Validation (AEV).

Prioritize your simulations

CTI-driven BAS mapped to MITRE ATT&CK and ATLAS turns generic scenario libraries into a simulation program built around the threats actually targeting your environment — not a shelf of unrelated techniques.

Automate red teaming

Agent-orchestrated attack path validation chains techniques the way a real adversary would — full pentesting and red team exercises, executed autonomously, without the cost or scheduling friction of a manual engagement.

Test human readiness & crisis response

Technical controls are only half the picture. Run team-based simulations and social engineering scenarios to pressure-test how your people, escalation paths, and processes actually hold up when it counts.

Validate detection & response

Continuously fire real-world attack scenarios at your SIEM, EDR, and SOC playbooks. Close the offense/defense loop and turn every simulation into a concrete, actionable detection or response improvement.

Exposure Management for Threat-Informed Defense

Build simulations leveraging live CTI, industry frameworks, and your existing security stack - turning prioritized intelligence into executed scenarios, measured posture, and faster remediation.

Input

Threat feeds

Commercial / open source

EDR / XDR

Bring-your-own EDR

Processing

MITRE ATT&CK
OpenAEV logo
Adversarial Exposure Validation
OpenAEV icon
Simulate real-life attack scenarios
OpenAEV icon
Assess readiness against prioritized threats
OpenAEV icon
Improve your security posture

Output

  • Execute scenarios on your assets through your EDR
  • Customizable scenarios and simulations – test and scale
  • Prioritized threat intelligence via the OpenCTI integration
  • MITRE ATT&CK framework and scenario library
  • Assess technical and human-side readiness
  • AI-powered, accelerated time-to-remediate

Prove your resilience.

A comprehensive solution to simulate and remediate vulnerabilities to confidently prove your resilience.

Intelligence-led Breach and Attack Simulation

Build realistic simulations that continuously test your posture against prioritized threats. Connect OpenCTI or any intel source and map scenarios to MITRE ATT&CK and ATLAS. Schedule your own or deploy pre-built scenarios from a curated library.

Autonomous Attack Chaining

Attack Chaining links individual actions and events into a full attack path, where each move triggers the next based on real findings — not a fixed script. It executes end-to-end on a live, transparent graph you can drill into at every step. Orchestrate your chained scenarios manually, or fully autonomously with dedicated agents.

OpenAEV live simulation view showing a “LIVE” status indicator and a “Simulation running” message, waiting for the first inject executions.

Tabletop Exercises & Crisis Simulation

Evaluate team readiness with hyper-realistic crisis tabletop exercises. Run structured scenarios, set clear expectations, challenge players under real pressure, and review outcomes in detail to improve escalation, coordination, communication, and response across your entire organization.

OpenAEV tabletop exercise injecting a simulated breaking-news post about a ransomware incident

Adversarial Exposure Scoring

Quantify your security posture with a single, trackable score. Benchmark performance over time, map coverage against MITRE ATT&CK and domain-based controls, and drill down by scenario or technique — turning every simulation into actionable evidence, not just a result.

OpenAEV adversarial exposure overview with a critical exposure score of 97 broken down by pillar

Agentic Remediation & Scenario Creation

Let AI accelerate the full loop: automatically generate actions and new attack scenarios from emerging threat intel, and get AI-suggested remediation for every exposure found. Or leverage XTM One agents to orchestrate complete adversary emulation scenarios.


The OpenAEV Scenario Creator agent in XTM One, showing its persona and configuration

Flexible. Extensible. Customizable. Open.

Adapt OpenAEV's open, extensible architecture to your environment, not the other way around. Deploy with or without an endpoint agent, across cloud, on-prem, or multi-tenant setups, and integrate easily with your existing tools via injectors, executors, and collectors — including your own EDR. Simulations and their results are completely transparent and configurable, giving you full control over how validation fits into your stack.

OpenAEV integrations catalogue listing collectors, injectors and executors from the XTM ecosystem

Trusted by industry experts

Attack Simulation is the highest quality integrated product I have used in the AEV space.
Gartner Peer Insights
Verified user in Crisis Management
IT Security & Risk Management Associate, Manufacturing
The OpenAEV solution fully meets our needs because it allows us to simulate attacks on various types of assets and provide truly relevant execution status results.
Gartner Peer Insights
Verified user in Crisis Management
IT Security & Risk Management Associate, IT Services
I’m impressed with Filigran’s pragmatic, execution-focused approach to CTEM. Rather than adding more tools or operational overhead, their model focuses on measurable outcomes. That’s what practical CTEM should look like — outcome-driven, integrated, and scalable.
Chris Novak
Chris Novak
Cybersecurity Executive
We have conducted numerous crisis exercises. It is easy to use, very intuitive, allows for an unlimited number of players and exercise catalog, while creating a completely realistic environment for the players. The platform takes into account the needs of the users and the customer support is excellent.
G2 reviews logo
Verified user in Crisis Management
Mid-Market (51-1,000 emp.), on G2
The realism of OpenAEV injects (emails and SMS as they would happen in real life) creates a real sense of urgency and stress, which is exactly what we aim for in our exercises.
Swiss FDFA logo
Margaux Messerli
Margaux Messerli
Crisis Manager, Swiss FDFA

Choose the deployment that works for you

Free forever

Community Edition

Install OpenAEV Community Edition on-premise using the open-source releases, with help available through Filigran support packages.

  • Attack simulation and tabletop exercises
  • MITRE ATT&CK and ATLAS scenario mapping
  • Community support on Slack
  • Security coverage integration with OpenCTI
  • Threat Arsenal and Scenario Library
Contact us

Enterprise Edition

Deploy OpenAEV Enterprise Edition on-premise or SaaS to access advanced integrations, AI-powered recommendations and scenario generation, along with our comprehensive support package.

  • AI-generated scenarios and actions
  • Bring-your-own-EDR integrations
  • Autonomous attack chaining
  • AI-powered remediation guidance
  • Vendor support with SLAs
  • Multi-tenancy
  • And much more...
Contact us

SaaS

A fully managed OpenAEV enterprise instance hosted by Filigran with self-service provisioning and support included; Bring-Your-Own-Cloud options available.

  • Hosted and operated by Filigran
  • Enterprise Edition included
  • Bring-Your-Own-Cloud options

Sign up for your 30-day free trial

Explore full OpenAEV Enterprise Edition features, such as autonomous attack chaining, integrations with your current EDRs, automated scenario generation, and AI-powered remediation guidance... and more.


Discover the ecosystem

The XTM Paltform (eXtended Threat Management) is tailored to help organizations understand threat environments, anticipate and detect incidents, and conduct attack simulations.

OpenCTI logo

OpenCTI

Filigran’s open-source cyber threat intelligence platform, enabling organizations to manage and operationalize their threat knowledge and observables.

Discover OpenCTI
XTM Platform

XTM Platform

The full eXtended Threat Management platform: threat intelligence, exposure validation and agentic AI working as one.

Discover XTM Platform
XTM Hub

XTM Hub

The central, collaborative platform for users to access valuable resources and tradecraft for XTM products.

Discover XTM Hub

Ready to see OpenAEV in action?

Try the live demo for free or book a personalized demo to discover how our solutions can streamline your cybersecurity operations.