Threat-Informed, Autonomous Exposure Validation
Prove your resilience with real attack simulation, autonomous pentesting, and tabletop exercises with open-source, CTI-driven Adversarial Exposure Validation.

Prioritize, Test, and Fix — Continuously
Continuously assess, prioritize, validate and remediate exposures across your attack surface – at both human and technical levels – with open-source, threat-led, agentic Adversarial Exposure Validation (AEV).
Prioritize your simulations
CTI-driven BAS mapped to MITRE ATT&CK and ATLAS turns generic scenario libraries into a simulation program built around the threats actually targeting your environment — not a shelf of unrelated techniques.
Automate red teaming
Agent-orchestrated attack path validation chains techniques the way a real adversary would — full pentesting and red team exercises, executed autonomously, without the cost or scheduling friction of a manual engagement.
Test human readiness & crisis response
Technical controls are only half the picture. Run team-based simulations and social engineering scenarios to pressure-test how your people, escalation paths, and processes actually hold up when it counts.
Validate detection & response
Continuously fire real-world attack scenarios at your SIEM, EDR, and SOC playbooks. Close the offense/defense loop and turn every simulation into a concrete, actionable detection or response improvement.
Exposure Management for Threat-Informed Defense
Build simulations leveraging live CTI, industry frameworks, and your existing security stack - turning prioritized intelligence into executed scenarios, measured posture, and faster remediation.
Input
Threat feeds
Commercial / open source
EDR / XDR
Bring-your-own EDR
Processing
Output
- Execute scenarios on your assets through your EDR
- Customizable scenarios and simulations – test and scale
- Prioritized threat intelligence via the OpenCTI integration
- MITRE ATT&CK framework and scenario library
- Assess technical and human-side readiness
- AI-powered, accelerated time-to-remediate
Prove your resilience.
A comprehensive solution to simulate and remediate vulnerabilities to confidently prove your resilience.
Intelligence-led Breach and Attack Simulation
Build realistic simulations that continuously test your posture against prioritized threats. Connect OpenCTI or any intel source and map scenarios to MITRE ATT&CK and ATLAS. Schedule your own or deploy pre-built scenarios from a curated library.

Autonomous Attack Chaining
Attack Chaining links individual actions and events into a full attack path, where each move triggers the next based on real findings — not a fixed script. It executes end-to-end on a live, transparent graph you can drill into at every step. Orchestrate your chained scenarios manually, or fully autonomously with dedicated agents.

Tabletop Exercises & Crisis Simulation
Evaluate team readiness with hyper-realistic crisis tabletop exercises. Run structured scenarios, set clear expectations, challenge players under real pressure, and review outcomes in detail to improve escalation, coordination, communication, and response across your entire organization.

Adversarial Exposure Scoring
Quantify your security posture with a single, trackable score. Benchmark performance over time, map coverage against MITRE ATT&CK and domain-based controls, and drill down by scenario or technique — turning every simulation into actionable evidence, not just a result.

Agentic Remediation & Scenario Creation
Let AI accelerate the full loop: automatically generate actions and new attack scenarios from emerging threat intel, and get AI-suggested remediation for every exposure found. Or leverage XTM One agents to orchestrate complete adversary emulation scenarios.

Flexible. Extensible. Customizable. Open.
Adapt OpenAEV's open, extensible architecture to your environment, not the other way around. Deploy with or without an endpoint agent, across cloud, on-prem, or multi-tenant setups, and integrate easily with your existing tools via injectors, executors, and collectors — including your own EDR. Simulations and their results are completely transparent and configurable, giving you full control over how validation fits into your stack.

Trusted by industry experts
Join the OpenAEV community
Connect with fellow Filigran community members, focused on threat intelligence analysis and adversary simulation.
GitHub
Your gateway to exploring, contributing, and shaping the future of exposure validation.
Access OpenAEV Community EditionIntegrations
Discover a list of all available resources to complete your OpenAEV journey.
Explore OpenAEV integrationsDocumentation
Find all documents to get started, release notes and presentations about the platform.
Access OpenAEV documentationSlack
Stay informed about platform developments and engage in broader discussions.
Join the Filigran communityChoose the deployment that works for you
Community Edition
Install OpenAEV Community Edition on-premise using the open-source releases, with help available through Filigran support packages.
- Attack simulation and tabletop exercises
- MITRE ATT&CK and ATLAS scenario mapping
- Community support on Slack
- Security coverage integration with OpenCTI
- Threat Arsenal and Scenario Library
Enterprise Edition
Deploy OpenAEV Enterprise Edition on-premise or SaaS to access advanced integrations, AI-powered recommendations and scenario generation, along with our comprehensive support package.
- AI-generated scenarios and actions
- Bring-your-own-EDR integrations
- Autonomous attack chaining
- AI-powered remediation guidance
- Vendor support with SLAs
- Multi-tenancy
- And much more...
SaaS
A fully managed OpenAEV enterprise instance hosted by Filigran with self-service provisioning and support included; Bring-Your-Own-Cloud options available.
- Hosted and operated by Filigran
- Enterprise Edition included
- Bring-Your-Own-Cloud options
Sign up for your 30-day free trial
Explore full OpenAEV Enterprise Edition features, such as autonomous attack chaining, integrations with your current EDRs, automated scenario generation, and AI-powered remediation guidance... and more.
Discover the ecosystem
The XTM Paltform (eXtended Threat Management) is tailored to help organizations understand threat environments, anticipate and detect incidents, and conduct attack simulations.
OpenCTI
Filigran’s open-source cyber threat intelligence platform, enabling organizations to manage and operationalize their threat knowledge and observables.
Discover OpenCTIXTM Platform
The full eXtended Threat Management platform: threat intelligence, exposure validation and agentic AI working as one.
Discover XTM PlatformXTM Hub
The central, collaborative platform for users to access valuable resources and tradecraft for XTM products.
Discover XTM HubExplore OpenAEV possibilities
Read more about key use cases and customer stories to see how OpenAEV can operationalize your threat intelligence.
Implementing DORA: Threat-Led Penetration Testing for Financial Institutions
Implement DORA TLPT requirements and discover how to turn regulatory testing into continuous resilience and meet ECB expectations.
Read the blog postRetail’s Vulnerabilities Exposed: Check Your Defenses Against DragonForce
The UK retail attacks were a sharp reminder that even well-defended organizations remain exposed to tactics that bypass technical controls entirely. A resilient security posture must assess both technical controls and human readiness.
Read the blog postTraditional Red Teaming vs OpenAEV: Why Continuous Validation Matters
OpenAEV and red teaming are not rivals – they are complementary mechanisms for continuously testing and improving your defenses.
Read the blog postReady to see OpenAEV in action?
Try the live demo for free or book a personalized demo to discover how our solutions can streamline your cybersecurity operations.



