97% of security teams cannot tell if their exposures are exploitable. Are you one of them?Read the report
Filigran
OpenAEV logo

Exposure Management for Threat-Informed Defense

OpenAEV is the industry’s first open-source, threat-informed exposure validation platform – the validation pillar of CTEM.

Simulate real-life attack scenarios, validate exploitable paths, and assess team readiness to prove cyber resilience – for tools, people and processes.

OpenAEV dashboard
-80%
in crisis simulation planning time
-70%
in threat detection and response times
100%
growth in simulation programs
30+
integrations across your security stack

Prioritize, Test, and Fix — Continuously

Continuously assess, prioritize, validate and remediate exposures across your attack surface – at a human and technical level – with open-source, threat-led Adversarial Exposure Validation (AEV).

CTI-driven attack simulation

Simulate real-life attack scenarios based on prioritized threat intelligence and MITRE ATT&CK to validate your organization’s specific attack surface vulnerabilities.

Open-Source DNA

Open and transparent by design, OpenAEV is extensible and customizable to your environment with broad integrations, a bring-your-own-EDR approach, and a community-led ecosystem. You have the control.

Test human, tools and process readiness

Complement technical control validation with hyper-realistic tabletop exercises to rehearse crisis escalation and evaluate how your teams and processes perform under pressure.

CTEM-led exposure validation

Operationalize your CTEM approach: scope what matters, discover exposures, prioritize with threat intelligence, validate with attack simulations, and mobilize guided remediation.

Sign up for your 30-day free trial

Explore full OpenAEV Enterprise Edition features such as the use of your existing EDR agents, automated scenario generation, and AI-powered remediation guidance.

Trusted for exercises that actually land

We have conducted numerous crisis exercises. It is easy to use, very intuitive, allows for an unlimited number of players and exercise catalog, while creating a completely realistic environment for the players. The platform takes into account the needs of the users and the customer support is excellent.
G2 reviews logo
Verified user in Crisis Management
Mid-Market (51-1,000 emp.), on G2
I’m impressed with Filigran’s pragmatic, execution-focused approach to CTEM. Rather than adding more tools or operational overhead, their model focuses on measurable outcomes. That’s what practical CTEM should look like — outcome-driven, integrated, and scalable.
Chris Novak
Chris Novak
Cybersecurity Executive
From a technical standpoint, it’s open-source, meaning that you have the possibility to contribute to it easily. Then, the number of connectors for enrichers and external sources is very varied, meaning that a lot of external sources are easy to integrate.
G2 reviews logo
Quentin F.
CTI Analyst, Enterprise (>1,000 emp.), on G2
Filigran handles threat intelligence better than many of the market’s biggest players. Having opted for an Enterprise account, we have very regular discussions with their highly qualified CSM team. The support team is very responsive and assists us on many issues.
G2 reviews logo
Verified user in IT and Services
Enterprise (>1,000 emp.), on G2
The realism of OpenAEV injects (emails and SMS as they would happen in real life) creates a real sense of urgency and stress, which is exactly what we aim for in our exercises.
Swiss FDFA logo
Margaux Messerli
Margaux Messerli
Crisis Manager, Swiss FDFA

OpenCTI ⇆ OpenAEV: validate what actually threatens you

OpenAEV pulls live intelligence directly from OpenCTI to build attack simulations tailored to your real threat landscape.

Input

Threat feeds

Commercial / open source

EDR / XDR

Bring-your-own EDR

Processing

MITRE ATT&CK
OpenAEV logo
Adversarial Exposure Validation
OpenAEV icon
Simulate real-life attack scenarios
OpenAEV icon
Assess readiness against prioritized threats
OpenAEV icon
Improve your security posture

Output

  • Execute scenarios on your assets through your EDR
  • Customizable scenarios and simulations – test and scale
  • Prioritized threat intelligence via the OpenCTI integration
  • MITRE ATT&CK framework and scenario library
  • Assess technical and human-side readiness
  • AI-powered, accelerated time-to-remediate

Reduce risk. Save time. Stop attacks.

Proactively detect and remediate vulnerabilities before they can be exploited.

Intelligence-led breach and attack simulation

Build realistic simulations to continuously test your security posture from prioritized threats by connecting with OpenCTI (or any intel source) and mapping scenarios to MITRE ATT&CK. Create and schedule your own scenarios or deploy pre-built versions from a curated library.

OpenAEV intelligence-led breach and attack simulation - interactive demo

AI-powered simulations and remediation

Reduce MTTD and MTTR with AI-powered scenario generation and remediation. Quickly build contextual scenarios to detect real threats, then prioritize and deploy fixes based on risk and observed gaps with actionable, AI-driven “how to improve” recommendations.

OpenAEV AI-powered remediation

Complete attack surface exposure visibility

Analyze attack surface exposures and simulation results from customizable dashboards: high-level scores, performance trackers, trends, domain-based security controls, kill-chain mapping, and granular drill-downs per scenario and ATT&CK technique.

OpenAEV dashboard

Tabletop exercises to test human and process readiness

Evaluate team readiness with hyper-realistic crisis tabletop exercises. Run structured scenarios, set expectations, challenge players, and review outcomes to improve escalation, coordination and response.

OpenAEV tabletop crisis exercise

Flexible. Extensible. Customizable. Open.

Deploy and run simulations without adding an endpoint agent (hybrid options available). Integrate easily using injectors, executors and collectors, bring your own EDR, and adapt the platform to your environment thanks to OpenAEV’s open, extensible architecture.

OpenAEV injectors, executors and collectors - interactive demo

Choose the deployment that works for you

Leverage the power of fully integrated OpenCTI and OpenAEV to support your journey towards continuous threat exposure management.

Free forever

Community Edition

Install OpenAEV Community Edition on-premise using the open-source releases, with help available through Filigran support packages.

  • Attack simulation and tabletop exercises
  • MITRE ATT&CK scenario mapping
  • Community support on Slack
Contact us

Enterprise Edition

Deploy OpenAEV Enterprise Edition on-premise or SaaS to access advanced integrations, AI-powered recommendations and scenario generation, along with our comprehensive support package.

  • AI-generated scenarios from threat intel
  • Bring-your-own-EDR integrations
  • AI-powered remediation guidance
  • Vendor support with SLAs
Contact us

SaaS

A fully managed OpenAEV enterprise instance hosted by Filigran with self-service provisioning and support included; Bring-Your-Own-Cloud options available.

  • Hosted and operated by Filigran
  • Enterprise Edition included
  • Bring-Your-Own-Cloud options

Discover the ecosystem

Our eXtended Threat Management (XTM) platform is tailored to help organizations understand threat environments, anticipate and detect incidents, and conduct attack simulations.

OpenCTI logo

OpenCTI

Filigran’s open-source cyber threat intelligence platform, enabling organizations to manage and operationalize their threat knowledge and observables.

Discover OpenCTI
XTM Platform

XTM Platform

The full eXtended Threat Management platform: threat intelligence, exposure validation and agentic AI working as one.

Discover XTM Platform
XTM Hub

XTM Hub

The central, collaborative platform for users to access valuable resources and tradecraft for XTM products.

Discover XTM Hub

Ready to see OpenAEV in action?

Try the live demo for free or book a personalized demo to discover how our solutions can streamline your cybersecurity operations.