Getting started
OpenAEV lets you validate your security posture by simulating real-world adversary techniques. OpenAEV is part of the Filigran XTM suite and integrates with OpenCTI to generate meaningful attack Scenarios based on real threats.
This guide introduces the key concepts and workflows behind the platform.
The workflow
A typical OpenAEV workflow follows six steps:
- Define your targets -- Register the Assets (endpoints) and People (Players, Teams) you want to test.
- Prepare your actions -- Browse or create Threat Arsenal Actions: the technical or non-technical actions that will be executed (shell commands, phishing emails, DNS resolutions, etc.).
- Build Injects -- Wrap each Action into an Inject by specifying the target, the schedule, and the expected outcome (Expectations).
- Assemble a Scenario -- Combine Injects into a Scenario: a reusable attack sequence that tells the story of a threat.
- Run a Simulation -- Execute the Scenario as a Simulation to measure your security posture. Run it once or schedule it for recurrence.
- Analyze results -- Review outcomes across four axes (prevention, detection, vulnerability, human response) in Dashboards and drill into individual Findings.
You can also skip Scenarios entirely and run standalone Atomic Tests to validate a single technique in isolation.
Starter pack
OpenAEV ships with a starter pack that provides ready-to-use content so you can run your first Simulation immediately after installation. The starter pack includes:
| Content | Description |
|---|---|
| Pre-built Scenarios | Tabletop, agentless, and agent-based Scenarios covering common attack techniques |
| Dashboards | Four Dashboards for monitoring prevention, detection, and response metrics |
| Injectors | Nmap and Nuclei Injectors for network and vulnerability scanning |
| Collectors | Atomic Red Team, MITRE ATT&CK, and CVE/NVD (National Vulnerability Database) feeds |
| Agentless endpoint | One pre-configured endpoint with an Asset group |
The starter pack is available from the XTM Hub. Import it from Settings > XTM Hub after registering your platform.
What's next?
- Scenarios and Simulations -- Understand the Scenario/Simulation model
- Inject overview -- Create and configure Injects
- Threat Arsenal -- Manage Actions and Payloads
- Assets -- Register endpoints and Asset groups
- People -- Manage Players and Teams