# NextronSystems/APTSimulator

A toolset to make a system look as if it was the victim of an APT attack

Repository: https://github.com/NextronSystems/APTSimulator
Canonical: https://ross.abutalabs.com/products/aptsimulator
Homepage: https://www.nextron-systems.com
Language: Batchfile
License: MIT
License Family: permissive
Last push: 2025-09-23T10:20:43+00:00

## Health v2 (maintenance only)
Score: 42/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 43, release rhythm 8, longevity 100
- inputs: {"age_days": 3133, "days_push": 344, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2764, forks 452 (observed 2026-08-28T04:07:18.606326+00:00)

## What it is
APT Simulator is a Windows Batch script toolset that makes a system look as if it was the victim of an APT attack, using tools and output files to simulate adversary activity without malware. It requires no web server, database, or agents—just extract the release archive and run the batch file as Administrator.

## Use cases
- test endpoint detection agent or EDR detection capabilities
- run a POC for compromise assessment tools
- test SOC response to a realistic threat instead of EICAR or a port scan
- prepare an environment for digital forensics training classes
- simulate adversary activity on a Windows demo system
- validate security monitoring detections

## When to choose
- you need a simple, fast adversary simulation on Windows with no infrastructure like servers, databases, or VM agents
- you want to test EDR, SIEM, or SOC detection and response against realistic APT artifacts
- you need a demo system seeded with attacker toolmarks for forensics training
- you prefer a tool that is easy to read, modify, and extend

## When to avoid
- you need to simulate actual malware behavior rather than adversary activity
- you require multi-host attack chains, C2 infrastructure, or advanced adversary emulation frameworks
- you are on a non-Windows platform
- you need an actively developed tool with ongoing updates

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: security, penetration-testing, developer-tools, cli
- domain: security, penetration-testing, developer-tools
- platform: windows, cli
- tags: apt-simulation, adversary-simulation, edr-testing, soc-testing, detection-testing, batch-script, compromise-assessment, digital-forensics-training

## Member repositories
- NextronSystems/APTSimulator (main) score 42

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:18.606326+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T08:16:46.903847+00:00, confidence not recorded.
  - readme: https://github.com/NextronSystems/APTSimulator (fetched 2026-08-28T04:07:18.606326+00:00, sha eb45449be3a5)
  - homepage: https://www.nextron-systems.com (fetched 2026-08-29T09:56:27.613958+00:00, sha 1525cc3dc7bc)
  - site_page: https://www.nextron-systems.com/about (fetched 2026-08-29T09:56:27.617209+00:00, sha 42bb13ed9b16)
  - site_page: https://www.nextron-systems.com/thor/integrations (fetched 2026-08-29T09:56:27.619213+00:00, sha e7a7d160d3e9)
  - site_page: https://www.nextron-systems.com/thor (fetched 2026-08-29T09:56:27.621104+00:00, sha ba61ab5dfc39)
- Data as of 2026-08-30T08:39:29.467469+00:00.
