# guardicore/monkey

Infection Monkey - An open-source adversary emulation platform

Repository: https://github.com/guardicore/monkey
Canonical: https://ross.abutalabs.com/products/monkey
Homepage: https://www.guardicore.com/infectionmonkey/
Language: Python
License: GPL-3.0
License Family: copyleft
Topics: penetration-testing, security-tools, security-automation, infection-monkey, adversary-emulation
Last push: 2025-05-01T13:34:05+00:00

## Health v2 (maintenance only)
Score: 31/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 19, release rhythm 8, longevity 100
- inputs: {"age_days": 4021, "days_push": 489, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 7076, forks 828 (observed 2026-08-28T04:09:55.708727+00:00)

## What it is
Infection Monkey is an open-source adversary emulation platform that simulates malware-like self-propagation across a network to test security controls. It consists of a configurable worm agent and a centralized command-and-control server (Monkey Island) for controlling and visualizing simulations.

## Use cases
- test whether my security controls detect lateral movement
- simulate ransomware propagation safely in my network
- run a breach and attack simulation to validate defenses
- find unpatched machines an attacker could pivot through
- measure my network's resilience to worm-like malware
- verify detection of credential theft and exploitation attempts

## When to choose
- you want empirical, automated validation of detection and prevention controls against worm-like threats
- you need a safe, self-propagating agent to test segmentation and lateral-movement defenses
- you want a centralized dashboard to visualize how far an attack could spread

## When to avoid
- you need a full red-team toolkit with manual exploitation and C2 frameworks like Metasploit or Cobalt Strike
- you want passive vulnerability scanning rather than active attack simulation
- you cannot authorize intrusive testing on the target network

## Facets
- artifact type: application
- maturity: active
- function: penetration-testing, security, networking, monitoring
- domain: security, penetration-testing, networking
- platform: self-hosted, python
- tags: adversary-emulation, breach-attack-simulation, network-worm-simulation, lateral-movement, security-posture, linux, docker

## Member repositories
- guardicore/monkey (main) score 31

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:55.708727+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:40:12.754999+00:00, confidence not recorded.
  - readme: https://github.com/guardicore/monkey (fetched 2026-08-28T04:09:55.708727+00:00, sha 9edbe6469c60)
- Data as of 2026-08-30T08:39:29.467469+00:00.
