# OpenAEV-Platform/openaev

Open Adversarial Exposure Validation Platform

Repository: https://github.com/OpenAEV-Platform/openaev
Canonical: https://ross.abutalabs.com/products/openaev
Homepage: https://openaev.io
Language: Java
License: NOASSERTION
License Family: other
Topics: attack-simulation, breach-simulator, purple-team, cybersecurity, adversary-emulation, aev, adversary-exposure-validation
Last push: 2026-08-26T16:24:43+00:00

## Health v2 (maintenance only)
Score: 95/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 99, release rhythm 86, longevity 100
- inputs: {"age_days": 3642, "days_push": 7, "days_rel": 12, "gap_med": 3, "n_releases_24m": 124}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1782, forks 220 (observed 2026-08-28T04:05:35.651401+00:00)

## What it is
OpenAEV is an open-source platform for planning, scheduling, and running cyber adversary simulation campaigns and security exercises, from technical attack emulation to strategic tabletop drills. It integrates with OpenCTI for threat context and supports injectors for email, SMS, social media, and other channels.

## Use cases
- run breach and attack simulation campaigns against my infrastructure
- validate whether our security controls detect adversary techniques
- schedule purple team exercises with technical and strategic scenarios
- test incident response and crisis communication with tabletop exercises
- measure security gaps against real threat intelligence from OpenCTI
- automate adversarial exposure validation continuously

## When to choose
- you need an open-source alternative to commercial BAS/AEV platforms
- your team runs purple team or adversary emulation programs and wants scenario management
- you already use OpenCTI and want threat-informed simulation
- you need to orchestrate injects across email, SMS, and other channels for exercises

## When to avoid
- you only need a vulnerability scanner or pentest tool rather than simulation orchestration
- you want a lightweight CLI rather than a full self-hosted platform
- you need enterprise features like advanced reporting without an EE license

## Facets
- artifact type: application
- maturity: active
- function: security, monitoring, testing, workflow-automation, self-hosted
- domain: security
- platform: self-hosted, cross-platform
- tags: adversary-emulation, breach-and-attack-simulation, purple-team, exposure-validation, cyber-drills, attack-simulation, opencti-integration, devops, automation, docker, web-server

## Member repositories
- OpenAEV-Platform/openaev (main) score 95

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:35.651401+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:24:20.615207+00:00, confidence not recorded.
  - readme: https://github.com/OpenAEV-Platform/openaev (fetched 2026-08-28T04:05:35.651401+00:00, sha 7f909bf808c7)
  - homepage: https://openaev.io (fetched 2026-08-29T11:02:56.000220+00:00, sha 02eabd3fa938)
- Data as of 2026-08-30T08:39:29.467469+00:00.
