DataDog/stratus-red-team
:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud observed · 2026-08-28
Health v2 · maintenance only
99/100
- Activity 99
- Release rhythm 98
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 15
- age_days: 1699
- days_rel: 15
- days_push: 7
- n_releases_24m: 28
Adoption not part of the score
2379 stars · 319 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Stratus Red Team is a self-contained Go CLI that emulates granular, actionable cloud attack techniques mapped to MITRE ATT&CK, against AWS, Azure, GCP, and Kubernetes. It uses Terraform under the hood to spin up prerequisites, detonate techniques, and clean up, helping teams validate threat detections.
Use cases
- validate cloud detection rules by detonating real attack techniques
- emulate MITRE ATT&CK techniques against a sandbox AWS account
- test whether CloudTrail stop or EBS snapshot exfiltration triggers alerts
- run purple team exercises in cloud environments
- simulate cloud-native attacks on Kubernetes clusters
- practice detection engineering with reproducible attack TTPs
When to choose
- you need granular, self-contained attack emulation for AWS, Azure, GCP, or Kubernetes
- you want to validate detection rules against real offensive techniques mapped to MITRE ATT&CK
- you prefer a single Go binary with automatic infrastructure setup and cleanup via Terraform
When to avoid
- you need to detonate techniques against your own pre-existing infrastructure rather than sandbox accounts
- you need a plugin system for custom techniques in a scripting language (custom techniques require Go library usage)
- you lack administrator access to a disposable cloud account or cluster
Facets
cli-tool · maturity active
security penetration-testing cli developer-tools security cloud-computing penetration-testing windows go cli adversary-emulation mitre-attack purple-team detection-engineering cloud-security red-team aws azure gcp kubernetes devops linux macos docker
4 sources
- readme: https://github.com/DataDog/stratus-red-team · fetched 2026-08-28 · 1849cb383ca0
- homepage: https://stratus-red-team.cloud · fetched 2026-08-29 · 92aa248d6cf8
- site_page: https://stratus-red-team.cloud/user-guide/getting-started · fetched 2026-08-29 · a119f098b382
- site_page: https://stratus-red-team.cloud/faq · fetched 2026-08-29 · ee291ad4c95c
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| DataDog/stratus-red-team | main | 99 |
For agents
markdown · JSON · MCP: product_card(name="DataDog/stratus-red-team")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem