Environment Setup
Atomic Red Team is a collection of MITRE ATT&CK techniques and test cases designed for red team operations. Setting up the framework involves installing dependencies, configuring the environment, and initializing the test suite to ensure compatibility with your target environment. This guide walks through the process for Linux/macOS systems; Windows-specific steps may vary slightly.
Prerequisites¶
Before proceeding, ensure your environment meets these requirements:
- Python 3.8+ (with pip installed)
- Docker (for some test cases; optional)
- Administrative privileges for system-level testing
- A working internet connection for package installation
Installation¶
-
Clone the repository
Use Git to download Atomic Red Team from its official source:
-
Install dependencies
Note: Some tests may require additional tools (e.g.,
Install required Python packages viapip:
docker,vboxmanage)—check theREADME.mdfor specifics.
Configuration¶
-
Set environment variables
Replace
Define the working directory and test types:
/path/to/your/test/directorywith your preferred location. -
Customize
config.yaml
Modify the configuration file to specify output formats, test exclusions, or environment-specific settings:
This file is typically located inoutput: format: "json" file: "/path/to/output.json" tests: exclude: - "T1087" # Example: Exclude a specific techniqueatomic-data/config.yaml.
Initialization¶
-
Run the framework
This outputs all supported techniques. To run a specific test:
Execute the main command to initialize and list available tests:
ReplaceT1087with the desired technique ID. -
Verify setup
Check the output directory for results and ensure no errors occur.
Test basic functionality by running a sample test:
Troubleshooting¶
- Missing dependencies: If tests fail, install required tools (e.g.,
docker,vboxmanage) or disable incompatible tests. - Permissions issues: Run commands with
sudoif you encounter permission errors. - Configuration conflicts: Review
config.yamland environment variables for typos or misconfigurations.
Key takeaways¶
- Install Atomic Red Team via Git and Python dependencies.
- Configure environment variables and
config.yamlto tailor tests. - Use
./atomic --listto explore techniques and--testto execute specific scenarios. - Always verify prerequisites and review the
README.mdfor test-specific requirements. - Regularly update the framework to align with the latest MITRE ATT&CK techniques.