Skip to content

Environment Setup

Atomic Red Team is a collection of MITRE ATT&CK techniques and test cases designed for red team operations. Setting up the framework involves installing dependencies, configuring the environment, and initializing the test suite to ensure compatibility with your target environment. This guide walks through the process for Linux/macOS systems; Windows-specific steps may vary slightly.


Prerequisites

Before proceeding, ensure your environment meets these requirements: - Python 3.8+ (with pip installed) - Docker (for some test cases; optional) - Administrative privileges for system-level testing - A working internet connection for package installation


Installation

  1. Clone the repository
    Use Git to download Atomic Red Team from its official source:

    git clone https://github.com/atomic-red-team/atomic-red-team.git
    cd atomic-red-team
    

  2. Install dependencies
    Install required Python packages via pip:

    pip install -r requirements.txt
    
    Note: Some tests may require additional tools (e.g., docker, vboxmanage)—check the README.md for specifics.


Configuration

  1. Set environment variables
    Define the working directory and test types:

    export ATOMIC_WD=/path/to/your/test/directory
    export ATOMIC_TEST_TYPES="execution privilege_access"
    
    Replace /path/to/your/test/directory with your preferred location.

  2. Customize config.yaml
    Modify the configuration file to specify output formats, test exclusions, or environment-specific settings:

    output:
      format: "json"
      file: "/path/to/output.json"
    tests:
      exclude:
        - "T1087"  # Example: Exclude a specific technique
    
    This file is typically located in atomic-data/config.yaml.


Initialization

  1. Run the framework
    Execute the main command to initialize and list available tests:

    ./atomic --list
    
    This outputs all supported techniques. To run a specific test:
    ./atomic --test T1087 --output /path/to/results
    
    Replace T1087 with the desired technique ID.

  2. Verify setup
    Test basic functionality by running a sample test:

    ./atomic --test T1087 --output /tmp/test_output
    
    Check the output directory for results and ensure no errors occur.


Troubleshooting

  • Missing dependencies: If tests fail, install required tools (e.g., docker, vboxmanage) or disable incompatible tests.
  • Permissions issues: Run commands with sudo if you encounter permission errors.
  • Configuration conflicts: Review config.yaml and environment variables for typos or misconfigurations.

Key takeaways

  • Install Atomic Red Team via Git and Python dependencies.
  • Configure environment variables and config.yaml to tailor tests.
  • Use ./atomic --list to explore techniques and --test to execute specific scenarios.
  • Always verify prerequisites and review the README.md for test-specific requirements.
  • Regularly update the framework to align with the latest MITRE ATT&CK techniques.