WELCOME
 

Welcome to this month's edition of the Atomic Newsletter, a monthly email with updates and news about Atomic Red Team™ and its related projects such as MITRE ATT&CK®Invoke-AtomicRedTeamAtomicTestHarnesses, and more. Check out the archive for previous editions, visit our website, and chat with us on Slack

 
 
THE LATEST FROM ATOMIC RED TEAM
 
 

Testing 123

In this new video, Brian Donohue, Principal Information Security Researcher at Red Canary, explains what Atomic Red Team is, how and why to use it, and gives tips on operationalizing Atomic tests. Already familiar with the ins and outs of Atomic? Share it with a friend!



ATOMIC IN THE WILD
 
 
Using AI to test cybersecurity detection rules
 

This new AI evaluation framework leverages the full Atomic Red Team library to test the ability of large language models (LLMs) to generate cybersecurity detection rules. Using 188 different test scenarios, KQL Benchmark sees how different AI models—GPT-4.1, Gemini 2.5 Flash, etc.—perform.

Build your own purple team lab
 

Cybersecurity student Ziad Okka (0xZetss on Medium) blogs about a blue/purple team SOC lab he built using open-source tools. It's designed to simulate, detect, and respond to real-world attacks using Atomic for technique evasion, Sysmon for Windows event logging, and Wazuh for log analysis. 

Simulating ransomware attacks to strengthen cyber defense
 

In this blog, Sebastian Kandler, who heads a cyber defense and SOC team, walks readers through how to simulate a typical ransomware infection path using tools like Atomic Red Team—he talks about using techniques to run LSASS dumps, SAM extraction, and token impersonation—and Invoke-AtomicAssessment. 

Top contributors
 
First-time contributors 
 
UPCOMING WEBINAR
 
 
Modern ransomware and how to stop it
 

Ransomware is always evolving. Join this upcoming webinar to learn how to detect pre-ransomware activity quickly, mitigate it throughout the intrusion chain, and limit its potential impact.




Atomic Red Team Logo.png
 
 
 
  Twitter   LinkedIn   GitHub   YouTube   Slack