OpenAEV Attack Emulation and Validation Overview | C3SA

KB-Filigran-002 — Overview of OpenAEV Attack Emulation and Validation

Purpose

Provides a high-level overview of OpenAEV to support understanding of its role in cyber defence validation and attack emulation activities.

Overview

OpenAEV is an open-source Attack Emulation and Validation platform developed by Filigran. It is designed to help organizations assess and validate the effectiveness of security controls by safely emulating adversary behaviours in controlled environments.

OpenAEV supports threat-informed defence by enabling organizations to test detection, response, and resilience capabilities against realistic attack scenarios aligned to known threat techniques and adversary behaviours.

Scope

This article provides conceptual and reference information only. Configuration, deployment, scenario design, and execution are environment-specific and governed by organizational policies, authorization processes, and risk management requirements.
This article does not provide:
  • Step-by-step attack emulation instructions
  • Exploitation techniques or payload details
  • Operational playbooks or response procedures

Authoritative Documentation

Official Filigran documentation for OpenAEV is available at:

Support & Escalation

For advisory, integration, or service-related assistance, submit a support request through this portal.

Compliance & Control Alignment (Informative)

This knowledge base article supports organizational awareness, documentation, and operational understanding related to cyber defence validation and security control testing. It may contribute to regulatory and compliance objectives depending on system design, deployment scope, and control implementation.
  • ITSG-33 (Canada – GC / PBMM): PL-2, SA-9, SI-4, IR-1 / IR-4, CA-7
  • CMMC (United States – DoD): SI.L2-3.14.1, IR.L2-3.6.1, CA.L2-3.12.1, RM.L2-3.11.1
  • ISO/IEC 27001:2022: A.5.1, A.5.19, A.5.24, A.8.16, A.8.28
  • FedRAMP (Moderate / High – Informative): SI-4, CA-7, IR-4, PL-2
  • NIS2 (EU): Article 21(2)(a), (b), (e)
  • DORA (EU – Financial Sector): Articles 6, 8, 10, 24
InfoImportant Note
This article does not constitute evidence of compliance, certification, authorization, or accreditation. Compliance outcomes depend on implemented controls, governance processes, and independent assessment results.