What is Atomic Red Team, and what does running a single atomic test actually do?
answer
- open-source, per-technique
- maps to ATT&CK
- a library, not a platform
- no C2, no chaining
- YAML executor plus cleanup_command
basics
~20 sAtomic Red Team is an open-source library of small, per-technique tests mapped to MITRE ATT&CK. Running one atomic executes a short scripted action for a single technique, so you can check whether your telemetry recorded it and your detections fired.
solid answer
~40 sAtomic Red Team is a library, not a platform: each test (an "atomic") is a small, portable, YAML-defined action for one ATT&CK technique, usually a command or two, run manually or through the `Invoke-AtomicRedTeam` PowerShell module. You pick a technique — say scheduled-task persistence — fire its atomic on a test host, and then look at your EDR, Sysmon or platform logs to see whether the behaviour was recorded and whether a detection alerted. That is the whole loop: one technique, one observable action, one check of your visibility. It has no command-and-control channel, does no chaining of steps, and makes no decisions for you — it is a shared, versioned set of building blocks for validating detections, and everything around them (sequencing, cleanup, judging the result) is yours to run.
go deeper
Know the one-line definition: an open-source library of small per-technique tests mapped to ATT&CK, run to check whether your telemetry and detections notice a known behaviour.
Be ready to describe an atomic's anatomy — YAML, executor, command, cleanup_command — and to explain why it has no C2 and does no chaining, versus what CALDERA and operator C2 add.
Show you use it as detection-validation: run the technique, then reason about telemetry captured versus rule fired versus analyst acted, rather than treating a green run as coverage.
Frame where a library fits in an emulation program — cheap, transparent, ATT&CK-mapped coverage checks — and where it stops, so investment in richer frameworks or hands-on emulation is justified by objective.
## What it is **Atomic Red Team** is an open-source project (maintained by Red Canary) that provides a large library of small, self-contained security tests. Each test is called an **atomic** because it exercises exactly one behaviour: a single **MITRE ATT&CK technique** — ATT&CK being the public catalogue of attacker techniques, each with an identifier such as `T1053.005` (Scheduled Task). The point of the library is **detection validation**: you run a known technique on purpose and then check whether your defensive stack noticed it. ## What an atomic contains Atomics are defined in **YAML**. A typical atomic has: - a **name** and description of the technique it emulates; - **supported_platforms** (windows, macos, linux); - optional **input_arguments** with defaults you can override; - an **executor** — the interpreter (`command_prompt`, `powershell`, `sh`, `bash`) and the **command** to run; - a **cleanup_command** that undoes the action (this is the part people forget). You can run an atomic two ways: copy the command out of the YAML and run it by hand, or drive it through the **`Invoke-AtomicRedTeam`** PowerShell module, which reads the YAML, resolves arguments, runs the executor, and can run the cleanup command if you tell it to. ## What running one does — and does not do Running a single atomic performs **one observable action** on the host: it might create a scheduled task, spawn `mshta`, dump a registry hive, or write to a startup folder. That action is designed to leave the same telemetry a real use of that technique would leave — a process-creation record, a file write, a registry change — so you can then go to your **endpoint telemetry** (EDR, Sysmon Event ID 1 for process creation, Windows Security 4688, `auditd` on Linux) and your **detections** and ask: *did the record exist, and did a rule fire?* What it deliberately does **not** do frames the rest of this leaf: - **No command-and-control.** An atomic is a local action. There is no beacon, no operator session, no remote tasking. That is what CALDERA (agent-driven) and operator C2 like Cobalt Strike or Sliver add. - **No chaining.** One atomic is one technique. It will not walk an intrusion from initial access to exfiltration; you sequence steps yourself. - **No decisions.** It does not read the environment and choose what to do next; it runs the command you selected. - **No guaranteed cleanup.** Cleanup only happens if you run the cleanup command. Skip it and the artefact — the scheduled task, the registry key — stays on the host. ## Why interviewers ask it Atomic Red Team is the entry point to purple-teaming: it is cheap, transparent (you can read exactly what each test does before running it), and mapped one-to-one to ATT&CK, which makes coverage easy to talk about. A candidate who understands that it is a **test library** — a set of building blocks for validating visibility, not an emulation platform and not a C2 — has the mental model the rest of the tooling questions build on. The common junior mistake is to describe it as "a red-team tool that attacks the network," which misses that it is local, per-technique, and does nothing across hosts on its own.
- If an atomic runs cleanly and no alert fires, does that prove the technique is undetectable in your environment?No. A single atomic executes one specific implementation of the technique. A missed detection could mean the telemetry never arrived, a rule did not match this exact command, an analyst never saw the alert, or your version of the technique differs from what a real actor would use. "No alert" is a prompt to find which stage swallowed it, not a conclusion that the behaviour is invisible.
- How does an atomic relate to a MITRE ATT&CK technique ID like T1053.005?Each atomic is tagged with the technique (and sub-technique) it emulates, so `T1053.005` (Scheduled Task) has one or more atomics that create tasks in different ways. That mapping lets you talk about coverage in ATT&CK terms — which techniques you have exercised — but remember one atomic is one implementation, not the whole technique.
saying these in an interview costs you the question
- Calling it a full attack platform or exploitation framework
- Thinking it includes command-and-control or a beacon
- Assuming it chains techniques into a full intrusion automatically
- Believing cleanup happens automatically after every test
- Treating one passed atomic as full coverage of the technique