skip to content

What is Atomic Red Team, and what does running a single atomic test actually do?

level: juniorimportance: must knowfreq 55%

answer

  1. open-source, per-technique
  2. maps to ATT&CK
  3. a library, not a platform
  4. no C2, no chaining
  5. YAML executor plus cleanup_command

basics

~20 s

Atomic Red Team is an open-source library of small, per-technique tests mapped to MITRE ATT&CK. Running one atomic executes a short scripted action for a single technique, so you can check whether your telemetry recorded it and your detections fired.

solid answer

~40 s

Atomic Red Team is a library, not a platform: each test (an "atomic") is a small, portable, YAML-defined action for one ATT&CK technique, usually a command or two, run manually or through the `Invoke-AtomicRedTeam` PowerShell module. You pick a technique — say scheduled-task persistence — fire its atomic on a test host, and then look at your EDR, Sysmon or platform logs to see whether the behaviour was recorded and whether a detection alerted. That is the whole loop: one technique, one observable action, one check of your visibility. It has no command-and-control channel, does no chaining of steps, and makes no decisions for you — it is a shared, versioned set of building blocks for validating detections, and everything around them (sequencing, cleanup, judging the result) is yours to run.

go deeper

for a junior

Know the one-line definition: an open-source library of small per-technique tests mapped to ATT&CK, run to check whether your telemetry and detections notice a known behaviour.

for a middle

Be ready to describe an atomic's anatomy — YAML, executor, command, cleanup_command — and to explain why it has no C2 and does no chaining, versus what CALDERA and operator C2 add.

for a senior

Show you use it as detection-validation: run the technique, then reason about telemetry captured versus rule fired versus analyst acted, rather than treating a green run as coverage.

for a principal

Frame where a library fits in an emulation program — cheap, transparent, ATT&CK-mapped coverage checks — and where it stops, so investment in richer frameworks or hands-on emulation is justified by objective.

## What it is **Atomic Red Team** is an open-source project (maintained by Red Canary) that provides a large library of small, self-contained security tests. Each test is called an **atomic** because it exercises exactly one behaviour: a single **MITRE ATT&CK technique** — ATT&CK being the public catalogue of attacker techniques, each with an identifier such as `T1053.005` (Scheduled Task). The point of the library is **detection validation**: you run a known technique on purpose and then check whether your defensive stack noticed it. ## What an atomic contains Atomics are defined in **YAML**. A typical atomic has: - a **name** and description of the technique it emulates; - **supported_platforms** (windows, macos, linux); - optional **input_arguments** with defaults you can override; - an **executor** — the interpreter (`command_prompt`, `powershell`, `sh`, `bash`) and the **command** to run; - a **cleanup_command** that undoes the action (this is the part people forget). You can run an atomic two ways: copy the command out of the YAML and run it by hand, or drive it through the **`Invoke-AtomicRedTeam`** PowerShell module, which reads the YAML, resolves arguments, runs the executor, and can run the cleanup command if you tell it to. ## What running one does — and does not do Running a single atomic performs **one observable action** on the host: it might create a scheduled task, spawn `mshta`, dump a registry hive, or write to a startup folder. That action is designed to leave the same telemetry a real use of that technique would leave — a process-creation record, a file write, a registry change — so you can then go to your **endpoint telemetry** (EDR, Sysmon Event ID 1 for process creation, Windows Security 4688, `auditd` on Linux) and your **detections** and ask: *did the record exist, and did a rule fire?* What it deliberately does **not** do frames the rest of this leaf: - **No command-and-control.** An atomic is a local action. There is no beacon, no operator session, no remote tasking. That is what CALDERA (agent-driven) and operator C2 like Cobalt Strike or Sliver add. - **No chaining.** One atomic is one technique. It will not walk an intrusion from initial access to exfiltration; you sequence steps yourself. - **No decisions.** It does not read the environment and choose what to do next; it runs the command you selected. - **No guaranteed cleanup.** Cleanup only happens if you run the cleanup command. Skip it and the artefact — the scheduled task, the registry key — stays on the host. ## Why interviewers ask it Atomic Red Team is the entry point to purple-teaming: it is cheap, transparent (you can read exactly what each test does before running it), and mapped one-to-one to ATT&CK, which makes coverage easy to talk about. A candidate who understands that it is a **test library** — a set of building blocks for validating visibility, not an emulation platform and not a C2 — has the mental model the rest of the tooling questions build on. The common junior mistake is to describe it as "a red-team tool that attacks the network," which misses that it is local, per-technique, and does nothing across hosts on its own.

  • If an atomic runs cleanly and no alert fires, does that prove the technique is undetectable in your environment?
    No. A single atomic executes one specific implementation of the technique. A missed detection could mean the telemetry never arrived, a rule did not match this exact command, an analyst never saw the alert, or your version of the technique differs from what a real actor would use. "No alert" is a prompt to find which stage swallowed it, not a conclusion that the behaviour is invisible.
  • How does an atomic relate to a MITRE ATT&CK technique ID like T1053.005?
    Each atomic is tagged with the technique (and sub-technique) it emulates, so `T1053.005` (Scheduled Task) has one or more atomics that create tasks in different ways. That mapping lets you talk about coverage in ATT&CK terms — which techniques you have exercised — but remember one atomic is one implementation, not the whole technique.

saying these in an interview costs you the question

  • Calling it a full attack platform or exploitation framework
  • Thinking it includes command-and-control or a beacon
  • Assuming it chains techniques into a full intrusion automatically
  • Believing cleanup happens automatically after every test
  • Treating one passed atomic as full coverage of the technique

context