Tech riderRev. 29 Sept 2026
  1. 1Runs onAPI, Linux, self-hosted, Web
  2. 2CostsFree plan · free trial
  3. 3Attack simulation modeshybrid
  4. 4Included attack surfacesendpoints, asset groups, people, teams, network hosts, email, phishing landing pages, SMS, phone-based social engineering, media pressure, tabletop exercises
  5. 5MITRE ATT&CK mappingYes
  6. 6Custom attack scenariosYes
  7. 7Continuous schedulingYes
  8. 8Deployment modelhybrid
8 lines stated Written from the maker's own pages: filigran.io
The OpenAEV homepage

Overview

OpenAEV is an Adversarial Exposure Validation platform for creating cyberattack simulations, stress tests, and crisis exercises. Its breach and attack simulations draw on cyber threat intelligence and map scenarios to MITRE ATT&CK and ATLAS. Attack Chaining links actions into paths based on findings; teams can orchestrate these manually or use dedicated agents. Structured tabletop exercises are available for evaluating readiness, escalation, coordination, communication, and response. Adversarial Exposure Scoring tracks posture over time and maps coverage to MITRE ATT&CK and domain-based controls. The product lists more than 30 integrations and connections to OpenCTI, threat feeds, EDR/XDR, SIEM, and SOC playbooks. Deployment options include cloud, on-premise, and multi-tenant setups, with air-gapped and bring-your-own-cloud options listed for Enterprise Edition. Community Edition is free forever for on-premise core simulations and tabletop exercises, with community support. Enterprise Edition pricing is quote-based, and its SaaS trial lasts 30 days. Components are available as Docker images and manual installation packages; Kubernetes is recommended for production deployments.

Who it is for

OpenAEV is aimed at cybersecurity and crisis-management teams that need simulations, tabletop exercises, and exposure scoring. Its Enterprise Edition is described as serving governments, financial institutions, and enterprises.

What is good

  • Maps simulations to MITRE ATT&CK and ATLAS
  • Supports manual or agent-based attack chaining
  • Includes tabletop exercises and exposure scoring
  • Community Edition is free forever for on-premise use

What to know first

  • Enterprise pricing is quote-based
  • Enterprise SaaS trial lasts 30 days
  • Community Edition includes community support

Specifiction review

OpenAEV: the full review

OpenAEV brings attack simulation, tabletop exercises, and exposure tracking together, with both community and enterprise editions. Compare the community edition’s on-premise scope with Enterprise deployment options and support needs.

Overview

OpenAEV is a security validation platform for teams that need to exercise both technical defenses and crisis response. It is a strong fit for organizations with mature security operations; smaller teams may find its breadth and Enterprise Edition’s custom pricing difficult to justify.

Filigran, founded in 2022 and headquartered in Paris, develops OpenAEV. The company lists SOC 2 Type 2, ISO 27001:2022, and GDPR trust items.

Key features

Threat-led simulations and attack chaining

OpenAEV uses cyber threat intelligence to shape breach and attack simulations, with scenarios mapped to MITRE ATT&CK and ATLAS. Teams can create custom scenarios, schedule work continuously, enrich indicators, and connect actions into attack paths based on findings. Attack chains can be orchestrated manually or autonomously using dedicated agents. That combination supports recurring, threat-informed validation, but it is likely more platform than a team seeking occasional, narrowly scoped tests needs.

Coverage spans endpoints, asset groups, people, teams, and network hosts, along with email, phishing landing pages, SMS, phone-based social engineering, and media pressure. STIX/TAXII support, reporting, workflow automation, and case management round out the operational toolkit.

Exercises and exposure tracking

Structured tabletop exercises let teams assess readiness, escalation, coordination, communication, and response. Adversarial Exposure Scoring tracks posture over time and maps coverage against MITRE ATT&CK and domain-based controls. Together, these features connect simulated activity with both measurable exposure and human response, making OpenAEV relevant beyond teams focused solely on endpoint testing.

Integrations and governance

OpenAEV has 30+ integrations, including connections for OpenCTI, threat feeds, EDR/XDR, SIEM, and SOC playbooks. Community Edition includes OpenCTI security coverage integration, prepackaged scenarios, Threat Arsenal, atomic testing, tabletop exercises, scoring, CVE findings, alert fetching, and RBAC. Enterprise Edition adds SSO, full audit logging, data segregation, and advanced role-based access controls. The latter matters for organizations with stricter governance needs; teams needing only core exercises can start with the community feature set.

Pricing

The freemium model offers a free Community Edition and a 30-day Enterprise Edition SaaS trial. The trial gives teams a time-limited way to explore the platform before deciding whether Enterprise deployment and support fit their needs.

PlanPrice and termsWhat it includes
Community Edition0.00 USD per free; free foreverOn-premise deployment, core attack simulation and tabletop exercises, and community support.
Enterprise EditionCustom pricing; quote based on number of instances, instance size, and support servicesSaaS or on-premise deployment, advanced integrations, AI features, and vendor support with SLAs.

Community Edition is the sensible starting point for organizations able to operate an on-premise installation and rely on community support. It gives up Enterprise’s deployment choices, advanced integrations, AI features, and vendor-backed SLAs. Enterprise is the better fit when SaaS or more specialized deployment options, governance, or service commitments are important, but its quote-based cost requires a direct purchasing decision rather than a published price comparison. Enterprise support includes a customer support portal and a dedicated Customer Success Manager, with standard 8×5 and premium 24×7 options.

Platforms

OpenAEV supports API, Linux, self-hosted, and web access. Deployments can be cloud, on-premise, or multi-tenant, with or without an endpoint agent; Enterprise Edition also offers air-gapped and bring-your-own-cloud options. Components are available as Docker images and manual installation packages, while Kubernetes is recommended for production deployments. This flexibility suits organizations with deployment constraints, though the on-premise Community Edition places operational responsibility on the adopting team.

Who it's for

OpenAEV is aimed at cybersecurity and crisis management teams that want to connect threat-led simulations, exposure measurement, and response exercises. Its scenario breadth and tracking are most useful where security and crisis teams can coordinate ongoing exercises. Filigran says Enterprise Edition is trusted by governments, financial institutions, and enterprises; organizations with strict governance or deployment requirements have Enterprise options, while smaller teams can assess the core experience through Community Edition.

Pros and cons

  • Pros: Technical attack simulations and structured crisis exercises share one platform, supporting a joined-up view of defense and response.
  • Pros: MITRE ATT&CK and ATLAS mapping, exposure scoring, and continuous scheduling support repeatable validation rather than isolated exercises.
  • Pros: Community Edition is free forever and includes core simulations and tabletop exercises, giving teams an on-premise entry point.
  • Cons: Community Edition is on-premise and backed by community support, so teams seeking hosted service or vendor SLAs need Enterprise.
  • Cons: Enterprise pricing depends on instances, instance size, and support, making costs less predictable before obtaining a quote.
  • Cons: The wide mix of technical and human attack surfaces may be excessive for teams looking only for a focused simulation capability.

Alternatives

For a narrower threat-intelligence lookup use case, IBM X-Force Exchange has a free plan, but that tier does not include X-Force API access. If open-source licensing is the priority, ThreatForge offers a free Community Edition under AGPL-3.0-or-later. Security Vision TIP is a paid threat intelligence platform with sales-calculated pricing; consider it when that platform category, rather than combined simulation and crisis exercises, is the priority.

SOCRadar Extended Threat Intelligence Platform offers dark-web monitoring plans starting at 600.00 USD per month for one domain and one seat, a more targeted choice for that monitoring scope. Group-IB Attack Surface Management is a paid alternative whose Standard pricing depends on confirmed external assets. Flashpoint Ignite has pricing by request, while Anomali Platform requires contacting sales for pricing. AhnLab V3 Internet Security is a paid Windows product with subscription plans, rather than a platform for attack simulation and crisis exercises.

Browse our Threat Intelligence Platforms and Breach and Attack Simulation Software lists to compare by category.

Verdict

Choose OpenAEV if your cybersecurity and crisis management teams need a shared system for threat-led attack validation, exposure tracking, and structured response exercises. Its free, on-premise Community Edition provides a credible route to core capabilities; look elsewhere if you need a narrowly focused tool, or prefer not to operate the community deployment and cannot accommodate a custom Enterprise quote.

OpenAEV plans and pricing

All plans
Community Edition Free Free forever On-premise · core attack simulation and tabletop exercises · community support filigran.io · 29 Sept 2026
Enterprise Edition Not published Quote based on number of instances, instance size and support services SaaS or on-premise · advanced integrations · AI features · vendor support with SLAs filigran.io · 29 Sept 2026

Compared on threat intelligence platforms

Free plan
Yesfiligran.io
Attack simulation modes
hybridfiligran.io
Included attack surfaces
endpoints, asset groups, people, teams, network hosts, email, phishing landing pages, SMS, phone-based social engineering, media pressure, tabletop exercisesfiligran.io
MITRE ATT&CK mapping
Yesfiligran.io
Custom attack scenarios
Yesfiligran.io
Continuous scheduling
Yesfiligran.io
Deployment model
hybridfiligran.io

Facts

Purpose
OpenAEV is an Adversarial Exposure Validation platform for creating attack simulations, stress tests, and crisis management exercises.filigran.io · 29 Sept 2026
Threat-led simulations
Its breach and attack simulations use cyber threat intelligence and map scenarios to MITRE ATT&CK and ATLAS.filigran.io · 29 Sept 2026
Autonomous attack chaining
Attack Chaining links actions into attack paths based on findings and can be orchestrated manually or autonomously with dedicated agents.filigran.io · 29 Sept 2026
Crisis exercises
The platform supports structured tabletop exercises to evaluate team readiness, escalation, coordination, communication, and response.filigran.io · 29 Sept 2026
Exposure scoring
Adversarial Exposure Scoring tracks posture over time and maps coverage against MITRE ATT&CK and domain-based controls.filigran.io · 29 Sept 2026
Integrations
The product page states that OpenAEV has 30+ integrations and describes connecting OpenCTI, threat feeds, EDR/XDR, SIEM, and SOC playbooks.filigran.io · 29 Sept 2026
Deployment
OpenAEV supports cloud, on-premise, and multi-tenant deployments, with or without an endpoint agent; Enterprise Edition also lists air-gapped and bring-your-own-cloud options.filigran.io · 29 Sept 2026
Community features
Community Edition includes OpenCTI security coverage integration, prepackaged scenarios, Threat Arsenal, atomic testing, tabletop exercises, scoring, CVE findings, alert fetching, and RBAC.filigran.io · 29 Sept 2026
Enterprise governance
Enterprise Edition lists SSO, full audit logging, data segregation, and advanced role-based access controls.filigran.io · 29 Sept 2026
Trial
The Enterprise Edition SaaS trial provides 30 days to explore the platform.filigran.io · 29 Sept 2026
Support
Enterprise Edition includes a customer support portal and dedicated Customer Success Manager; Filigran lists standard 8×5 and premium 24×7 support options.filigran.io · 29 Sept 2026
Install options
The documentation says OpenAEV components are available as Docker images and manual installation packages, with Kubernetes also recommended for production deployments.docs.openaev.io · 29 Sept 2026
Intended users
Filigran describes OpenAEV as serving cybersecurity and crisis management teams, and says its Enterprise Edition is trusted by governments, financial institutions, and enterprises.filigran.io · 29 Sept 2026
Company security attestations
Filigran lists SOC 2 Type 2, ISO 27001:2022, and GDPR trust items on its site.filigran.io · 29 Sept 2026

Company

Founded
2022filigran.io · 28 Sept 2026
Headquarters
Paris, Francefiligran.io · 28 Sept 2026

Best OpenAEV alternatives

See all 12

Where it ranks on Specifiction

Is OpenAEV yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources