- 1Runs onAPI, Linux, self-hosted, Web
- 2CostsFree plan · free trial
- 3Attack simulation modeshybrid
- 4Included attack surfacesendpoints, asset groups, people, teams, network hosts, email, phishing landing pages, SMS, phone-based social engineering, media pressure, tabletop exercises
- 5MITRE ATT&CK mappingYes
- 6Custom attack scenariosYes
- 7Continuous schedulingYes
- 8Deployment modelhybrid

Overview
OpenAEV is an Adversarial Exposure Validation platform for creating cyberattack simulations, stress tests, and crisis exercises. Its breach and attack simulations draw on cyber threat intelligence and map scenarios to MITRE ATT&CK and ATLAS. Attack Chaining links actions into paths based on findings; teams can orchestrate these manually or use dedicated agents. Structured tabletop exercises are available for evaluating readiness, escalation, coordination, communication, and response. Adversarial Exposure Scoring tracks posture over time and maps coverage to MITRE ATT&CK and domain-based controls. The product lists more than 30 integrations and connections to OpenCTI, threat feeds, EDR/XDR, SIEM, and SOC playbooks. Deployment options include cloud, on-premise, and multi-tenant setups, with air-gapped and bring-your-own-cloud options listed for Enterprise Edition. Community Edition is free forever for on-premise core simulations and tabletop exercises, with community support. Enterprise Edition pricing is quote-based, and its SaaS trial lasts 30 days. Components are available as Docker images and manual installation packages; Kubernetes is recommended for production deployments.
Who it is for
OpenAEV is aimed at cybersecurity and crisis-management teams that need simulations, tabletop exercises, and exposure scoring. Its Enterprise Edition is described as serving governments, financial institutions, and enterprises.
What is good
- Maps simulations to MITRE ATT&CK and ATLAS
- Supports manual or agent-based attack chaining
- Includes tabletop exercises and exposure scoring
- Community Edition is free forever for on-premise use
What to know first
- Enterprise pricing is quote-based
- Enterprise SaaS trial lasts 30 days
- Community Edition includes community support
Specifiction review
OpenAEV: the full review
OpenAEV brings attack simulation, tabletop exercises, and exposure tracking together, with both community and enterprise editions. Compare the community edition’s on-premise scope with Enterprise deployment options and support needs.
Overview
OpenAEV is a security validation platform for teams that need to exercise both technical defenses and crisis response. It is a strong fit for organizations with mature security operations; smaller teams may find its breadth and Enterprise Edition’s custom pricing difficult to justify.
Filigran, founded in 2022 and headquartered in Paris, develops OpenAEV. The company lists SOC 2 Type 2, ISO 27001:2022, and GDPR trust items.
Key features
Threat-led simulations and attack chaining
OpenAEV uses cyber threat intelligence to shape breach and attack simulations, with scenarios mapped to MITRE ATT&CK and ATLAS. Teams can create custom scenarios, schedule work continuously, enrich indicators, and connect actions into attack paths based on findings. Attack chains can be orchestrated manually or autonomously using dedicated agents. That combination supports recurring, threat-informed validation, but it is likely more platform than a team seeking occasional, narrowly scoped tests needs.
Coverage spans endpoints, asset groups, people, teams, and network hosts, along with email, phishing landing pages, SMS, phone-based social engineering, and media pressure. STIX/TAXII support, reporting, workflow automation, and case management round out the operational toolkit.
Exercises and exposure tracking
Structured tabletop exercises let teams assess readiness, escalation, coordination, communication, and response. Adversarial Exposure Scoring tracks posture over time and maps coverage against MITRE ATT&CK and domain-based controls. Together, these features connect simulated activity with both measurable exposure and human response, making OpenAEV relevant beyond teams focused solely on endpoint testing.
Integrations and governance
OpenAEV has 30+ integrations, including connections for OpenCTI, threat feeds, EDR/XDR, SIEM, and SOC playbooks. Community Edition includes OpenCTI security coverage integration, prepackaged scenarios, Threat Arsenal, atomic testing, tabletop exercises, scoring, CVE findings, alert fetching, and RBAC. Enterprise Edition adds SSO, full audit logging, data segregation, and advanced role-based access controls. The latter matters for organizations with stricter governance needs; teams needing only core exercises can start with the community feature set.
Pricing
The freemium model offers a free Community Edition and a 30-day Enterprise Edition SaaS trial. The trial gives teams a time-limited way to explore the platform before deciding whether Enterprise deployment and support fit their needs.
| Plan | Price and terms | What it includes |
|---|---|---|
| Community Edition | 0.00 USD per free; free forever | On-premise deployment, core attack simulation and tabletop exercises, and community support. |
| Enterprise Edition | Custom pricing; quote based on number of instances, instance size, and support services | SaaS or on-premise deployment, advanced integrations, AI features, and vendor support with SLAs. |
Community Edition is the sensible starting point for organizations able to operate an on-premise installation and rely on community support. It gives up Enterprise’s deployment choices, advanced integrations, AI features, and vendor-backed SLAs. Enterprise is the better fit when SaaS or more specialized deployment options, governance, or service commitments are important, but its quote-based cost requires a direct purchasing decision rather than a published price comparison. Enterprise support includes a customer support portal and a dedicated Customer Success Manager, with standard 8×5 and premium 24×7 options.
Platforms
OpenAEV supports API, Linux, self-hosted, and web access. Deployments can be cloud, on-premise, or multi-tenant, with or without an endpoint agent; Enterprise Edition also offers air-gapped and bring-your-own-cloud options. Components are available as Docker images and manual installation packages, while Kubernetes is recommended for production deployments. This flexibility suits organizations with deployment constraints, though the on-premise Community Edition places operational responsibility on the adopting team.
Who it's for
OpenAEV is aimed at cybersecurity and crisis management teams that want to connect threat-led simulations, exposure measurement, and response exercises. Its scenario breadth and tracking are most useful where security and crisis teams can coordinate ongoing exercises. Filigran says Enterprise Edition is trusted by governments, financial institutions, and enterprises; organizations with strict governance or deployment requirements have Enterprise options, while smaller teams can assess the core experience through Community Edition.
Pros and cons
- Pros: Technical attack simulations and structured crisis exercises share one platform, supporting a joined-up view of defense and response.
- Pros: MITRE ATT&CK and ATLAS mapping, exposure scoring, and continuous scheduling support repeatable validation rather than isolated exercises.
- Pros: Community Edition is free forever and includes core simulations and tabletop exercises, giving teams an on-premise entry point.
- Cons: Community Edition is on-premise and backed by community support, so teams seeking hosted service or vendor SLAs need Enterprise.
- Cons: Enterprise pricing depends on instances, instance size, and support, making costs less predictable before obtaining a quote.
- Cons: The wide mix of technical and human attack surfaces may be excessive for teams looking only for a focused simulation capability.
Alternatives
For a narrower threat-intelligence lookup use case, IBM X-Force Exchange has a free plan, but that tier does not include X-Force API access. If open-source licensing is the priority, ThreatForge offers a free Community Edition under AGPL-3.0-or-later. Security Vision TIP is a paid threat intelligence platform with sales-calculated pricing; consider it when that platform category, rather than combined simulation and crisis exercises, is the priority.
SOCRadar Extended Threat Intelligence Platform offers dark-web monitoring plans starting at 600.00 USD per month for one domain and one seat, a more targeted choice for that monitoring scope. Group-IB Attack Surface Management is a paid alternative whose Standard pricing depends on confirmed external assets. Flashpoint Ignite has pricing by request, while Anomali Platform requires contacting sales for pricing. AhnLab V3 Internet Security is a paid Windows product with subscription plans, rather than a platform for attack simulation and crisis exercises.
Browse our Threat Intelligence Platforms and Breach and Attack Simulation Software lists to compare by category.
Verdict
Choose OpenAEV if your cybersecurity and crisis management teams need a shared system for threat-led attack validation, exposure tracking, and structured response exercises. Its free, on-premise Community Edition provides a credible route to core capabilities; look elsewhere if you need a narrowly focused tool, or prefer not to operate the community deployment and cannot accommodate a custom Enterprise quote.
OpenAEV plans and pricing
All plansCompared on threat intelligence platforms
- Free plan
- Yesfiligran.io
- Attack simulation modes
- hybridfiligran.io
- Included attack surfaces
- endpoints, asset groups, people, teams, network hosts, email, phishing landing pages, SMS, phone-based social engineering, media pressure, tabletop exercisesfiligran.io
- MITRE ATT&CK mapping
- Yesfiligran.io
- Custom attack scenarios
- Yesfiligran.io
- Continuous scheduling
- Yesfiligran.io
- Deployment model
- hybridfiligran.io
Facts
- Purpose
- OpenAEV is an Adversarial Exposure Validation platform for creating attack simulations, stress tests, and crisis management exercises.filigran.io · 29 Sept 2026
- Threat-led simulations
- Its breach and attack simulations use cyber threat intelligence and map scenarios to MITRE ATT&CK and ATLAS.filigran.io · 29 Sept 2026
- Autonomous attack chaining
- Attack Chaining links actions into attack paths based on findings and can be orchestrated manually or autonomously with dedicated agents.filigran.io · 29 Sept 2026
- Crisis exercises
- The platform supports structured tabletop exercises to evaluate team readiness, escalation, coordination, communication, and response.filigran.io · 29 Sept 2026
- Exposure scoring
- Adversarial Exposure Scoring tracks posture over time and maps coverage against MITRE ATT&CK and domain-based controls.filigran.io · 29 Sept 2026
- Integrations
- The product page states that OpenAEV has 30+ integrations and describes connecting OpenCTI, threat feeds, EDR/XDR, SIEM, and SOC playbooks.filigran.io · 29 Sept 2026
- Deployment
- OpenAEV supports cloud, on-premise, and multi-tenant deployments, with or without an endpoint agent; Enterprise Edition also lists air-gapped and bring-your-own-cloud options.filigran.io · 29 Sept 2026
- Community features
- Community Edition includes OpenCTI security coverage integration, prepackaged scenarios, Threat Arsenal, atomic testing, tabletop exercises, scoring, CVE findings, alert fetching, and RBAC.filigran.io · 29 Sept 2026
- Enterprise governance
- Enterprise Edition lists SSO, full audit logging, data segregation, and advanced role-based access controls.filigran.io · 29 Sept 2026
- Trial
- The Enterprise Edition SaaS trial provides 30 days to explore the platform.filigran.io · 29 Sept 2026
- Support
- Enterprise Edition includes a customer support portal and dedicated Customer Success Manager; Filigran lists standard 8×5 and premium 24×7 support options.filigran.io · 29 Sept 2026
- Install options
- The documentation says OpenAEV components are available as Docker images and manual installation packages, with Kubernetes also recommended for production deployments.docs.openaev.io · 29 Sept 2026
- Intended users
- Filigran describes OpenAEV as serving cybersecurity and crisis management teams, and says its Enterprise Edition is trusted by governments, financial institutions, and enterprises.filigran.io · 29 Sept 2026
- Company security attestations
- Filigran lists SOC 2 Type 2, ISO 27001:2022, and GDPR trust items on its site.filigran.io · 29 Sept 2026
Company
- Founded
- 2022filigran.io · 28 Sept 2026
- Headquarters
- Paris, Francefiligran.io · 28 Sept 2026
Best OpenAEV alternatives
See all 12Where it ranks on Specifiction
Is OpenAEV yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- filigran.io/our-story· checked 29 Sept 2026
- filigran.io/products/openaev· checked 29 Sept 2026
- filigran.io/services/openaev-enterprise-edition· checked 29 Sept 2026
- docs.openaev.io/latest/deployment/installation/· checked 29 Sept 2026

