Exposure Management for Threat-Informed Defense
OpenAEV is the industry’s first open-source, threat-informed exposure validation platform – the validation pillar of CTEM.
Simulate real-life attack scenarios, validate exploitable paths, and assess team readiness to prove cyber resilience – for tools, people and processes.

Prioritize, Test, and Fix — Continuously
Continuously assess, prioritize, validate and remediate exposures across your attack surface – at a human and technical level – with open-source, threat-led Adversarial Exposure Validation (AEV).
CTI-driven attack simulation
Simulate real-life attack scenarios based on prioritized threat intelligence and MITRE ATT&CK to validate your organization’s specific attack surface vulnerabilities.
Open-Source DNA
Open and transparent by design, OpenAEV is extensible and customizable to your environment with broad integrations, a bring-your-own-EDR approach, and a community-led ecosystem. You have the control.
Test human, tools and process readiness
Complement technical control validation with hyper-realistic tabletop exercises to rehearse crisis escalation and evaluate how your teams and processes perform under pressure.
CTEM-led exposure validation
Operationalize your CTEM approach: scope what matters, discover exposures, prioritize with threat intelligence, validate with attack simulations, and mobilize guided remediation.
Sign up for your 30-day free trial
Explore full OpenAEV Enterprise Edition features such as the use of your existing EDR agents, automated scenario generation, and AI-powered remediation guidance.
Trusted for exercises that actually land
OpenCTI ⇆ OpenAEV: validate what actually threatens you
OpenAEV pulls live intelligence directly from OpenCTI to build attack simulations tailored to your real threat landscape.
Input
Threat feeds
Commercial / open source
EDR / XDR
Bring-your-own EDR
Processing
Output
- Execute scenarios on your assets through your EDR
- Customizable scenarios and simulations – test and scale
- Prioritized threat intelligence via the OpenCTI integration
- MITRE ATT&CK framework and scenario library
- Assess technical and human-side readiness
- AI-powered, accelerated time-to-remediate
Reduce risk. Save time. Stop attacks.
Proactively detect and remediate vulnerabilities before they can be exploited.
Intelligence-led breach and attack simulation
Build realistic simulations to continuously test your security posture from prioritized threats by connecting with OpenCTI (or any intel source) and mapping scenarios to MITRE ATT&CK. Create and schedule your own scenarios or deploy pre-built versions from a curated library.

AI-powered simulations and remediation
Reduce MTTD and MTTR with AI-powered scenario generation and remediation. Quickly build contextual scenarios to detect real threats, then prioritize and deploy fixes based on risk and observed gaps with actionable, AI-driven “how to improve” recommendations.

Complete attack surface exposure visibility
Analyze attack surface exposures and simulation results from customizable dashboards: high-level scores, performance trackers, trends, domain-based security controls, kill-chain mapping, and granular drill-downs per scenario and ATT&CK technique.

Tabletop exercises to test human and process readiness
Evaluate team readiness with hyper-realistic crisis tabletop exercises. Run structured scenarios, set expectations, challenge players, and review outcomes to improve escalation, coordination and response.

Flexible. Extensible. Customizable. Open.
Deploy and run simulations without adding an endpoint agent (hybrid options available). Integrate easily using injectors, executors and collectors, bring your own EDR, and adapt the platform to your environment thanks to OpenAEV’s open, extensible architecture.

Join the OpenAEV community
Connect with fellow Filigran community members, focused on threat intelligence analysis and adversary simulation.
GitHub
Your gateway to exploring, contributing, and shaping the future of exposure validation.
Access OpenAEV Community EditionInjectors
Discover a list of all resources available to complete your OpenAEV journey.
Explore OpenAEV integrationsDocumentation
Find all documents to get started, release notes and presentations about the platform.
Access OpenAEV documentationSlack
Stay informed about platform developments and engage in broader discussions.
Join the Filigran communityChoose the deployment that works for you
Leverage the power of fully integrated OpenCTI and OpenAEV to support your journey towards continuous threat exposure management.
Community Edition
Install OpenAEV Community Edition on-premise using the open-source releases, with help available through Filigran support packages.
- Attack simulation and tabletop exercises
- MITRE ATT&CK scenario mapping
- Community support on Slack
Enterprise Edition
Deploy OpenAEV Enterprise Edition on-premise or SaaS to access advanced integrations, AI-powered recommendations and scenario generation, along with our comprehensive support package.
- AI-generated scenarios from threat intel
- Bring-your-own-EDR integrations
- AI-powered remediation guidance
- Vendor support with SLAs
SaaS
A fully managed OpenAEV enterprise instance hosted by Filigran with self-service provisioning and support included; Bring-Your-Own-Cloud options available.
- Hosted and operated by Filigran
- Enterprise Edition included
- Bring-Your-Own-Cloud options
Discover the ecosystem
Our eXtended Threat Management (XTM) platform is tailored to help organizations understand threat environments, anticipate and detect incidents, and conduct attack simulations.
OpenCTI
Filigran’s open-source cyber threat intelligence platform, enabling organizations to manage and operationalize their threat knowledge and observables.
Discover OpenCTIXTM Platform
The full eXtended Threat Management platform: threat intelligence, exposure validation and agentic AI working as one.
Discover XTM PlatformXTM Hub
The central, collaborative platform for users to access valuable resources and tradecraft for XTM products.
Discover XTM HubExplore OpenAEV possibilities
Read more about key use cases and customer stories to see how OpenAEV can operationalize your threat intelligence.
Implementing DORA: Threat-Led Penetration Testing for Financial Institutions
Implement DORA TLPT requirements and discover how to turn regulatory testing into continuous resilience and meet ECB expectations.
Read the blog postRetail’s Vulnerabilities Exposed: Check Your Defenses Against DragonForce
The UK retail attacks were a sharp reminder that even well-defended organizations remain exposed to tactics that bypass technical controls entirely. A resilient security posture must assess both technical controls and human readiness.
Read the blog postTraditional Red Teaming vs OpenAEV: Why Continuous Validation Matters
OpenAEV and red teaming are not rivals – they are complementary mechanisms for continuously testing and improving your defenses.
Read the blog postReady to see OpenAEV in action?
Try the live demo for free or book a personalized demo to discover how our solutions can streamline your cybersecurity operations.


