The powerful malware
technique emulator

A technique emulation framework for blue teams and researchers. Generate telemetry, validate detections and observe tradecraft without hosted infrastructure or weaponised samples.

Combat Theater technique emulation interface generating telemetry

Built for blue teams.
Powered by real malware techniques.

Combat Theater is a malware technique testing framework designed specifically for blue team detection engineers and security researchers.

It bridges the gap between blue teaming and malware development by giving defenders the ability to execute real-world malware techniques in isolation - safely, repeatably, and with full visibility.

No weaponised malware. No lab overhead. No infrastructure. Just accurate technique execution that behaves like the real thing.

For

Detection Engineers

Execute malware techniques, generate telemetry, validate detections effortlessly.

For

Security Researchers

Experiment with advanced and niche tradecraft without hours of tedious development.

Built for real technique execution.

Atomic scripts, C2 frameworks and BAS platforms each solve a different job. Combat Theater is for isolating, customizing and observing malware techniques whether you're validating detections, purple teaming, or researching tradecraft.

Combat Theater Atomic Red Team Caldera BAS
Ground-truth API-level execution logging
No-code low-level API / memory customization
Research-grade malware technique fidelity
No hosting or web infrastructure required
Threat playbooks / scenario chaining
Run-safe payloads out of the box
Easy install — up and running in 30 seconds
Scriptable / extensible techniques

Where technique execution earns its keep.

One framework for the jobs that need real malware techniques, without C2 overhead or script-only approximations.

01

Validate detections

Execute a technique, generate telemetry, and confirm your rule fires before production traffic is the only test.

02

Evaluate detection products

Independently validate how an EDR or detection stack actually performs against real techniques, before you buy, renew, or expand coverage.

03

Purple team exercises

Emulate real TTPs with clean, observable execution. Useful for joint red/blue work without standing up a full C2 stack.

04

Research & analyst training

Explore niche tradecraft or walk analysts through behaviors that matter, repeatably, safely, and with ground-truth logs.

View case studies

Everything you need for emulation.

A complete ecosystem for malware technique execution and validation.

Extensive malware technique emulation library in Combat Theater
Library

Large Technique Library

From commodity malware behavior to nation-state tradecraft — constantly updated for the current threat landscape.

Combat Theater execution logging console for blue team validation
Telemetry

Advanced Logging

Ground-truth API, memory, and system interaction logs from the execution engine.

Customisable shellcode injection technique configuration interface
Control

Execution Customization

No-code pick'n'mix for APIs, page permissions, and execution options.

Blue team detection validation workflow in Combat Theater
Visibility

Technique Transparency

Execution flow, system interactions, and detection opportunities for defenders.

Drive Combat Theater from your AI agent.

Connect over MCP and let your agent run techniques, launch playbooks, build configs, and author new techniques — without leaving the chat.

Combat Theater MCP demo — driving techniques and playbooks from an AI agent

Run-safe payloads.

Execute continuously with confidence. Combat Theater uses custom built payloads designed to mimic real malware structure without the malicious side effects.

Core guarantee

Peace of Mind

Our "run safe" payloads perform no network connections and no destructive actions — so you can execute continuously without collateral risk.

10+ Supported Types

Shellcode, DLLs, EXEs, and more exotic formats out of the box.

Bundled Source

Every payload ships with its source. Edit it, rebuild it, or duplicate it into your own variant.

Bring Your Own

Import real-world samples or custom payloads — the framework stays agnostic.

Chain techniques into playbooks.

Sequence multiple techniques into a single execution flow. Build your own with the playbook builder or run a pre-curated chain in one click.

Playbook automation system for malware technique emulation
Nation-state

APT

Emulate known nation-state tradecraft and advanced persistent threat chains.

Crimeware

Criminal

Reproduce ransomware group activity and commodity malware behaviour.

Detection

Challenge

Curated detection challenges — from easy wins to obscure, hard-to-catch techniques.

Implement your own techniques with Lua.

We provide 190+ ready to go technique scripts, however should you want to add your own or customize existing techniques, we expose our custom "ctapi" for you.

Combat Theater uses Lua as a control and orchestration layer, while all technique execution is performed by a native C++ engine.

Lua defines the GUI, configuration and execution flow of a technique but the underlying behavior is handled entirely by C++. This ensures techniques behave like real malware but with the ease of scripting.

-- CreateRemoteThread Shellcode Injection

local meta = require "meta"
local gui  = require "gui"
local api  = require "api"

function Init()
	meta.SetRequiredPermissions("user")
	meta.SetSupportedPayloads("shellcode")
	meta.SetReadme(readme)
end

function Configurator()
	gui.SetTarget(ctxTarget, true, true, true, false)
	gui.SetPayload(ctxPayload);
	gui.AllocateMemory(ctxAlloc)
	gui.WriteMemory(ctxWrite)
	gui.ChangePagePermissions(ctxPage)
	gui.CreateThread(ctxThread)
	gui.FreeMemory(ctxFree)
end

function ExecuteTechnique()
	-- Init
	local hTargetProcess, hTargetThread = api.InitializeTarget(ctxTarget)

	-- Payload
	local pPayload, iPayloadSize = api.GetPayload(ctxPayload)

	-- Memory
	local pPayloadAddress = api.AllocateMemory(ctxAlloc, hTargetProcess, iPayloadSize)
	api.WriteMemory(ctxWrite, hTargetProcess, pPayloadAddress, pPayload, iPayloadSize)
	api.ChangePagePermissions(ctxPage, hTargetProcess, pPayloadAddress, iPayloadSize)

	-- Execute
	local hThread = api.CreateThread(ctxThread, hTargetProcess, pPayloadAddress, false)

	-- Cleanup
	api.FreeMemory(ctxFree, hTargetProcess, pPayloadAddress)
	api.FreePayload(pPayload)
	api.CloseHandles(ctxFree, hTargetProcess, hTargetThread, hThread)
end

Not a BAS platform.
A local tool.

Combat Theater runs entirely on your machine. No cloud agents, no hosted infrastructure, no outbound product telemetry — just emulation you control.

Positioning Built for the desk, not the cloud

Unlike Breach & Attack Simulation platforms, Combat Theater isn't a hosted service with agents and orchestration. It's software you install and run locally.

Runtime Fully local & offline

Execute techniques on your workstation or lab VM with no cloud dependency. After install, it works without a network.

Setup Seconds, not sprints

No infrastructure to provision. No agents to deploy. No dependencies to babysit. Install and go.

Privacy Nothing leaves the box

No technique execution logging or product usage telemetry sent outbound. Your runs stay where you ran them.

See it in action.

Licensing options.

Professional
For internal detection & security teams
$450 / month
Billed annually at $5,400
Includes 5 device activations
Use on up to 5 machines at a time.

  • All techniques
  • Advanced execution logging
  • Event viewer & report generation
  • Internal use within your organisation
  • Standard email support
Request demo
Enterprise
For consultancies, MSSPs & mature security teams
Custom pricing
Billed annually
10+ device activations
Additional capacity available.

  • Everything in Professional
  • External / client-facing use permitted
  • Headless command-line mode
  • Playbook library, builder & runner
  • MCP support
  • Priority support
  • Flexible deployment licensing
Talk to sales