Atomic Red Team FAQ
    • 18 Aug 2025
    • 1 Minute to read
    • PDF

    Atomic Red Team FAQ

    • PDF

    Article summary


    Why did an Atomic Read Team test not generate a Red Canary published threat?

    While Red Canary may have detector coverage for a specific technique, we commonly fine-tune our detectors with requirements on the process chain and surrounding telemetry to focus on true adversary activity and limit false positives from normal admin activity or regular business procedures.

    Does this tool replace the need for performing a penetration test or red team exercise?

    No, Atomic Red Team is an alert validation tool that helps you identify gaps in your security posture whether it be lack of telemetry or misconfigured alert logic. Penetration testing, on the other hand, verifies that the security measures in place are effective at blocking and preventing adversary activity. Red Team exercises take penetration testing a step further in that they are more focused on testing the security team’s investigation and response processes. For more information about the different kinds of security testing, see our blog.

    Is there an ISO or Docker image I can use to install Atomic Red Team?

    We have an on-demand webinar that shows how to use Docker and Windows Sandbox with Atomic Red Team to simplify the setup process.

    Are there recommended Atomic Red Team tests?

    Choosing the right or best Atomic Red Team test is very dependent on your use case and goals for testing. That being said, Red Canary’s annual Threat Detection Report calls out the tactics and techniques we commonly see in the wild. We also have blogs that outline emulation plans for common threat profiles like SocGholish and GootLoader.

    How many ATT&CK techniques are covered by Atomic Red Team tests?

    ATT&CK coverage statistics are available here.

    Does Atomic Red Team cover threats that do not occur on the endpoint (Cloud/SaaS)?

    Yes, the on the Atomic Red Team Test library page you’ll see links for Azure AD, Containers, Office 365, and other platforms.


    Was this article helpful?

    What's Next
    Changing your password will log you out immediately. Use the new password to log back in.
    First name must have atleast 2 characters. Numbers and special characters are not allowed.
    Last name must have atleast 1 characters. Numbers and special characters are not allowed.
    Enter a valid email
    Enter a valid password
    Your profile has been successfully updated.