MITRE Caldera provides a bunch of agents that can be used out of the box for adversarial emulation. Sandcat is one of the most widely used agent/plugin for Linux environments.
This repository provides a k8s deployment for MITRE Caldera Sandcat Agent.
- k8s cluster-admin role for caldera-agent to simulate attacks effectively
- Once the k8s-sandcat deployment is deployed, the agents pod name will show up on Caldera Server.
There are two primary configurations:
- Caldera server to use
- Group name to use for the agent
Both these configuration are part of the deployment manifest.