Skip to content

Commit 8365fe1

Browse files
authored
Merge branch 'master' into master
2 parents 2d5362f + c73ac3c commit 8365fe1

File tree

1 file changed

+21
-5
lines changed

1 file changed

+21
-5
lines changed

README.md

Lines changed: 21 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -6,8 +6,6 @@
66

77
# MITRE Caldera™
88

9-
`🚨Security Notice🚨`: (17 Feb 2025 10:00 EST) Please pull v5.1.0+ for a recent security patch for [CVE-2025-27364](https://www.cve.org/CVERecord?id=CVE-2025-27364). Please update your Caldera instance, especially if you host Caldera on a publicly accessible network. [Vulnerability walkthrough.](https://medium.com/@mitrecaldera/mitre-caldera-security-advisory-remote-code-execution-cve-2025-27364-5f679e2e2a0e)
10-
119
MITRE Caldera™ is a cyber security platform designed to easily automate adversary emulation, assist manual red-teams, and automate incident response.
1210

1311
It is built on the [MITRE ATT&CK™ framework](https://attack.mitre.org/) and is an active research project at MITRE.
@@ -24,6 +22,12 @@ an asynchronous command-and-control (C2) server with a REST API and a web interf
2422
* ✍️ [Caldera's blog](https://medium.com/@mitrecaldera/welcome-to-the-official-mitre-caldera-blog-page-f34c2cdfef09)
2523
* 🌐 [Homepage](https://caldera.mitre.org)
2624

25+
### User Survey
26+
27+
It is always incredibly helpful for our team to hear from users about their Caldera use cases and the value that Caldera provides for their learning, research, or cyber security work. If you or your team uses Caldera significantly, we would greatly appreciate hearing from you.
28+
29+
📋 **Survey** - https://forms.office.com/g/ByBWxYTf8e
30+
2731
## Plugins
2832

2933
:star: Create your own plugin! Plugin generator: **[Skeleton](https://github.com/mitre/skeleton)** :star:
@@ -96,6 +100,8 @@ The `--build` flag automatically installs any VueJS UI dependencies, bundles the
96100

97101
If you prefer to not use the new VueJS UI, revert to Caldera v4.2.0. Correspondingly, do not use the `--build` flag for earlier versions as not required.
98102

103+
**Additionally, please note [security recommendations](#Security) for deploying Caldera.**
104+
99105
## Docker Installation
100106

101107
Local build:
@@ -133,6 +139,8 @@ There are two variants available, *full* and *slim*. The *slim* variant doesn't
133139
- If you wish to modify data used by the `atomic` plugin, clone the `Atomic Red Team` repository outside the container, apply your modifications and bind-mount it (`-v`) to `/usr/src/app/plugins/atomic/data/atomic-red-team` within the container.
134140
- If you wish to modify data used by `emu`, clone the `adversary_emulation_library` repository locally and bind-mount it (`-v`) to `/usr/src/app/plugins/emu/data/adversary-emulation-plans`.
135141

142+
**Additionally, please note [security recommendations](#Security) for deploying Caldera.**
143+
136144
### User Interface Development
137145

138146
If you'll be developing the UI, there are a few more additional installation steps.
@@ -148,14 +156,22 @@ If you'll be developing the UI, there are a few more additional installation ste
148156

149157
Your Caldera server is available at http://localhost:8888 as usual, but there will now be a hot-reloading development server for the VueJS front-end available at http://localhost:3000. Both logs from the server and the front-end will display in the terminal you launched the server from.
150158

151-
## Contributing
159+
## Security
152160

153-
Refer to our [contributor documentation](CONTRIBUTING.md).
161+
The Caldera team highly reccommends standing up the Caldera server on a secure environment/network, and not exposing it to the internet. The Caldera server does not have a hardened and thoroughly pentested web application interface, but only basic authentication and security features. Both MITRE and MITRE's US Government sponsors nearly exclusively only use Caldera on secure environments and do not rely on Caldera's own security protocols for proper cyber security.
154162

155-
## Vulnerability Disclosures
163+
### Vulnerability Disclosures
156164

157165
Refer to our [Vulnerability Disclosure Documentation](SECURITY.md) for submitting bugs.
158166

167+
#### Recent Vulnerability Disclosures
168+
169+
`🚨Security Notice🚨`: (17 Feb 2025 10:00 EST) Please pull v5.1.0+ for a recent security patch for [CVE-2025-27364](https://www.cve.org/CVERecord?id=CVE-2025-27364). Please update your Caldera instance, especially if you host Caldera on a publicly accessible network. [Vulnerability walkthrough.](https://medium.com/@mitrecaldera/mitre-caldera-security-advisory-remote-code-execution-cve-2025-27364-5f679e2e2a0e)
170+
171+
## Contributing
172+
173+
Refer to our [contributor documentation](CONTRIBUTING.md).
174+
159175
## Licensing
160176

161177
To discuss licensing opportunities, please reach out to [email protected] or directly to [MITRE's Technology Transfer Office](https://www.mitre.org/about/corporate-overview/contact-us#technologycontact).

0 commit comments

Comments
 (0)