Skip to content

MITRESecurity Automation Framework

Open source security testing and compliance automation toolkit

MITRE SAF™ Is

Free

All MITRE SAF™ content is free to use under the Apache 2 license. The Framework is currently in use by government sponsors, vendors, and private sector companies, tailoring content for their own organizational requirements.

Open Source

MITRE SAF™ hosts all source code for tools and test profiles publicly on GitHub. Organizations are free to use the code or its capabilities however required.

A Community

All MITRE SAF™ content is generated and maintained by a robust security community of both MITRE and non-MITRE contributors; MITRE serves as the framework steward. Collaboration across the community multiplies the impact for all users.

The MITRE SAF™ Open Source Toolset

MITRE SAF™ is made up of a toolkit of utilities that support security automation. MITRE SAF™ is modularized into different functions so you can use whichever one makes sense for your favorite security tools. You can use MITRE SAF™ tools on their own or without a container.

saf

SAF CLI

The MITRE SAF™ Command Line Interface (CLI) gives users the ability to quickly normalize disparate scan results from multiple tools to HDF, generate InSpec profiles, and validate that security requirements have been met.

heimdall

Heimdall

Heimdall is MITRE SAF™'s visualization platform. Upload results from the baseline validations that you have run or view existing security standards, and generate reports to give to your organization's reporting or SIEM tools.

Supports Capabilities:
saf

Vulcan

The MITRE SAF™ Vulcan application allows users to create security guidance utilizing the Security Requirements Guides. Vulcan streamlines the process to help authors concentrate on writing quality security guidance.

Supports Capabilities:

Content Library

The MITRE SAF™ content library includes InSpec validation profiles and Chef, Ansible, and Puppet hardening content. These can be used as a starting point or as reference material for developing your organization's security controls and hardening baselines.

Supports Capabilities:
saf

eMASS

eMASS integration with MITRE SAF™ provides automated workflows to support continuous monitoring and assessment workflows.

Supports Capabilities:
saf

OHDF

OASIS Heimdall Data Format (OHDF) is the common data format standard that facilitates security results analysis and consumption as a building metric, consolidate data, compare security results from a variety of tools over time, and much more.

Supports Capabilities:

Adopted by The Community

Sponsors

Platform OnePlatform One
Defense Security Cooperation AgencyDefense Security Cooperation Agency
Defense Counterintelligence and Security AgencyDefense Counterintelligence and Security Agency
United States Air ForceUnited States Air Force
Department of Defense CIODepartment of Defense CIO
Defense Information Systems AgencyDefense Information Systems Agency
United States Army Enterprise Cloud Management AgencyUnited States Army Enterprise Cloud Management Agency
Centers for Medicare & Medicaid ServicesCenters for Medicare & Medicaid Services
Center for Disease Control and PreventionCenter for Disease Control and Prevention
National Reconnaissance OfficeNational Reconnaissance Office

Vendors

Progress ChefProgress Chef
VMwareVMware
SophosSophos
Lockheed MartinLockheed Martin
Rancher Government SolutionsRancher Government Solutions
Google CloudGoogle Cloud
GitHubGitHub
AnsibleAnsible
CrunchyDataCrunchyData
ElasticElastic

User Stories

"How can I determine what security baseline I should measure against?"
Quality security automation content should be tied back to trusted human-readable security guidance, such as baseline documents published by government and industry (e.g., DISA STIGs). Before you can test your software automatically, know not only what you are testing, but why. If there are no existing published baseline guidance documents for your software component, you can research and author your own.
"How do I manage a diverse set of security data?"
Normalization enhances the analysis of security data, facilitating wholistic system security assessments. Converting security tool output to the Heimdall Data Format enables you to aggregate data and visualize the disparate security results across all components of a stack.
"How do I provide sufficient evidence to authorize (or ATO) my system?"
Modern software environments require effective, pervasive automated testing. Each component of the stack – no matter how simple or how complex – should be regularly scanned. Heimdall and the SAF CLI can generate robust reports for your data to illustrate a positive security posture.

MITRE Security Automation Framework (MITRE SAF) is a trademark of The MITRE Corporation. Released under the Apache 2.0 License.