Bounty Hunter: Autonomous, Comprehensive Emulation of Multi-Faceted Adversaries
cs.CR
Submitted: 2025-12-17
Updated: 2026-09-09
Comments: To be published in Digital Threats: Research and Practice '26
Code: https://github.com/fkie-cad/bountyhunter
License: http://creativecommons.org/licenses/by/4.0/
The gist: Adversary emulation is an essential procedure for cybersecurity assessments such as evaluating an organization's security posture or facilitating structured training and research in dedicated
Terminology
Abstract
Adversary emulation is an essential procedure for cybersecurity assessments such as evaluating an organization's security posture or facilitating structured training and research in dedicated environments. To allow for systematic and time-efficient assessments, several approaches from academia and industry have worked towards the automation of adversarial actions. However, they exhibit significant limitations regarding autonomy, tactics coverage, and real-world applicability. Consequently, adversary emulation remains a predominantly manual task requiring substantial human effort and security expertise - even amidst the rise of large language models. In this paper, we present Bounty Hunter, an automated adversary emulation method, designed and implemented as an open-source plugin for the popular adversary emulation platform Caldera, that enables autonomous emulation of adversaries with multi-faceted behavior while providing a wide coverage of tactics. To this end, it realizes diverse adversarial behavior, such as different levels of detectability and varying attack paths across repeated emulations. By autonomously compromising a simulated enterprise network, Bounty Hunter showcases its ability to achieve given objectives without prior knowledge of its target, including pre-compromise, initial compromise, and post-compromise attack tactics. Overall, Bounty Hunter facilitates autonomous, comprehensive, and multi-faceted adversary emulation to help researchers and practitioners in performing realistic and time-efficient security assessments as well as research and training in intrusion detection, incident response, and forensic analysis.
Sources
- SoK: A Survey of Open-Source Threat Emulators
- AutoAttacker: A Large Language Model Guided System to Implement Automatic Cyber-attacks
- From Sands to Mansions: Towards Automated Cyberattack Emulation with Classical Planning and Large Language Models
- LLMs as Hackers: Autonomous Linux Privilege Escalation Attacks
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs