Exposure discovery EU-developed

OpenAEV

Adversarial exposure validation platform for planning and running attack simulations, measuring defensive coverage, and tracking remediation against tested scenarios.

By Filigran · France

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Exposure discovery
Developer or maintainer
Filigran
Recorded country
France
Product model
Open core
Deployment
Self-hosted / SaaS
Software license
Mixed: Apache-2.0 Community Edition; OpenAEV Enterprise Edition License
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

Designed and developed by French company Filigran; formerly named OpenBAS.

Reported capabilities

  • Runs simulation campaigns and individual tests against selected targets.
  • Reports validation results to help prioritize remediation.
  • Community Edition is Apache-2.0; Enterprise Edition has a separate license.

Scope and limits

OpenBAS is the previous name, not a separate product. Adversary validation is an imperfect fit for the current Exposure discovery workflow label.

Inspect the research evidence 6 source observations
  1. identity / origin / capabilities / deployment / maintenance

    The upstream README describes simulation and validation functions, names Filigran as designer/developer, documents Docker/manual installation, and says development is ongoing.

    Read source
  2. country

    Filigran's current privacy policy identifies Filigran SAS as its French group entity at 66 avenue des Champs Élysées, Paris.

    Read source
  3. license

    The license identifies Apache-2.0 for Community Edition and a distinct proprietary Enterprise Edition license.

    Read source
  4. identity

    Filigran explicitly says OpenBAS was renamed OpenAEV; it is not an additional independent product.

    Read source
  5. deployment

    Filigran offers self-hosted Community and Enterprise editions plus a fully managed OpenAEV Enterprise Edition SaaS service, separate from its trial.

    Read source
  6. license

    Filigran's current license page links a separate OpenAEV Enterprise Edition agreement and says Community Edition remains Apache-2.0.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Scope exposure discovery, validate vulnerability findings, prioritize affected assets and verify remediation. Practical guidance with documented European tools.

From vulnerability finding to verified remediation