Installation - Windows

Warning

MACAT may not work properly if you do not follow all instructions including adding a Windows Defender exception.

Atomic Red Team content and MITRE Enteprise ATT&CK data may be quarantined on download, and your installation will be broken.

Installation Steps for Windows

  1. Download the latest version of MACAT for Windows from the official website or GitHub releases page.
  2. Note that it’s easiest to run MACAT with a Defender folder exception and your endpoint tools in detect-only or passive mode. If you don’t create a folder exception, it’s likely that Defender will quarantine Atomic Red Team content and possibly the MITRE Attack Framework json file. This will break MACAT’s content sync. I’m investigating creating a version that ships with this content prepopulated, but it’s not ready yet.
  3. To add a Windows Defender exception, go to Windows Settings > Virus & Threat Protection > Virus & Threat Protection settings [Manage Settings] > Scroll down to Add / Remove Exclusions > Add Exclusion for MACAT’s install directory.
  4. Install to your chosen location like C:\MACAT
  5. Run MACAT