Adversary Emulation

Pick an adversary, run the playbook, prove the coverage.

Breach and attack simulation aligned with MITRE ATT&CK, driven by an AI operator on the same agent you already use for pentests. Browse a curated library of real-world adversaries, reuse the kill chain step by step, and watch every technique land on a live timeline. Run dry to storyboard the attack on paper, or run live to actually exercise your detections, end to end.

Start a dry-run Browse adversary gallery

From a picked adversary to a complete kill chain

No bespoke tooling, no scripts to maintain. Pick a playbook, the operator walks the techniques, and the platform records every action with evidence you can replay later.

1
Pick or import an adversary
Start from the gallery (APT29, FIN7, Volt Typhoon, ransomware operator, insider threat) or build a custom adversary by chaining MITRE techniques in any order. Versioned, editable, reusable.
2
Reuse the agent you already deploy
Same network agent that runs internal pentests handles emulations. One install, two workflows. Bound to a single emulation at a time so a live engagement never collides with another job.
3
Pick dry-run or live
Dry-run produces a narrative storyboard with no commands hitting any host. Live mode wires up agent_exec, runs the real techniques, captures cumulative output per action, and respects a soft retry cap so a stubborn step never burns the engagement.
4
Watch every action with evidence
Each step opens a bound action. Output appends across retries so corrections stay visible. The phase gate refuses to mark the emulation complete until every required step has a final status.

The whole ATT&CK Enterprise matrix, refreshed from the source

222 active top-level techniques across 14 tactics, synced from the official ATT&CK STIX bundle. Highlighted cells are techniques that at least one adversary in the gallery below already covers, so you can see at a glance where your simulations land.

Synced 2 months ago Coverage from gallery: 100 / 222 techniques
Reconnaissance
TA0043
12 techniques
T1589 Gather Victim Identity Information
T1590 Gather Victim Network Information
T1591 Gather Victim Org Information
T1592 Gather Victim Host Information
T1593 Search Open Websites/Domains
T1594 Search Victim-Owned Websites
T1595 Active Scanning
T1596 Search Open Technical Databases
T1597 Search Closed Sources
T1598 Phishing for Information
T1681 Search Threat Vendor Data
T1682 Query Public AI Services
Resource Development
TA0042
9 techniques
T1583 Acquire Infrastructure
T1584 Compromise Infrastructure
T1585 Establish Accounts
T1586 Compromise Accounts
T1587 Develop Capabilities
T1588 Obtain Capabilities
T1608 Stage Capabilities
T1650 Acquire Access
T1683 Generate Content
Initial Access
TA0001
11 techniques
T1078 Valid Accounts
T1091 Replication Through Removable Media
T1133 External Remote Services
T1189 Drive-by Compromise
T1190 Exploit Public-Facing Application
T1195 Supply Chain Compromise
T1199 Trusted Relationship
T1200 Hardware Additions
T1566 Phishing
T1659 Content Injection
T1669 Wi-Fi Networks
Execution
TA0002
20 techniques
T1047 Windows Management Instrumentation
T1053 Scheduled Task/Job
T1059 Command and Scripting Interpreter
T1072 Software Deployment Tools
T1106 Native API
T1127 Trusted Developer Utilities Proxy Execution
T1129 Shared Modules
T1197 BITS Jobs
T1203 Exploitation for Client Execution
T1204 User Execution
T1559 Inter-Process Communication
T1569 System Services
T1574 Hijack Execution Flow
T1609 Container Administration Command
T1610 Deploy Container
T1648 Serverless Execution
T1651 Cloud Administration Command
T1674 Input Injection
T1675 ESXi Administration Command
T1677 Poisoned Pipeline Execution
Persistence
TA0003
22 techniques
T1037 Boot or Logon Initialization Scripts
T1053 Scheduled Task/Job
T1078 Valid Accounts
T1098 Account Manipulation
T1112 Modify Registry
T1133 External Remote Services
T1136 Create Account
T1137 Office Application Startup
T1176 Software Extensions
T1197 BITS Jobs
T1205 Traffic Signaling
T1505 Server Software Component
T1525 Implant Internal Image
T1542 Pre-OS Boot
T1543 Create or Modify System Process
T1546 Event Triggered Execution
T1547 Boot or Logon Autostart Execution
T1554 Compromise Host Software Binary
T1556 Modify Authentication Process
T1653 Power Settings
T1668 Exclusive Control
T1671 Cloud Application Integration
Privilege Escalation
TA0004
13 techniques
T1037 Boot or Logon Initialization Scripts
T1053 Scheduled Task/Job
T1055 Process Injection
T1068 Exploitation for Privilege Escalation
T1078 Valid Accounts
T1098 Account Manipulation
T1134 Access Token Manipulation
T1484 Domain or Tenant Policy Modification
T1543 Create or Modify System Process
T1546 Event Triggered Execution
T1547 Boot or Logon Autostart Execution
T1548 Abuse Elevation Control Mechanism
T1611 Escape to Host
Defense Evasion
0 techniques
No techniques synced yet
Credential Access
TA0006
17 techniques
T1003 OS Credential Dumping
T1040 Network Sniffing
T1056 Input Capture
T1110 Brute Force
T1111 Multi-Factor Authentication Interception
T1187 Forced Authentication
T1212 Exploitation for Credential Access
T1528 Steal Application Access Token
T1539 Steal Web Session Cookie
T1552 Unsecured Credentials
T1555 Credentials from Password Stores
T1556 Modify Authentication Process
T1557 Adversary-in-the-Middle
T1558 Steal or Forge Kerberos Tickets
T1606 Forge Web Credentials
T1621 Multi-Factor Authentication Request Generation
T1649 Steal or Forge Authentication Certificates
Discovery
TA0007
34 techniques
T1007 System Service Discovery
T1010 Application Window Discovery
T1012 Query Registry
T1016 System Network Configuration Discovery
T1018 Remote System Discovery
T1033 System Owner/User Discovery
T1040 Network Sniffing
T1046 Network Service Discovery
T1049 System Network Connections Discovery
T1057 Process Discovery
T1069 Permission Groups Discovery
T1082 System Information Discovery
T1083 File and Directory Discovery
T1087 Account Discovery
T1120 Peripheral Device Discovery
T1124 System Time Discovery
T1135 Network Share Discovery
T1201 Password Policy Discovery
T1217 Browser Information Discovery
T1482 Domain Trust Discovery
T1497 Virtualization/Sandbox Evasion
T1518 Software Discovery
T1526 Cloud Service Discovery
T1538 Cloud Service Dashboard
T1580 Cloud Infrastructure Discovery
T1613 Container and Resource Discovery
T1614 System Location Discovery
T1615 Group Policy Discovery
T1619 Cloud Storage Object Discovery
T1622 Debugger Evasion
T1652 Device Driver Discovery
T1654 Log Enumeration
T1673 Virtual Machine Discovery
T1680 Local Storage Discovery
Lateral Movement
TA0008
9 techniques
T1021 Remote Services
T1072 Software Deployment Tools
T1080 Taint Shared Content
T1091 Replication Through Removable Media
T1210 Exploitation of Remote Services
T1534 Internal Spearphishing
T1550 Use Alternate Authentication Material
T1563 Remote Service Session Hijacking
T1570 Lateral Tool Transfer
Collection
TA0009
17 techniques
T1005 Data from Local System
T1025 Data from Removable Media
T1039 Data from Network Shared Drive
T1056 Input Capture
T1074 Data Staged
T1113 Screen Capture
T1114 Email Collection
T1115 Clipboard Data
T1119 Automated Collection
T1123 Audio Capture
T1125 Video Capture
T1185 Browser Session Hijacking
T1213 Data from Information Repositories
T1530 Data from Cloud Storage
T1557 Adversary-in-the-Middle
T1560 Archive Collected Data
T1602 Data from Configuration Repository
Command and Control
TA0011
18 techniques
T1001 Data Obfuscation
T1008 Fallback Channels
T1071 Application Layer Protocol
T1090 Proxy
T1092 Communication Through Removable Media
T1095 Non-Application Layer Protocol
T1102 Web Service
T1104 Multi-Stage Channels
T1105 Ingress Tool Transfer
T1132 Data Encoding
T1205 Traffic Signaling
T1219 Remote Access Tools
T1568 Dynamic Resolution
T1571 Non-Standard Port
T1572 Protocol Tunneling
T1573 Encrypted Channel
T1659 Content Injection
T1665 Hide Infrastructure
Exfiltration
TA0010
9 techniques
T1011 Exfiltration Over Other Network Medium
T1020 Automated Exfiltration
T1029 Scheduled Transfer
T1030 Data Transfer Size Limits
T1041 Exfiltration Over C2 Channel
T1048 Exfiltration Over Alternative Protocol
T1052 Exfiltration Over Physical Medium
T1537 Transfer Data to Cloud Account
T1567 Exfiltration Over Web Service
Impact
TA0040
15 techniques
T1485 Data Destruction
T1486 Data Encrypted for Impact
T1489 Service Stop
T1490 Inhibit System Recovery
T1491 Defacement
T1495 Firmware Corruption
T1496 Resource Hijacking
T1498 Network Denial of Service
T1499 Endpoint Denial of Service
T1529 System Shutdown/Reboot
T1531 Account Access Removal
T1561 Disk Wipe
T1565 Data Manipulation
T1657 Financial Theft
T1667 Email Bombing
Covered by at least one gallery adversary Available in the matrix, not covered by gallery Scroll horizontally and vertically. Click any technique to copy its ID.

Storyboard the attack, then run it for real

Most teams should start dry-run, walk the kill chain on paper with the SOC, and only flip to live mode once expectations are aligned. Both modes share the same playbook and the same UI.

What the operator does

  • Walks every step of the picked adversary in sequence, narrating intent and expected detection signals.
  • Writes a full action log per step with the command it would have run, marked clearly as a simulation.
  • Refuses to call agent_exec. The tool is hard-disabled so nothing reaches a live host by accident.
  • Outputs a complete kill chain narrative your SOC can review before authorising a live run.

Best for

  • Tabletop exercises with the blue team.
  • Validating a custom adversary playbook before pointing it at production.
  • Generating board-ready evidence of MITRE coverage without operational risk.
  • Detection engineering: "if this attacker hits us, what should we have caught?"
[dry-run] T1003 - OS Credential Dumping > would invoke: lsass.exe MiniDump via comsvcs.dll > expected detection: Sysmon ID 10, EDR memory access alert

What the operator does

  • Calls agent_exec on the bound network agent. Real commands run on the host you authorised.
  • Streams output back to the action log. Every retry appends, so corrections stay readable.
  • Honours a per-action soft retry cap. After 25 attempts the operator is forced to mark the step and move on.
  • Refuses to run if the bound action is already terminal, so a successful step never gets clobbered by a stray retry.

Use it for

  • Purple team exercises with both sides watching the timeline.
  • SOC drills against a real adversary playbook, not synthetic noise.
  • Validating a fresh SIEM rule by triggering its target technique on cue.
  • Acquisition due diligence: prove what an attacker can actually do once they get a foothold.
[live] T1003.001 - LSASS Memory $ comsvcs.dll MiniDump 612 C:\Windows\Temp\m.dmp full => success; dump size 60.4 MB; cumulative output preserved

Built like the rest of the platform: agentic, MCP-driven, auditable

MITRE-aligned playbooks
Every step references a real ATT&CK technique. The platform pulls names, descriptions, and platform tags directly from the synced catalog, so reports match what your SOC reads in their other tools.
Dry-run by default, live mode opt-in
Every emulation starts as a dry-run unless the operator explicitly flips it. Going live requires a bound agent and an authorised host. agent_exec is hard-disabled in dry mode, so an accidental setting cannot leak commands to production.
Action-bound evidence
Each step opens a bound action. Output from every retry appends to the same record, so the operator's first failed attempt and the successful correction live next to each other. Soft cap of 25 retries per action keeps a flaky step from running away with the engagement.
Phase-gated execution
An emulation cannot be marked complete while any step is still pending. Each step ends as success, failure, or skipped with a written reason. No half-walked kill chain dressed up as a finished engagement.
Reuses the pentest agent
Same enrolment flow, same heartbeat, same network plumbing as our internal pentest product. One agent install on a host you control covers both workflows. The session allocator makes sure an emulation never collides with an active engagement on the same agent.
Per-tenant adversary library with versioning
Forked from a MITRE group or built from scratch, every adversary lives in your workspace as a versioned artefact. Edits create a new revision, older versions remain replayable, restoring an old version creates a fresh revision without rewriting history.

Adversary emulation is how you turn ATT&CK from a poster into evidence

Validate detections without scheduling a red team
Pick an adversary, run live, watch the SIEM. Either the rule fires on T1003 or it does not. Cheaper than an external red team, faster than an internal exercise, and reproducible whenever you change a detection.
Show coverage to executives in language they read
"We can detect 78 of the 102 techniques used by APT29" beats a dashboard of charts. The platform produces a coverage view per adversary, per tactic, with timestamps, so the board sees a real number tied to a real adversary.
Train the blue team against a moving target
Schedule a different adversary every month. Same UI, same evidence, different TTPs. Analysts get reps against techniques they would otherwise only read about, and the playbook stays close to real-world tradecraft.
Confirm a SIEM rule before you trust it
A new detection rule for kerberoasting is only useful if it actually fires on kerberoasting. Run a one-step emulation that just executes T1558.003 on cue, watch the alert pipeline, then commit the rule with confidence.

What the platform brings to the table

Pulled directly from the engine. Every emulation runs on these primitives, regardless of which adversary you pick.

MITRE ATT&CK Enterprise 14 tactics covered Curated adversary gallery Custom adversary builder Per-tenant versioning Atomic Red Team compatible Action-level evidence Cumulative retries Soft retry cap (25) Dry-run storyboard Live agent execution Phase-gated completion Bound action lifecycle MCP server architecture Reuses pentest agent Session allocator Windows + Linux targets Hybrid playbooks SOC validation Detection engineering Purple team exercises

Run a real adversary on your own infrastructure

Pick a playbook from the gallery, install the agent if you have not already, and let the operator walk the techniques. Start dry, go live when the SOC is ready.

Have questions? Get in touch →