What is an assumed-breach start, and which detections can it never test compared with earned initial access?
answer
- the exercise starts after the door
- granted foothold or issued credentials
- the edge emits nothing about it
- silence there is not a pass
- time certainty bought with lost coverage
basics
~20 sAn assumed-breach engagement begins with the operator already holding a foothold or valid credentials, so everything up to initial access is skipped. The edge and phishing detections are never exercised, and their silence proves nothing about them.
solid answer
~50 sIn an assumed-breach start the client hands the operator the beginning: an implant placed on a managed workstation by agreement, or a valid low-privilege account. It buys time and certainty — the internal technique set you actually wanted measured definitely gets exercised, instead of the operator burning three weeks failing to get in. The cost is that initial access leaves the exercise entirely. Nothing reaches the internet-facing remote-access appliance's own authentication log, nothing attributable appears in perimeter flow records at the ingress point, and no phishing or exploit-attempt control is touched. That silence is not a pass; those surfaces were never asked a question, and the report's limitations section has to say so. Earned access tests the edge for real, but is unbounded in time and gives you one operator's sample from one fortnight. The usual compromise is a time-boxed attempt with a granted foothold as the contractual fallback.
go deeper
Know the phrase itself: the operator is given the starting foothold, so the exercise measures what happens after access rather than how access was obtained.
Explain concretely which surfaces go quiet — the remote-access appliance's authentication log, ingress flow records, phishing and exploit-attempt controls — and why that silence carries no information in either direction.
Argue the trade in front of a sponsor: budget certainty and guaranteed internal coverage against a genuinely untested perimeter, and design the time-boxed hybrid that recovers both where it matters.
Decide what the organisation is content to leave unmeasured this year, and require the limitations section to be drafted before the engagement rather than negotiated after the result.
## What "assumed breach" actually changes An **assumed-breach** engagement begins after initial access. By agreement, the client hands the operator the starting position: an implant installed on a managed workstation, a standard build to work from, or a valid low-privilege account. The exercise then measures what happens *after* someone is inside — discovery, credential access, lateral movement, persistence, collection, exfiltration. ### Why anyone would design it that way Time and certainty. Earning access is unbounded work: the operator may spend the whole engagement probing an internet-facing edge and never get in, and you will have paid a full engagement fee to learn that the perimeter held that week against that operator. An assumed-breach start guarantees the internal technique set — usually the thing the client actually wanted measured — is exercised. It is also the standard start for a purple exercise, where the point is per-technique detection evidence rather than a path. ### The cost, stated precisely Everything up to and including initial access is **outside the exercise**, and therefore unmeasured: - The internet-facing remote-access appliance's own authentication log records nothing about the exercise, because no credential was presented to it. - Perimeter flow records at the ingress point contain nothing attributable to it. (Those records carry the five-tuple, byte and packet counts and timestamps — they can show that a session existed and how much moved, and they carry no payload at all, so they never show what moved.) - Exploit-attempt detection on the public surface, phishing controls on the mail platform, and every preventive control at the edge are untouched. The trap is the report's reader. "No perimeter detections fired during the engagement" is true and worthless, and an executive will hear "the perimeter held". Absence of a signal on a surface that was never asked a question is not a pass; it is an untested surface. Say so in the limitations section, and write that section before you know the result. ### What earned access buys instead An earned-access engagement — the operator must find and use a real route in — tests the initial-access detections and the preventive controls for real, and it produces genuine artefacts on the edge surfaces: a successful authentication on the appliance from an unusual source, a session in the ingress flow records with byte counts consistent with a tunnel. Note the direction of claim even then: a successful authentication event proves **a credential was accepted**, not that the legitimate owner was present. Its costs are the mirror image. It is unbounded in time; it may consume the budget before any internal technique runs; the result depends heavily on what happened to be patch-current that fortnight; and a failure to get in is weak evidence, because it is one operator's sample. ### The hybrid most mature programmes buy Time-box the earned attempt, with a granted foothold as a contractual fallback: "if no access by day five, we place an implant on an agreed host and continue". You keep a genuine test of initial access while guaranteeing the rest of the technique set gets measured, and the report can honestly separate the two halves. ### One artificiality worth telling the SOC If defenders detect the assumed-breach implant and investigate, their investigation will dead-end: there is no upstream story, because there was no intrusion into the estate. A competent analyst will keep digging for an origin that does not exist. Debrief that explicitly, or the exercise quietly teaches the team that a missing entry point is normal — and record it as a known artificiality of the design rather than as a gap in the analyst's tradecraft.
- What does the edge actually record when access is earned through an internet-facing remote-access appliance?Two independent surfaces. The appliance's own authentication log shows a credential being accepted or rejected with the source address — which proves a credential was accepted, not that its owner was present. Perimeter flow records show a session at the ingress with byte and packet counts and timestamps, and carry no payload at all, so they can show a tunnel was built and never what went through it.
- Your assumed-breach exercise ran and no perimeter alerts fired. What may the report say?That the perimeter was out of scope and remains unmeasured. Writing that no perimeter detections fired invites the reader to hear that the perimeter held. Name the untested surfaces explicitly in the limitations section, and write that section before the result is known — the next reader is an executive deciding where the following engagement's money goes.
- An analyst investigates the assumed-breach implant and cannot find how the host was compromised. Is that an investigative failure?No, it is an artefact of the design: there is no upstream story, so a competent investigation dead-ends at the entry point. Debrief it explicitly and record it as a known artificiality, otherwise the exercise quietly teaches the team that a missing origin is normal.
saying these in an interview costs you the question
- Reads absent perimeter alerts as evidence the perimeter held
- Thinks assumed breach means the operator cheated
- Believes ingress flow records carry payload content
- Says a successful appliance logon proves the real user connected
- Assumes earned access always produces the better evidence