skip to content

When do you choose atomic single-technique tests over one full-chain emulation campaign?

level: middleimportance: must knowfreq 57%

answer

  1. one behaviour, or one story
  2. diagnosis versus realism
  3. isolation removes noise and preceding activity
  4. a chain caught at stage two
  5. the claim you owe picks the shape

basics

~20 s

Choose atomic tests when the question is which behaviours you can see, because each result is isolated and diagnosable. Choose a chained campaign when the question is whether people and process turn a realistic sequence into a verdict.

solid answer

~50 s

An atomic test executes one behaviour in isolation, so a failure is attributable to the telemetry, the rule or the response, and it is cheap to repeat as a regression check. Isolation is artificial, though: the behaviour arrives with no preceding activity and no competing noise. A full-chain campaign runs an ordered sequence at realistic tempo, which is the only way to test correlation across stages, analyst triage under uncertainty, and hand-offs while activity is live. Its weaknesses are sampling and attribution: it is one run, and if you are contained at stage two the later stages never executed, so nothing can be claimed about them. The claim you owe decides the shape - "which of these behaviours do we see" is atomic, "would we have stopped this crew" is a chain - and many programmes run atomics first, then chain to test the loop.

go deeper

for a junior

Know the difference in plain terms: an atomic test runs one behaviour on its own, a chained campaign runs a realistic sequence end to end, and they are chosen for different reasons.

for a middle

Explain the mechanics: why isolation makes an atomic result attributable and repeatable, and why a chain is the only shape that exercises correlation, triage under uncertainty and hand-offs between stages.

for a senior

Show judgment about the confound - what a chain contained at stage two can and cannot claim - and design a plan that uses atomics for diagnosis and regression before spending a chain on the end-to-end question.

for a principal

Own how exercise budget splits between repeatable breadth and one expensive realistic run, and make sure the reporting never lets a narrative chain finding be trended as if it were a measurement.

## The two shapes **Atomic test.** One technique, executed on its own, with a defined precondition, a defined observable and a defined success criterion. It is small enough to run repeatedly, to script, and to diff against last quarter's result. **Full-chain campaign.** A sequence of techniques in the order and roughly the tempo a real intrusion would follow - initial access, then whatever the profile says comes next, through to the objective. It is one continuous story rather than a set of independent experiments. Both are legitimate; they answer different questions, and choosing between them is a selection decision made before anything runs. ## What each can honestly claim An atomic result supports a narrow, strong statement: *this behaviour, implemented this way, on this date, produced this telemetry, and this rule fired or did not*. Because nothing else was happening, the result is attributable - a failure is localisable to a missing log source, a missing rule, or an unworked alert. A chain result supports a broad, weaker statement: *this sequence, run this once, was or was not turned into a verdict within this time*. It is weaker because it is a single sample under one set of conditions, and because a result at stage five is entangled with everything that happened at stages one to four. It is broader because it is the only shape that exercises the things that only exist between stages: correlation across data sources, an analyst deciding that two mediocre signals together are worth escalating, a hand-off between shifts while the activity is still live. ## The confound that catches people out If a six-stage chain is contained at stage two, stages three to six did not run under realistic conditions. Teams routinely report the whole chain as "tested" because it was planned, which is a fabrication. There are two defensible options, and both must be stated in the report: - **Stop.** The exercise answered its question - the intrusion was caught early - and the later stages remain unmeasured. - **Continue by prior agreement.** The operator resumes from an assumed position after the defenders have been told, and every result from that point is labelled as executed under artificial conditions, because a real adversary would already have lost access. What you cannot do is average the two and present one coverage claim. ## Cost, repeatability and trending Atomic tests are cheap enough to run many of, which means you can cover breadth, cover several **variants** of the same behaviour, and re-run them after a rule change to check for regressions. That repeatability is what makes them trendable: a number that moves for a comprehensible reason. A chain is expensive, disruptive and hard to repeat identically, so its output is a narrative finding rather than a metric. Trending single chain runs across quarters is close to meaningless, because the conditions differ every time - different staffing, different noise, different estate. ## An illustration Suppose the profile describes an identity-and-SaaS route: consent phishing, a token granted to an application, then paced collection out of mailboxes. - **As atomics**: one test grants a consent and checks whether the identity provider's grant audit record is collected and alerted; a second uses a token to read a seeded mailbox and checks whether the tenant's audit trail shows it. You learn precisely which of the two surfaces you can see. - **As a chain**: the consent happens, days pass, the collection starts slowly, and you learn whether anybody joined the grant to the later reads and called it an intrusion. If nobody did, you learn something the atomics cannot tell you - both signals may have existed and still not have been assembled into a verdict. Notice that the atomic version can pass on both tests while the chain still fails. That gap is the reason mature programmes run both. ## How to decide Ask what claim you owe the sponsor. | The question asked | The shape that answers it | | --- | --- | | Which of these behaviours produce evidence we can see? | Atomic | | Did a rule change break detections that used to work? | Atomic, re-run | | How narrow is our detection for this behaviour? | Atomic variants | | Would this crew's sequence be turned into a verdict? | Chain | | Does correlation and hand-off work while activity is live? | Chain | A common and defensible plan is atomics first to establish per-technique visibility, fixes applied, then a chain to test whether the loop assembles those signals into a decision. The reverse order is defensible too when the sponsor's question is genuinely end-to-end and nobody wants a diagnosis yet.

  • A six-stage chain is contained at stage two. What can you report about the remaining stages?
    Nothing, unless you resume them by prior agreement and label them as executed under artificial conditions. Planning a stage is not testing it. The honest report says the intrusion was caught at stage two, lists the unmeasured stages, and either schedules them as atomics or notes them as open.
  • Why is a passing atomic test a weaker result than it looks?
    It ran in isolation: no preceding stages, no competing noise, and often an analyst who knows a test is happening. Real activity arrives buried in a queue with a different base rate, so a rule that fires cleanly in isolation can still fail to produce a verdict in production.
  • Which shape gives you a number you can trend across quarters?
    Atomics. They are repeatable enough that a change in the result usually reflects a change in the estate rather than in the conditions. A chain run is a single sample under conditions that differ every time, so its value is the narrative finding, not a trend line.

Atomic tests are unit tests and a chained campaign is one end-to-end run: the unit tests tell you which part is broken, the end-to-end run tells you whether the whole thing works, once.

saying these in an interview costs you the question

  • Says a chained campaign is always more valuable than atomics
  • Counts planned stages as tested after early containment
  • Trends single chain runs as if they were a metric
  • Picks the shape before knowing what claim is owed
  • Runs one implementation per technique and calls the behaviour covered

context