skip to content

Adversary Emulation

Running a known technique against your own estate on purpose, then reading what the defence did: telemetry, rule, triage, response. Interviewers use it to tell asserted coverage from proven coverage.

on this pageshow

explore

questions

page 2 of 2

A red-team report says every test artefact was removed. What do you require before accepting that?

level: seniorimportance: nice to knowfreq 34%

basics

~20 s

An itemised inventory of everything planted — files, persistence, accounts, credentials, exclusions — each with host, identifier and evidence of removal; then your own hunt for every item. What you cannot find is a visibility gap.

open as a page

Your SIEM does not ingest the identity provider's consent-grant audit log - do you still emulate that technique?

level: seniorimportance: nice to knowfreq 31%

basics

~20 s

Usually no. Executing a behaviour whose only observation surface is uncollected buys a miss you already predicted. The gap is the finding, recorded at design time, and the slot goes to a technique that can discriminate.

open as a page

How do you tell whether the SOC detected your emulation technique or just the operator's noise?

level: seniorimportance: nice to knowfreq 34%

basics

~10 s

Read which rule fired and what it keyed on. A threshold or a burst window is a detection of the pass, not the technique. Re-run it paced, from another host and account.

open as a page

A platform team that reports elsewhere refuses the preventive fix your exercise proved — how do you proceed?

level: principalimportance: nice to knowfreq 34%

basics

~20 s

You have evidence, not authority. Find out which refusal it is — disbelief, breakage fear, or priority — and answer that one. Take the cheaper destination you can land yourself, and if they still refuse, convert the gap into a written acceptance signed by someone who can carry the risk.

open as a page

One annual red team or continuous automated validation: which do you buy for a one-analyst SOC with an MSSP?

level: principalimportance: nice to knowfreq 34%

basics

~20 s

Buy continuous validation first while the detection baseline is unknown: it attributes each miss and catches regressions. Buy the red team once the basics reliably alert, so the engagement spends its money on what automation cannot test.

open as a page

Your emulation miss traces to absent auditd rules on one host image — who owns the finding, and how do you make that stick?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

The image and platform owners, not the detection team. Make it stick by scoping the finding to the host class with control-host evidence, naming an owner who can change the image, and setting the acceptance test as re-executing the technique.

open as a page

showing 31–36 of 36