Adversary Emulation
Running a known technique against your own estate on purpose, then reading what the defence did: telemetry, rule, triage, response. Interviewers use it to tell asserted coverage from proven coverage.
on this pageshowhide
explore
- Designing the Exercise12 questions
- Red, Purple or Pentest4 questions
- Choosing What to Emulate4 questions
- Authorisation and Deconfliction4 questions
- Against Live Defences12 questions
- Where the Chain Broke4 questions
- Blocked, Seen or Missed4 questions
- Atomic Tests and C24 questions
- Turning Results Into Coverage12 questions
- Tune and Retest Loop4 questions
- Routing Proven Gaps4 questions
- Regression by Re-Execution4 questions
questions
page 2 of 2A red-team report says every test artefact was removed. What do you require before accepting that?
basics
~20 sAn itemised inventory of everything planted — files, persistence, accounts, credentials, exclusions — each with host, identifier and evidence of removal; then your own hunt for every item. What you cannot find is a visibility gap.
Your SIEM does not ingest the identity provider's consent-grant audit log - do you still emulate that technique?
basics
~20 sUsually no. Executing a behaviour whose only observation surface is uncollected buys a miss you already predicted. The gap is the finding, recorded at design time, and the slot goes to a technique that can discriminate.
How do you tell whether the SOC detected your emulation technique or just the operator's noise?
basics
~10 sRead which rule fired and what it keyed on. A threshold or a burst window is a detection of the pass, not the technique. Re-run it paced, from another host and account.
A platform team that reports elsewhere refuses the preventive fix your exercise proved — how do you proceed?
basics
~20 sYou have evidence, not authority. Find out which refusal it is — disbelief, breakage fear, or priority — and answer that one. Take the cheaper destination you can land yourself, and if they still refuse, convert the gap into a written acceptance signed by someone who can carry the risk.
One annual red team or continuous automated validation: which do you buy for a one-analyst SOC with an MSSP?
basics
~20 sBuy continuous validation first while the detection baseline is unknown: it attributes each miss and catches regressions. Buy the red team once the basics reliably alert, so the engagement spends its money on what automation cannot test.
Your emulation miss traces to absent auditd rules on one host image — who owns the finding, and how do you make that stick?
basics
~20 sThe image and platform owners, not the detection team. Make it stick by scoping the finding to the host class with control-host evidence, naming an owner who can change the image, and setting the acceptance test as re-executing the technique.
showing 31–36 of 36