Offensive Security
Red Team Operations AI Red Teaming OT & IoT Red Teaming Adversary Emulation
AI Automation
AI Automation for Business
Consulting
Advisory & Consulting
Company
Intel About Request a briefing
Line 01 — Offensive Security

Adversary Emulation.

Real adversaries, replicated. We run the tradecraft of named threat actors against your environment — their tools, their patience, their mistakes — and measure exactly what your detection stack sees.

actor_profile.load — APT29
# APT29 — Cozy Bear · MITRE G0016
actor = load_ttp("APT29", provenance="confirmed")

# initial access → persistence → collection
actor.techniques([
    "T1566.002",  # spearphishing link
    "T1078.004",  # valid cloud accounts
    "T1098.001",  # additional credentials
    "T1114.002",  # remote email collection
])

campaign = Campaign(actor, mode="purple")
campaign.deploy(measure="detection_coverage")
01
Service definition

Real adversaries.
Replicated.

Test against who's actually coming

Generic attack simulation tells you whether you'd catch a generic attacker. That isn't the threat. Adversary emulation replicates a specific, named group — the tools they really use, the sequence they really follow, the infrastructure habits they really have — so the result maps to a threat you can name in a board paper.

Every profile is built from confirmed-incident provenance and scored for TTP fidelity, so you know how close the replication is.

The output is a measurement

For every technique we execute, we record whether you detected it, how long it took, and what fired. That produces a detection coverage score against the actor's full kill chain — a number that moves when your defences improve.

Then we re-run the same campaign after your team deploys new content, and show you the delta. Provable improvement, not an opinion.

Full MITRE ATT&CK coverage

Every emulated actor maps to specific ATT&CK techniques. Fourteen tactics, 600+ techniques, fully traceable in your detection content.

Actor library · 28 profiles

Nation-state, e-crime, hacktivist and insider threat profiles — each maintained with confirmed-incident provenance and TTP fidelity scoring.

Purple team mode

Run blind or collaborative — defenders watch our attacks in real time, refine detections, and we re-run for measurable improvement.

Detection engineering output

Every campaign produces Sigma rules, Splunk SPL, Sentinel KQL and Elastic queries — tested against your environment before delivery.

02
How it works

Four phases.
One actor.

Actor selection & profiling

You choose which threat actor to emulate, or we recommend based on your industry threat profile. We brief the operator team on TTPs, infrastructure habits and confirmed-incident behaviour.

Duration3–5 days

Campaign execution

Operators run the actor's full kill chain end to end. Initial access, foothold, escalation, lateral movement, objective — each step performed using the actor's actual tradecraft.

Duration2–3 weeks

Detection gap analysis

For every technique we used, we measure whether you saw it, when you saw it, and what alerted — or didn't. Detection coverage scored against the actor's full kill chain.

DeliverableCoverage score

Re-run & validate

After your team deploys new detection content, we re-run the same campaign and measure improvement. Same actor, same TTPs, different defensive posture. Provable return.

IncludedFree re-run
Sample detection scorecard · APT29 campaign
Initial access · spearphishing link
T1566.002 · 88%
Valid accounts · cloud identity
T1078.004 · 54%
Persistence · additional credentials
T1098.001 · 21%
Collection · remote email access
T1114.002 · 12%
Exfiltration · web service channel
T1567.002 · 47%
03
Actor library

Twenty-eight profiles.
Pick your adversary.

A representative selection. The full library is shared under NDA, and we build new profiles on request where confirmed-incident reporting supports it.

APT29G0016

Cozy Bear. Patient cloud-identity tradecraft, minimal on-disk footprint, long dwell.

Nation-state
LazarusG0032

Persistence and supply-chain compromise, financial and defence targeting.

Nation-state
FIN7G0046

Disciplined e-crime operation. Point-of-sale, hospitality and retail intrusion.

E-crime
APT41G0096

Dual espionage and financially motivated operations across a wide victim set.

Nation-state
Scattered SpiderG1015

Social engineering against help desks, MFA fatigue, rapid identity takeover.

E-crime
SandwormG0034

Destructive operations against industrial control and critical infrastructure.

Nation-state
04
What you get

Three artefacts.
Measurable defence.

01

The Threat Brief

Plain-language summary of the campaign, your detection posture against the chosen actor, and how it compares to industry peers.

02

The Operator Log

Every TTP executed, every detection or non-detection, every artefact. Engineering-ready, MITRE-mapped and fully reproducible.

03

The Detection Pack

For every gap, ready-to-deploy detection content tested against your environment. Vendor-specific and false-positive validated.

05
Engagement models

Three ways to test.

Scope, timeline and cost are all set in a threat-modelling session under NDA.

Single actor
Custom quote
One campaign · 3 weeks
  • One actor most relevant to your industry
  • Full kill chain emulated end to end
  • Detection scorecard delivered
  • Detection pack for every gap found
  • Free re-run after remediation
Pick one actor
Threat-modelled panel
Custom quote
3–4 actors · 8–12 weeks
  • Industry threat landscape profiled first
  • Three to four most-likely actors selected
  • Each emulated in sequence
  • Full purple-team collaboration optional
  • Comparative coverage across all actors
Most common
Persistent emulation
Custom quote
Retainer · 12 months
  • Quarterly campaigns against rotating actors
  • Detection content updated continuously
  • Coverage trend tracked over time
  • Quarterly board briefings on readiness
Discuss a retainer
06
Common questions

Before you engage.

How is this different from a red team engagement?

A red team operation asks whether we can reach an objective by any means. Adversary emulation asks a narrower, more measurable question: against this specific actor's known tradecraft, what does your detection stack catch? Red teaming tests resilience; emulation tests detection coverage. Many clients buy both, in that order.

Should we run it blind or as a purple team?

Blind gives you an honest baseline of what your SOC catches unprompted. Purple mode — defenders watching in real time — produces far more improvement per pound, because gaps get closed the same day they're found. Most clients run the first campaign blind for the baseline, then purple for every campaign after.

Which actor should we choose?

If you don't have a view, we'll build one: sector, geography, data types held and public incident history usually narrow it to three or four credible candidates within a session. Choosing an actor that has never targeted anyone like you produces a comfortable score and no useful information.

Do you use the actor's real malware?

We replicate behaviour, not binaries. Campaigns use our own tooling configured to produce the same observable techniques, artefacts and sequencing as the actor — which is what your detection content matches on. Running genuine malware samples in a client environment is not something we'll do.

How quickly can you start?

Threat-modelling sessions begin under NDA, with a written briefing delivered within 72 hours. Typical lead time from signature to campaign start is three weeks.

The adversary coming for you
has a name.

Threat-modelling sessions run under NDA, with a written briefing inside 72 hours. Let's work out who's actually looking at you.