Skip to main content

Adversary Simulation and Breach-and-Attack Simulation

Two terms sold as red teaming that are not. One is a tool that replays known techniques on a schedule; the other is people improvising. Both are useful, for different questions.

2 min read

Both phrases appear in red team proposals, and neither means the same thing as a red team. The distinction is worth twenty minutes because it decides whether you are buying software or people.

Breach-and-attack simulation

A product. You deploy agents across your estate and the platform continuously replays a library of known techniques — credential dumping, a particular lateral movement method, a known exfiltration pattern — then reports which ones your controls stopped or noticed.

What it is genuinely good at: breadth and repetition. It runs hundreds of techniques weekly without getting bored, and catches the day your detection rule silently stopped matching after a platform upgrade. Nothing staffed by humans covers that ground that often.

What it cannot do: anything not in its library, and anything requiring judgement. It will not notice that your service desk resets passwords without verifying identity, and it will not chain three unremarkable findings into a route nobody anticipated. It executes a catalogue.

Adversary simulation

Used two ways, which is most of the confusion.

Sometimes it means emulating a specific named threat actor — taking a group known to target your sector, working from published reporting on how they operate, and reproducing that tradecraft in order. The question is narrower and more useful than "could someone get in": it is could this particular adversary, behaving as they are documented to behave, achieve their objective here.

Sometimes it is simply a politer word for a red team, used because "red team" sounds adversarial to a board. Ask which is meant.

Choosing between them

  • You do not know what your controls detect. Breach-and-attack simulation, or a purple team. Both give coverage across many techniques quickly; a red team answers one route expensively. See purple team: when it beats a red team.
  • You have a specific adversary in mind, because of your sector or something in threat intelligence. Threat-actor emulation.
  • You want to know whether anyone would notice a patient intruder. A red team, and only a red team — what that involves.

The claim to check

A proposal offering "adversary simulation" at red team prices should say which adversary, on what reporting, and which techniques are being reproduced. A team doing threat-actor emulation properly can name the group and cite the source. One using the phrase as a synonym will describe a methodology instead.

Similarly, a "red team" delivered mostly through a breach-and-attack platform is a tool subscription with a report attached. That may be exactly what you need — but it is priced differently, and the team-weeks question exposes it in one line.