Bastion Security

What is Adversary Simulation?

Adversarial simulation exercises are designed to mimic a real-world attacker, simulating their tactics and techniques.
Talk to an expert
August 5, 2026

Adversarial simulation exercises are designed to mimic a real-world attacker, simulating their tactics, techniques, and procedures (TTPs). Where vulnerability scanning and penetration testing focuses on technical vulnerabilities, adversarial simulation can test an organisation’s people, processes, and systems. Assumptions can be challenged, responses evaluated and practiced, and leaders can gain insight into how their company might fare against a real-world attack.

Threat Intelligence-led

Adversarial simulation exercises first start by defining the threat:

  • Which groups are currently targeting your industry or geography?
  • What are their capabilities and motivations? And how are they getting in?

Cyber threat intelligence (CTI) can answer these questions, allowing for the simulation of threats and tactics most relevant to your organisation and sector.

Industry frameworks help to define and categorise attacker behaviour, providing a common language within the industry to define threat actors and their methods. MITRE’s ATT&CK® provides a matrix of common attacker TTPs, with columns denoting tactics and rows containing the techniques and procedures used to achieve that tactic or goal. Threat actors are also given names, examples including Scattered Spider, Volt Typhoon, Fancy Bear, or APT10. Confusingly, different vendors will refer to the same group by different names; Google (Mandiant) have just moved away from the ‘APT#’ scheme to a two-word cryptid naming scheme more in line with other vendors.

It is also worth noting that regulatory frameworks exist to define and oversee adversarial simulation exercises in some regions, often mandated by government and financial regulators. Some examples of such schemes are the CORIE Framework in Australia, CBEST and STAR in the UK, and TIBER in the EU.

Red, Purple, Blue?

Adversarial simulation comes in many different shapes and sizes: red team exercises, purple team exercises, social engineering and phishing simulations, as well as Denial of Service (DoS) testing.

A red team exercise simulates how a threat actor would target your organisation, which could start from an external perspective without any access provided to the red team, or from ceded initial access such as low-privilege credentials or a laptop (Assumed Breach). The exercise is conducted without the blue team’s prior knowledge, ensuring that the blue team’s response to the exercise most accurately reflects how they would respond to a real attack.

Only a few within the targeted organisation would be aware of the exercise happening, referred to as the control group or white team. The control group provides a line of communication between the organisation and the red team for oversight and deconfliction purposes.

Purple teaming allows an approach that is collaborative from the start, where the red team would sit alongside your organisation's blue team and run specific attack scenarios or sequences. After the red team has completed their attack, both sides can then work together to identify gaps in detection or incident response playbooks.

Bastion can also run social engineering campaigns, such as emulating Scattered Spider’s tactics by calling help desks and requesting password and MFA resets for accounts. We also have the capability to create highly convincing deep fake videos and cloned voices, including the ability to deploy these tactics in real time in a Teams video call, for example.  

Conclusion

Adversary simulation exercises move beyond just looking for technical vulnerabilities, testing your organisations detection and response. If you are interested in how your organisation’s response would hold up to a (simulated) real-world attack, contact us.  


Events

Latest events

Join Bastion experts for networking events, technical briefings, and hands-on workshops hosted throughout the year.
View all events
Cyber security news

Latest advisories

Stay ahead of emerging threats with our expert blog posts, research, and industry updates.
Access Token Exposure in URL Parameters in GridTime™ 3000 GNSS Time Server - (CVE-2026-12620)
During a security engagement, Leo Diamat discovered that the GridTime 3000 GNSS Time Server web application transmitted session access tokens via URL query string parameters on multiple endpoints.
Cross-Site Scripting (XSS) Vulnerability on Several Endpoints by Utilising Cross-Site Request Forgery (CSRF) in GridTime™ 3000 GNSS Time Server - (CVE-2026-12619)
During a security engagement, Leo Diamat discovered that multiple endpoints in the GridTime 3000 GNSS Time Server web application were vulnerable to reflected Cross-Site Scripting (XSS) via an unsanitised token parameter.
PHP-FPM (PHP Source) - Stored Cross-Site Scripting (XSS) (CVE-2026-6735)
During a security engagement, Conrad Draper discovered a stored XSS vulnerability in the PHP-FPM status endpoint which was due to a lack of input sanitisation of the request URI. This affects the request URI when displaying stored content.