Adversarial simulation exercises are designed to mimic a real-world attacker, simulating their tactics, techniques, and procedures (TTPs). Where vulnerability scanning and penetration testing focuses on technical vulnerabilities, adversarial simulation can test an organisation’s people, processes, and systems. Assumptions can be challenged, responses evaluated and practiced, and leaders can gain insight into how their company might fare against a real-world attack.
Threat Intelligence-led
Adversarial simulation exercises first start by defining the threat:
- Which groups are currently targeting your industry or geography?
- What are their capabilities and motivations? And how are they getting in?
Cyber threat intelligence (CTI) can answer these questions, allowing for the simulation of threats and tactics most relevant to your organisation and sector.
Industry frameworks help to define and categorise attacker behaviour, providing a common language within the industry to define threat actors and their methods. MITRE’s ATT&CK® provides a matrix of common attacker TTPs, with columns denoting tactics and rows containing the techniques and procedures used to achieve that tactic or goal. Threat actors are also given names, examples including Scattered Spider, Volt Typhoon, Fancy Bear, or APT10. Confusingly, different vendors will refer to the same group by different names; Google (Mandiant) have just moved away from the ‘APT#’ scheme to a two-word cryptid naming scheme more in line with other vendors.
It is also worth noting that regulatory frameworks exist to define and oversee adversarial simulation exercises in some regions, often mandated by government and financial regulators. Some examples of such schemes are the CORIE Framework in Australia, CBEST and STAR in the UK, and TIBER in the EU.
Red, Purple, Blue?
Adversarial simulation comes in many different shapes and sizes: red team exercises, purple team exercises, social engineering and phishing simulations, as well as Denial of Service (DoS) testing.
A red team exercise simulates how a threat actor would target your organisation, which could start from an external perspective without any access provided to the red team, or from ceded initial access such as low-privilege credentials or a laptop (Assumed Breach). The exercise is conducted without the blue team’s prior knowledge, ensuring that the blue team’s response to the exercise most accurately reflects how they would respond to a real attack.
Only a few within the targeted organisation would be aware of the exercise happening, referred to as the control group or white team. The control group provides a line of communication between the organisation and the red team for oversight and deconfliction purposes.
Purple teaming allows an approach that is collaborative from the start, where the red team would sit alongside your organisation's blue team and run specific attack scenarios or sequences. After the red team has completed their attack, both sides can then work together to identify gaps in detection or incident response playbooks.
Bastion can also run social engineering campaigns, such as emulating Scattered Spider’s tactics by calling help desks and requesting password and MFA resets for accounts. We also have the capability to create highly convincing deep fake videos and cloned voices, including the ability to deploy these tactics in real time in a Teams video call, for example.
Conclusion
Adversary simulation exercises move beyond just looking for technical vulnerabilities, testing your organisations detection and response. If you are interested in how your organisation’s response would hold up to a (simulated) real-world attack, contact us.
