Prove your detections work — against real endpoints, not a slide deck.
Netgraph's BAS runs with red-team parity: five-stage attack scenarios — recon, initial access, execution, lateral movement, exfiltration — execute against real deployed endpoints and validate against real telemetry read-back of alerts and logs. Not static rule-coverage claims. What fired is proven; what didn't becomes a gap; and every gap feeds the detection flywheel until it's a validated detection.
What is BAS (Breach & Attack Simulation)?
BAS safely executes real adversary techniques — mapped to MITRE ATT&CK — against your own environment to answer the question dashboards can't: would we actually detect this? Netgraph's BAS runs five-stage attack scenarios, then validates by reading back the telemetry and detections that fired (or didn't). Every gap becomes a drafted detection; every new detection is BAS-validated and retroactively replayed against history before going live. That closed loop — simulate, find the gap, ship the detection, re-prove it — is detection CI.
What ships in the module
BAS, red and purple team — one flywheel.
A run, honestly scored
Every stage executed. Every detection proven — or listed as a gap.
A scenario result isn't a coverage percentage from a rule catalog — it's a stage-by-stage record of what executed on which endpoints, which alerts and logs came back, which detections fired, and which techniques went unseen. The unseen ones don't get buried: they enter the flywheel as drafted detections and get replayed until they pass.
- Stage-level verdicts from real alert and log read-back.
- Gaps ranked into the ATT&CK matrix — you see exactly which technique slipped through.
- Drafted detections are BAS-validated before rollout — replay proves the fix.
- Detection-CI fails the pipeline if a change regresses proven coverage.
Functionality map
Module functions at a glance
| Function | What it does | Where it lives |
|---|---|---|
| Attack scenarios | Five-stage runs (recon → exfil) executed against real deployed endpoints | Attack Scenarios pages |
| Telemetry validation | Alert + log read-back proves per-stage detection — no static coverage claims | Scenario run results |
| Endpoint targeting | Deploy/select simulation targets via enrollment token groups | Scenario setup |
| Scheduling | Cron-scheduled recurring runs with an in-app dispatcher | Scenario scheduler |
| ATT&CK matrix | Technique-by-detection coverage and gap map from run evidence | Coverage matrix |
| Detection-CI | Gaps → drafted detections → BAS-validated rollout; CI fails on regression | Detect ▸ Detection CI / Detection Flywheel |
| Agent tools | Agentic SOC runs scenarios and reads gaps ( attacksim.run_scenario / list_gaps ) | Agentic AI skills library |
Common questions
Attack Simulation — asked and answered
How is BAS different from a vulnerability scan or pentest?+
A vulnerability scan lists weaknesses; a pentest is a point-in-time human exercise. BAS continuously exercises your detection and response pipeline with known techniques and measures whether your controls actually fired. It answers 'would we catch this today?' every day, not once a year.
Is it safe to run attack simulations in production?+
Scenarios use benign implementations of adversary techniques with controlled scope and rollback, and every run is scheduled, logged, and attributable. The point is to exercise detection paths, not to cause impact.
How does BAS connect to detection engineering?+
Directly: BAS results gate the detection pipeline. When RCA drafts a new detection from an investigation, BAS validates it fires against the relevant technique before rollout, and the ATT&CK coverage matrix tracks proven — not assumed — coverage over time.
Works with everything on the graph
NextGen SIEM
The detection pipeline BAS validates — drafted rules compile, backtest and deploy through the same Detection-as-Code flow.
Explore→CTEM
Attack simulation is the validation stage of the exposure lifecycle — proving exploitability and detectability in one run.
Explore→Phishing Simulation
The human-layer counterpart — simulated lures and awareness campaigns, as its own module.
Explore→