← All Netgraph solutions
Attack SimulationExposure & Validation

Prove your detections work — against real endpoints, not a slide deck.

Netgraph's BAS runs with red-team parity: five-stage attack scenarios — recon, initial access, execution, lateral movement, exfiltration — execute against real deployed endpoints and validate against real telemetry read-back of alerts and logs. Not static rule-coverage claims. What fired is proven; what didn't becomes a gap; and every gap feeds the detection flywheel until it's a validated detection.

Real endpointsreal telemetryFive-stage scenariosATT&CK coverage matrixCron-scheduled runsDetection-CI wired

What is BAS (Breach & Attack Simulation)?

BAS safely executes real adversary techniques — mapped to MITRE ATT&CK — against your own environment to answer the question dashboards can't: would we actually detect this? Netgraph's BAS runs five-stage attack scenarios, then validates by reading back the telemetry and detections that fired (or didn't). Every gap becomes a drafted detection; every new detection is BAS-validated and retroactively replayed against history before going live. That closed loop — simulate, find the gap, ship the detection, re-prove it — is detection CI.

What ships in the module

BAS, red and purple team — one flywheel.

01

Five-stage scenarios

Recon → initial access → execution → lateral → exfil-class stages, executed as real activity on real deployed endpoints — red-team parity, on demand.

02

Telemetry validation

Each run reads back the alerts and logs it should have produced. Detection is proven by what actually landed in the pipeline — never inferred from static rule coverage.

03

Endpoint targeting

Deploy and select simulation targets via enrollment token groups — point a scenario at exactly the fleet segment you want to test.

04

Scheduled runs

Cron-scheduled recurring simulations with an in-app dispatcher — continuous validation, not an annual pentest cadence.

05

ATT&CK coverage matrix

Which techniques are covered by which detections — and where the gaps are — mapped across the ATT&CK matrix from real run evidence.

06

Detection-CI

Simulation gaps wire into the detection flywheel: a gap becomes a drafted detection, the draft is BAS-validated before rollout, and CI fails on detection regression.

07

Agent tools

The agentic SOC runs deterministic scenarios and reads coverage gaps itself — attacksim.run_scenario and attacksim.list_gaps are first-class agent skills.

08

Purple-team workflow

Scenario → telemetry validation → gap list → detection draft → replay — the full purple-team loop in one console, with evidence at every step.

A run, honestly scored

Every stage executed. Every detection proven — or listed as a gap.

A scenario result isn't a coverage percentage from a rule catalog — it's a stage-by-stage record of what executed on which endpoints, which alerts and logs came back, which detections fired, and which techniques went unseen. The unseen ones don't get buried: they enter the flywheel as drafted detections and get replayed until they pass.

  • Stage-level verdicts from real alert and log read-back.
  • Gaps ranked into the ATT&CK matrix — you see exactly which technique slipped through.
  • Drafted detections are BAS-validated before rollout — replay proves the fix.
  • Detection-CI fails the pipeline if a change regresses proven coverage.

Functionality map

Module functions at a glance

FunctionWhat it doesWhere it lives
Attack scenariosFive-stage runs (recon → exfil) executed against real deployed endpointsAttack Scenarios pages
Telemetry validationAlert + log read-back proves per-stage detection — no static coverage claimsScenario run results
Endpoint targetingDeploy/select simulation targets via enrollment token groupsScenario setup
SchedulingCron-scheduled recurring runs with an in-app dispatcherScenario scheduler
ATT&CK matrixTechnique-by-detection coverage and gap map from run evidenceCoverage matrix
Detection-CIGaps → drafted detections → BAS-validated rollout; CI fails on regressionDetect ▸ Detection CI / Detection Flywheel
Agent toolsAgentic SOC runs scenarios and reads gaps ( attacksim.run_scenario / list_gaps )Agentic AI skills library

Common questions

Attack Simulation — asked and answered

How is BAS different from a vulnerability scan or pentest?+

A vulnerability scan lists weaknesses; a pentest is a point-in-time human exercise. BAS continuously exercises your detection and response pipeline with known techniques and measures whether your controls actually fired. It answers 'would we catch this today?' every day, not once a year.

Is it safe to run attack simulations in production?+

Scenarios use benign implementations of adversary techniques with controlled scope and rollback, and every run is scheduled, logged, and attributable. The point is to exercise detection paths, not to cause impact.

How does BAS connect to detection engineering?+

Directly: BAS results gate the detection pipeline. When RCA drafts a new detection from an investigation, BAS validates it fires against the relevant technique before rollout, and the ATT&CK coverage matrix tracks proven — not assumed — coverage over time.

See it live

Run one scenario. See what fires — and what doesn't.