Adversary Emulations
Threat-informed adversary emulation — building plans, emulating real APTs, and validating detections against ATT&CK. Follow it top to bottom — foundational first (16 tutorials).
Adversary EmulationAdversary Emulation vs. Adversary Simulation: Definitions, Differences, and Why It MattersAdversary emulation and adversary simulation are not synonyms. This tutorial breaks down both disciplines, maps them to MITRE ATT&CK, and shows you…Read →Adversary EmulationThreat-Informed Defense: Principles, Frameworks, and the Intelligence-Driven Security CycleMove beyond brittle IOCs with threat-informed defense. This tutorial covers the Pyramid of Pain, MITRE ATT&CK, the six-phase CTI lifecycle, STIX/TAXII, M3TID…Read →Adversary EmulationIntroduction to MITRE ATT&CK: Structure, Tactics, Techniques, and Sub-TechniquesA comprehensive introduction to the MITRE ATT&CK knowledge base covering its data model, 14 Enterprise tactics, related objects, Navigator layers, and how…Read →Adversary EmulationNavigating ATT&CK Navigator: Building, Annotating, and Exporting Technique LayersMaster ATT&CK Navigator to build technique layers, run gap analysis with score expressions, and export results for threat-informed defense and adversary emulation…Read →Adversary EmulationCyber Threat Intelligence (CTI) Fundamentals: Sources, Types, and the Intelligence LifecycleLearn how to build and operationalize a cyber threat intelligence program - covering the four intelligence types, the six-phase lifecycle, STIX 2.1/TAXII…Read →Adversary EmulationMapping CTI Reports to ATT&CK TTPs: A Step-by-Step MethodologyConvert threat intelligence reports into precise MITRE ATT&CK TTP layers using a structured four-step methodology - producing reusable artifacts that drive detection…Read →Adversary EmulationAPT Profiling: How to Build a Comprehensive Adversary Profile from Open-Source IntelligenceMaster APT profiling by systematically collecting OSINT, mapping TTPs to MITRE ATT&CK, and serializing a full adversary dossier in STIX 2.1 -…Read →Adversary EmulationEmulation Plan Architecture: Structuring Phases, Objectives, Scenarios, and Success CriteriaLearn how to architect an adversary emulation plan (AEP) the MITRE CTID way: intelligence summary, phased operational flow, TTP-by-TTP scenarios, and scorable…Read →Adversary EmulationBuilding an Adversary Emulation Plan: From CTI to Executable PlaybookLearn to build a complete adversary emulation plan - from CTI research and ATT&CK technique mapping through a full AD lab execution…Read →Adversary EmulationIntroduction to Atomic Red Team: Installation, Structure, and Running Your First Atomic TestInstall Atomic Red Team on an isolated Windows VM, explore the ATT&CK-mapped YAML test structure, and execute your first atomic against T1059.001…Read →Adversary EmulationAtomic Red Team Deep Dive: Writing Custom Atomics and Contributing to the LibraryLearn to write schema-valid custom Atomic Red Team tests for T1547.001 Registry Run Key persistence, capture Sysmon telemetry, build a paired Sigma…Read →Adversary EmulationIntroduction to CALDERA: Architecture, Agents, Abilities, and Adversary ProfilesLearn how MITRE CALDERA's C2 server, Sandcat agents, YAML abilities, and adversary profiles work together to automate ATT&CK-mapped breach simulation - then…Read →