Terminology Index

Glossary

170 terms starting with "A"

Open concept maps

Showing 33-64 of 170 terms

A
32

Adversary Emulation

Safely reproducing the specific techniques a real threat actor uses to test whether your defenses detect and stop them. Unlike a broad penetration test, it follows a known adversary's playbook to validate detection coverage.

Defenders use adversary emulation to find blind spots before a real attacker does, often mapping each emulated step to a detection rule to confirm it fires. It is closely tied to detection engineering, where atomic tests exercise individual techniques and feed improvements back into rules.

Introduced in: Blue Team Operations, Detection Engineering

Examples

  • Running atomic tests for a technique to confirm a SIEM rule alerts on it.
  • Emulating a known group's persistence steps during a tabletop or live exercise.
  • Validating that a new detection catches the behavior it was written for.

No related terms linked yet.