Terminology Index
Glossary
170 terms starting with "A"
Showing 33-64 of 170 terms
Active Directory
A directory service commonly used to manage Windows identities, devices, and policy.
Adversary Emulation
Safely reproducing the specific techniques a real threat actor uses to test whether your defenses detect and stop them. Unlike a broad penetration test, it follows a known adversary's playbook to validate detection coverage.
Defenders use adversary emulation to find blind spots before a real attacker does, often mapping each emulated step to a detection rule to confirm it fires. It is closely tied to detection engineering, where atomic tests exercise individual techniques and feed improvements back into rules.
Introduced in: Blue Team Operations, Detection Engineering
Examples
- Running atomic tests for a technique to confirm a SIEM rule alerts on it.
- Emulating a known group's persistence steps during a tabletop or live exercise.
- Validating that a new detection catches the behavior it was written for.
No related terms linked yet.
