Services / Adversary simulation
Adversary simulation
Adversary simulation tests an organisation the way a real attacker would: against a business objective, across people, process and technology, with the defenders' response measured as the attack unfolds.
Choose a covert red team engagement, a collaborative purple team exercise, or a focused stage of an attack such as assumed breach.
Before a first exercise, the adversary simulation readiness checklist sets out what it should establish, who needs to be involved and what belongs in scope.
The red team scoping questions list what a consultant asks on the scoping call, and why.
Choose an engagement
Choose the objective.
Then the exercise.
Red Teaming
Full-scope adversary simulation against your organisation to achieve real objectives and test your defences end-to-end.
Explore engagementPurple Teaming
Collaborative engagement that enhances your detection and response capabilities through joint attack and defence exercises.
Explore engagementCORIE Framework
Financial-sector resilience exercises guided by the CORIE framework.
Explore engagementAssumed Breach
Test your internal defences and incident response by simulating an attacker who has already gained initial access.
Explore engagementPerimeter Assessment
Comprehensive testing of your external attack surface to identify and validate vulnerabilities before attackers do.
Explore engagementSocial Engineering
Evaluate your human security controls through simulated phishing, vishing, and physical security tests.
Explore engagementRansomware Simulation
Controlled ransomware attack simulation to test your prevention, detection, and recovery capabilities.
Explore engagementCloud Assumed Breach
Specialised post-compromise assessment for cloud environments, testing cloud-native security controls and response.
Explore engagementOT/ICS Adversary Simulation
Specialised security assessment for operational technology and industrial control systems with safety-first approach.
Explore engagementSupply Chain Attack Assumed Breach
Start from a compromised developer account and establish what an attacker could reach, modelling a backdoored software dependency.
Explore engagementScattered Spider Adversary Emulation
A collaborative purple team exercise running test cases drawn from Scattered Spider’s published tactics, across the full lifecycle of their attacks.
Explore engagementWho adversary simulation is for
Adversary simulation suits organisations that need to know whether an attacker could move from a foothold towards a critical system, which actions their defenders would see, and where the response would interrupt the attack.
Red teaming fits a mature security program with a SOC, incident response or blue team to exercise. Where detection and response are still being built, purple teaming develops them alongside the defenders.
CORIE exercises are for banks, insurers and payment providers mandated by the Council of Financial Regulators.
Penetration testing is the better start when the question is which weaknesses in a defined system need fixing.
Common questions
How is adversary simulation different from penetration testing?
A penetration test finds weaknesses in a defined system. Adversary simulation works towards an agreed objective across the authorised scope and measures detection and response along the way. The red team vs penetration test guide compares them in detail.
Do the defenders know the exercise is running?
In a red team engagement only the Control Group knows: a small group of senior staff who can make risk-based decisions during the exercise. Purple teaming runs in the open, alongside the defensive team.
Where does an exercise start?
A red team engagement starts outside the organisation and includes gaining access. Assumed breach starts from agreed access, such as a compromised endpoint, cloud identity or developer account, so it cannot show whether the initial compromise would have been prevented.
Can adversary simulation run through the year?
Yes. CAOS (Continuous Adversary Operations Service) runs attacks in agreed cycles throughout the year, with optional purple team collaboration. Annual programs rotate penetration testing and adversary campaigns across twelve months.
Who carries out the exercises?
SilentGrid's own consultants, employed full time in Australia and background checked; testing is never subcontracted. The co-founders executed CBEST in the United Kingdom, the team has run CORIE engagements in Australia, and SilentGrid is a CREST ANZ approved company.