Services / Adversary simulation

Adversary simulation

Adversary simulation tests an organisation the way a real attacker would: against a business objective, across people, process and technology, with the defenders' response measured as the attack unfolds.

Choose a covert red team engagement, a collaborative purple team exercise, or a focused stage of an attack such as assumed breach.

Before a first exercise, the adversary simulation readiness checklist sets out what it should establish, who needs to be involved and what belongs in scope.

The red team scoping questions list what a consultant asks on the scoping call, and why.

Choose an engagement

Choose the objective.
Then the exercise.

Red Teaming

Full-scope adversary simulation against your organisation to achieve real objectives and test your defences end-to-end.

Explore engagement

Purple Teaming

Collaborative engagement that enhances your detection and response capabilities through joint attack and defence exercises.

Explore engagement

CORIE Framework

Financial-sector resilience exercises guided by the CORIE framework.

Explore engagement

Assumed Breach

Test your internal defences and incident response by simulating an attacker who has already gained initial access.

Explore engagement

Perimeter Assessment

Comprehensive testing of your external attack surface to identify and validate vulnerabilities before attackers do.

Explore engagement

Social Engineering

Evaluate your human security controls through simulated phishing, vishing, and physical security tests.

Explore engagement

Ransomware Simulation

Controlled ransomware attack simulation to test your prevention, detection, and recovery capabilities.

Explore engagement

Cloud Assumed Breach

Specialised post-compromise assessment for cloud environments, testing cloud-native security controls and response.

Explore engagement

OT/ICS Adversary Simulation

Specialised security assessment for operational technology and industrial control systems with safety-first approach.

Explore engagement

Supply Chain Attack Assumed Breach

Start from a compromised developer account and establish what an attacker could reach, modelling a backdoored software dependency.

Explore engagement

Scattered Spider Adversary Emulation

A collaborative purple team exercise running test cases drawn from Scattered Spider’s published tactics, across the full lifecycle of their attacks.

Explore engagement

Who adversary simulation is for

Adversary simulation suits organisations that need to know whether an attacker could move from a foothold towards a critical system, which actions their defenders would see, and where the response would interrupt the attack.

Red teaming fits a mature security program with a SOC, incident response or blue team to exercise. Where detection and response are still being built, purple teaming develops them alongside the defenders.

CORIE exercises are for banks, insurers and payment providers mandated by the Council of Financial Regulators.

Penetration testing is the better start when the question is which weaknesses in a defined system need fixing.

Common questions

How is adversary simulation different from penetration testing?

A penetration test finds weaknesses in a defined system. Adversary simulation works towards an agreed objective across the authorised scope and measures detection and response along the way. The red team vs penetration test guide compares them in detail.

Do the defenders know the exercise is running?

In a red team engagement only the Control Group knows: a small group of senior staff who can make risk-based decisions during the exercise. Purple teaming runs in the open, alongside the defensive team.

Where does an exercise start?

A red team engagement starts outside the organisation and includes gaining access. Assumed breach starts from agreed access, such as a compromised endpoint, cloud identity or developer account, so it cannot show whether the initial compromise would have been prevented.

Can adversary simulation run through the year?

Yes. CAOS (Continuous Adversary Operations Service) runs attacks in agreed cycles throughout the year, with optional purple team collaboration. Annual programs rotate penetration testing and adversary campaigns across twelve months.

Who carries out the exercises?

SilentGrid's own consultants, employed full time in Australia and background checked; testing is never subcontracted. The co-founders executed CBEST in the United Kingdom, the team has run CORIE engagements in Australia, and SilentGrid is a CREST ANZ approved company.

Tell us what you need the engagement to prove.