Skip to main content

Adversary Simulation and Breach-and-Attack Simulation

One is a tool that replays known techniques on a schedule. The other is people improvising. Both get sold as red teaming, and both are useful, for different questions.

By Siddarth G
August 19, 2026 Last updated 6 min read

Both phrases turn up in red team proposals, and neither one is a red team. The one you buy decides whether you get software or people.

Breach-and-attack simulation

A product. You deploy agents across your estate and the platform continuously replays a library of known techniques: credential dumping, a particular lateral movement method, a known exfiltration pattern. It then reports which ones your controls stopped or noticed.

What it is good at: breadth and repetition. It runs hundreds of techniques weekly without getting bored, and catches the day your detection rule silently stopped matching after a platform upgrade. No human team covers that much ground that often.

What it cannot do: anything not in its library, and anything requiring judgement. It will not notice that your service desk resets passwords without verifying identity, and it will not chain three unremarkable findings into a route nobody anticipated. It executes a catalogue.

What deploying one involves

The licence is the smaller half of the commitment. Agents go onto endpoints and servers, so you need a change window, an owner in infrastructure, and exclusions agreed with whoever runs your endpoint protection: a platform that simulates credential dumping gets stopped by the control you are trying to measure unless somebody lets it through. Each exclusion is a small hole opened so you can watch yourself, and somebody has to hold the list and close the entries afterwards.

Then somebody has to operate it. The platform produces findings every week, and findings nobody drains become a dashboard. Name three things before you sign: who reads the output, which queue the failures land in, and the meeting where the unfixed ones get argued about. If you cannot name all three, the subscription will renew before anyone notices it changed nothing.

Reading the score

Most platforms reduce a run to a percentage. It measures your controls against that library on that day, and it moves when the library is updated as readily as when your defences change. Use it as a trend line for your own estate, never as a comparison against anyone else's.

Two details decide whether the number means anything. Techniques execute in a safe form: the exfiltration goes to the vendor's collector, the destructive step writes to a scratch file. So a blocked result tells you the safe version was blocked. And detection is scored from telemetry, so a technique marked detected produced an alert somewhere. Whether a human would have acted on it at two in the morning is a question no agent can ask, and alert with no response is the failure mode that survives the most spending.

Adversary simulation

The phrase gets used in two ways.

Sometimes it means emulating a specific named threat actor: taking a group known to target your sector, working from published reporting on how they operate, and reproducing that tradecraft in sequence. It answers a narrower question than "could someone get in": could this particular adversary, behaving as documented, achieve their objective here.

Sometimes it is a politer word for a red team, used because "red team" sounds adversarial to a board. Ask which is meant.

What emulation needs before it earns its price

A reason to name that actor. Sector reporting, an intelligence feed you already pay for, or something in your own incident history that points at a group. Without one, the name on the proposal is decoration and you are paying a premium for a technique list somebody picked off a blog.

The honest limit is the source material. Published reporting describes what a group did on the intrusions somebody investigated and chose to write up: a partial record, and a historical one. Emulation reproduces documented behaviour faithfully; it cannot reproduce what the group changed afterwards, or the part of the operation nobody saw. A team that says so in its proposal is being straight with you.

Emulation done properly is easy to audit later, because every technique traces to a citation. Ask for the mapping before the work starts: technique, source, what we did, what you saw. A public framework such as MITRE ATT&CK supplies the column headings.

The three, side by side

Breach-and-attack simulationThreat-actor emulationRed team
CoverageWide, shallow, repeatedOne group's documented playbookOne route, chosen and improvised
AnswersDo my controls still do what they did last monthWould this group succeed hereWould anyone notice a patient intruder
Commercial shapeA licence that renewsTeam-weeksTeam-weeks
Evidence producedA trend lineA cited technique-by-technique mappingA narrative with a timeline

Who owns the follow-up

A red team produces one set of findings and a plan with a date on it. A platform produces findings for as long as you pay for it, and that needs a standing owner in a way a project does not.

It matters most if a managed provider runs your monitoring, which is common in the Indian mid-market. The agent rollout needs their change window, the tuning needs their engineers, and the backlog of missed techniques is a list of what they failed to catch. Settle in the contract who acts on that output and by when, before the platform is bought.

Choosing between them

  • You do not know what your controls detect. Breach-and-attack simulation, or a purple team. Both cover many techniques quickly; a red team answers one route and costs far more. See purple team: when it beats a red team.
  • You have a specific adversary in mind, because of your sector or something in threat intelligence. Threat-actor emulation.
  • You want to know whether anyone would notice a patient intruder. A red team, and only a red team. Here is what that involves.

Where the Indian instruments land

If SEBI regulates you, one amendment is directly on point. The technical clarifications of 28 August 2025 softened the relevant CSCRF guideline, and the acronyms BAS and CART no longer appear in the instrument. It now reads that regulated entities are recommended to consider deploying a range of security solutions in consultation with their IT Committee, such as threat simulation, vulnerability management and decoy systems. Recommended, in consultation, and with the product categories gone. A proposal citing CSCRF as the reason you must buy a platform is making a checkable claim about a document you can read. Tier first in any case: red teaming and SEBI CSCRF.

Under the RBI's 2026 Directions, paragraph 151 sets vulnerability assessment at least every six months and penetration testing at least every twelve for commercial banks, covering systems that are critical and/or sit in the DMZ with a customer interface. Paragraph 162 says red teams may be used, as the 2016 framework did.

Paragraph 156 puts the credentials and competency of the testing firm and its assigned personnel in scope at selection, appointment, engagement and renewal, and paragraph 157 asks for explicit assurance on each area assessed: a firm, named people, a signed statement. Paragraph 159 adds that where a CERT-In empanelled auditor is engaged, CERT-In's audit policy guidelines come into the supervisory relationship. Keep the platform's output beside that work, as the record of what held between assessments. The full reading is here.

When to buy neither

  • Your penetration tests still surface missing patches and default credentials. Both of these measure how a defended estate holds up. The answer for an undefended one is known already, and the money belongs in the hygiene work.
  • Nobody can change a detection rule this quarter. Platform output is a to-do list for detection engineering. Without an engineer who can act on it, you are buying a weekly report on a problem you cannot fix.
  • What you actually need is a story for the board. A coverage percentage will not carry a board meeting, and neither will a technique mapping. The narrative exercise is the red team.

The claim to check

A proposal offering "adversary simulation" at red team prices should say which adversary, on what reporting, and which techniques are being reproduced. A team doing threat-actor emulation properly can name the group and cite the source. One using the phrase as a synonym will describe a methodology instead.

A "red team" delivered mostly through a breach-and-attack platform is a tool subscription with a report attached. It is priced differently, and the team-weeks question exposes it in one line.

About the author

Siddarth G

Practice Director โ€” Cybersecurity

Leads Security Brigade's offensive security practice with deep expertise in vulnerability research, penetration testing, and red team operations. Ranked Top 80 globally on Bugcrowd.