Kill Chain

Kill Chain

The list of executed attack behaviors for the selected simulation, with their main technical characteristics.




Simulation events list

The table shows, for each executed event: execution status, exploitation status, event number and name, date & time of execution, severity, availability of an IOC / Sigma rule / comments / evidence, event type, MITRE ATT&CK tactic, execution source, targets, detection status, detection, reaction, Time to Detect (TTD) and Time to React (TTR). Use the button at the top right to choose which columns to display.
Execution status. The first column reports the outcome of the execution itself: whether the Attack Vector actually carried the adversary action out on the scope. It conditions how the rest of the row reads, since an event that did not execute carries neither a detection result nor an exploitation result. The detailed execution information for a given event — source and target, start and end times, duration, and the commands run with their results — is available on the  Event details  page.
Exploitation status. The second column reports each event's exploitation status — Exploited, Contained or N/A — which records the outcome of the action from the attacker's standpoint, independently of whether it was detected (see  Scores & statuses ). This is what makes the events list directly usable to identify exploitable security weaknesses: the Exploited events are the actions that actually succeeded on your systems, and therefore the exposures to address first. Read them together with the scope and the privileges granted for the campaign, as explained in  Security validation .
The bar at the bottom shows the total number of events and lets you set how many to display per page.

Selecting and filtering

Order events by date or event ID, search, and filter by event start time, severity, type, comments, proofs, Sigma rule, IOC, MITRE ATT&CK tactic, detection status, detection source, and reaction.

Execution control

Next to the search field, an execution control panel shows the simulation's progress. From it, you can stop the execution of an event at any time, then resume it or skip to the next event.

Export campaign data

Export everything for the campaign: a .csv file with all technical event information, and a zip archive with all evidence added to the events.

Qualify event statuses

Set each event's detection status directly from the list. The default is Unqualified; the three others are Undetected, Logged and Alerted (see  Scores & statuses ). The number of unqualified events is shown under the simulation name. Qualifying every event gives complete results and a better measure of your defenses — status is the criterion with the most impact on the score.