A scenario is a sequence of events that emulates a series of actions carried out by an attacker. It can replicate a complete attack pattern or a limited set of adversary behaviors (APT, data breach, ransomware, etc.). See Core concepts .
Scenarios are organized into tabs by type: network, system, cloud, and your custom company scenarios. Each scenario appears as a card showing its name, the number of events it contains, a description, prerequisites, and its last update and version. A badge marks scenarios recently created (New) or updated (Updated), and icons show the environments covered (network, windows, linux, macos).
A pill indicates the scenario :
- reproduces all or part of a Kill Chain, with events spanning several MITRE ATT&CK tactics.
- fewer events, centered on a common tactic or approach, with more varied technical implementations.
- checks the requirements of a directive, norm or standard such as NIS 2 or PCI DSS.
To work through the list, you can filter (format, MITRE ATT&CK tactic, protocol, state, last update, risk category), search, and switch between card and table views.
Click a scenario's name or its i button to open its full details: the description (Details tab) and the list of events it contains (Events tab). Hovering an event shows its description, including the to run it — the account types and the right targets.
The number of events actually executed in a campaign depends on the number of System Targets in scope: each system event runs once per System Target.
The Create attack campaign button starts a campaign based on the selected scenario. See Security validation for the campaign creation steps.
The Create scenario button lets you build a custom scenario, when this feature is included in your subscription.
Give the scenario a name and description, and choose its perimeter: network only, or network & system. For a system perimeter, select the environment (OS type) — a scenario is dedicated to one operating system.
Click Create to open the builder. The left panel is the scenario's event list; the right panel lists all events available for the chosen perimeter. For a system scenario, the mandatory session-creation events are added automatically and cannot be removed.
Check events on the right to add them; use the tactic selector (MITRE ATT&CK categories) and the search field to find them. On the left, reorder or remove events.
Edit the name and description at any time, and save as a draft to preserve your progress. . The preview summarizes the scenario, including event order, and lets you specify prerequisites to enrich its execution context.
Once published, the Create attack campaign button appears and you can use the scenario in a simulation. You can still edit a published scenario — for example to change its events.
To stop a scenario from being used in new campaigns, edit it and save it as a draft.