Event statuses & severity

Event statuses & severity

Reference for the statuses and the severity that qualify each simulated event


This page is the single reference for how BlackNoise qualifies events. The Kill Chain, the campaign Synthesis and the other result views all rely on these definitions. For how these values are turned into a score and a grade, see  Scoring & grades .

An event carries four statuses. The execution status and the exploitation status are determined automatically by the platform from what happened when the event ran. The detection status and the reaction status are qualified afterwards, either by you or by a connector.


Execution statuses

The execution status reports the outcome of the execution itself: whether the Attack Vector carried the adversary action out on the scope. It conditions how the rest of the event reads, since an event that did not run carries neither a detection nor an exploitation result.
Status
Status title
Execution description

https://slite.com/api/files/utN5f_8b10oJRu/event%20execution%20status_waiting.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODkxNDkwODUsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoieFNSWFdZUnFVcjZjLXQiLCJleHAiOjE3OTE3NDEwODV9.2k7TWwtXzfAQT_ryUywmkf4R6XFS82i3M0_p7cROGr0
Waiting
The event is queued, waiting to be executed by the Attack Vector. It cannot be qualified yet and is not counted in the simulation results.

https://slite.com/api/files/cc2xjE2hyieUbH/event%20execution%20status_in%20progress.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODkxNDkwODUsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoieFNSWFdZUnFVcjZjLXQiLCJleHAiOjE3OTE3NDEwODV9.2k7TWwtXzfAQT_ryUywmkf4R6XFS82i3M0_p7cROGr0
Processing
The event is currently being executed on the scope. It cannot be qualified yet and is not counted in the simulation results.

https://slite.com/api/files/EHN2HUKOCSMnp4/event%20execution%20status_executed.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODkxNDkwODUsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoieFNSWFdZUnFVcjZjLXQiLCJleHAiOjE3OTE3NDEwODV9.2k7TWwtXzfAQT_ryUywmkf4R6XFS82i3M0_p7cROGr0
Executed
The event ran through to completion on the target. Its detection status is Unqualified until you or a connector qualifies it, and it is counted in the simulation results.

https://slite.com/api/files/NpXV6bal7cJl8r/event%20execution%20status_executed-warning.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODkxNDkwODUsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoieFNSWFdZUnFVcjZjLXQiLCJleHAiOjE3OTE3NDEwODV9.2k7TWwtXzfAQT_ryUywmkf4R6XFS82i3M0_p7cROGr0
Executed with warning
The event ran on the target and generated activity, but part of its results could not be parsed, so not all of the information the event was expected to return was retrieved. The event can be qualified and counts towards the detection score.

https://slite.com/api/files/uf4Tf1izm5Tu6D/app.stage.blacknoise.co_campaigns_78553474-0708-4eab-872e-78a0666c9f0d_execution_id%3D8a3f89c1-265a-4c41-9e61-a3a681c18cf1%20(2)%20copie.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODkxNDkwODUsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoieFNSWFdZUnFVcjZjLXQiLCJleHAiOjE3OTE3NDEwODV9.2k7TWwtXzfAQT_ryUywmkf4R6XFS82i3M0_p7cROGr0
Executed without secrets
The event ran on the target but no secret could be retrieved. The following events of the scenario that depend on that secret cannot be executed on this target. It can be qualified and is counted in the simulation results.

https://slite.com/api/files/IxLbVG3BFJJD2x/event%20execution%20status_error.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODkxNDkwODUsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoieFNSWFdZUnFVcjZjLXQiLCJleHAiOjE3OTE3NDEwODV9.2k7TWwtXzfAQT_ryUywmkf4R6XFS82i3M0_p7cROGr0
Error
An error occurred during the execution of the event. The actions performed before the error may still have generated traces, so the event can be qualified and is counted in the simulation results.

https://slite.com/api/files/ODKrYmyOzUo5SE/event%20execution%20status_canceled.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODkxNDkwODUsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoieFNSWFdZUnFVcjZjLXQiLCJleHAiOjE3OTE3NDEwODV9.2k7TWwtXzfAQT_ryUywmkf4R6XFS82i3M0_p7cROGr0
Canceled
Execution was stopped by a user with the Stop button. The event can be run again, or you can move on to the next one. It can be qualified and is counted in the simulation results.

https://slite.com/api/files/AMBEg2olQlD4tD/event%20execution%20status_unexecuted.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODkxNDkwODUsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoieFNSWFdZUnFVcjZjLXQiLCJleHAiOjE3OTE3NDEwODV9.2k7TWwtXzfAQT_ryUywmkf4R6XFS82i3M0_p7cROGr0
Unexecuted
The event was not executed because the required technical conditions were not met — for example no session could be opened on the target, or a port needed by a brute-force event was not found open by the scan events. The reason is given alongside the status. The event cannot be qualified and is not counted in the simulation results.

https://slite.com/api/files/WSX2MEF5TYtaXn/event%20execution%20status_out-of-scope.png?apiToken=eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjMtMDUtMDQifQ.eyJzY29wZSI6Im5vdGUtZXhwb3J0IiwibmlkIjoiSV9xYm1zczJRbVNhRFkiLCJpYXQiOjE3ODkxNDkwODUsImlzcyI6Imh0dHBzOi8vc2xpdGUuY29tIiwianRpIjoieFNSWFdZUnFVcjZjLXQiLCJleHAiOjE3OTE3NDEwODV9.2k7TWwtXzfAQT_ryUywmkf4R6XFS82i3M0_p7cROGr0
Out of scope
The event does not apply to the scope defined for the campaign — for example an SSH-key session creation event when none of the System Targets uses SSH keys. The event cannot be qualified and is not counted in the simulation results.


Exploitation statuses

Complementary to an event's execution status, the exploitation status records the outcome of an adversary action from the attacker's standpoint — independent of whether the action was detected. It takes one of three values:
Status
Status title
Exploitation description
-
Not applicable
The action produces no exploitable result by nature. This is typical of reconnaissance actions (scans, discovery), whose goal is to gather information rather than exploit a weakness.
Exploited
The action produced the result the attacker intended: the targeted weakness is validated. This is the primary alert signal for the analyst, confirming a real exposure regardless of detection.
Contained
The action ran as intended but produced no offensive effect, often because a security solution (antivirus, EDR) blocked it. The attacker did not progress.


Detection statuses

Each executed event carries one of four detection statuses:
Status
Status title
Event description
Unqualified
Default status; no detection information has been provided yet.
Undetected

The attack simulation was missed: no log and no alert.
Logged
The security tools produced a technical trace (a log) for the simulated attack, but no alert was raised and no reaction was taken. To be valid, a Logged proof should indicate at least the source, the destination, the date & time, and if possible the type of action recorded.
Alerted
The security tools identified the simulated attack and raised an alert or a notification. To be valid, an Alerted proof should indicate at least the source, the destination, the date & time, and the type of threat identified. Any remediation applied by the security teams can be recorded in the reaction section.


Reaction statuses

Once an event is detected, its reaction status records whether a response was taken:
  • Reacted — at least one response action (response strategy) has been declared on the event after detection.
  • Ignored — no reaction was recorded after detection.


Severity

Severity flags the events that matter most to detect, on two levels:
  • High (red) — highly critical behavior, given the noise it generates and the impact of the action. Prioritize detecting and reacting to these as fast as possible.
  • Low (yellow) — less important to detect relative to other simulated attacks.