SecOps training

SecOps training

Test, train and improve your cyber teams and tools


Use attack simulations to strengthen your cyber strategy at both the human and technical levels:
  • Train your cybersecurity teams against real threats — real indicators and TTPs, no false positives.
  • Strengthen your detection tools with tailored, contextualized rules.


1) Launch an attack simulation

Create a campaign using the scenarios built by the BlackNoise R&D team, chosen to match the technical scope and the offensive behaviors you want to reproduce.
For the campaign setup, follow steps 1 to 4 on the  Security validation  page.
For training, we recommend manual execution mode, or at least an inter-event delay if you keep automatic mode. This makes it easier to analyze how your defense tools react in real time.
You can also attach a configured connector to enrich detection results with EDR/NDR/XDR data; it automatically processes each event's result and provides qualified detection data.


2) Identify indicators of attacker behavior

Evaluate the detection data from your deployed tools (EDR, NDR, SIEM, honeypots, etc.) for each executed event. The alerts and logs generated feed the detection data in BlackNoise, consolidating the results.
Use the simulation to train the blue team to work effectively in their detection tools: generating precise alerts, using the right dashboards, building log queries, and so on. It is also a chance to assess reaction processes and coordination between teams.


3) Strengthen defenses

Use the application's Sigma and Suricata detection rules to improve your tool configurations.