BlackNoise is an platform: it validates your true exposure to real-world threats by simulating attacker behaviors directly against your own environment, then measuring the outcome.
Its capabilities let you assess how effectively your security tools detect and respond to an attack. and modules broaden your understanding of your exposure beyond simple detection and response.
This page walks you through your first campaign, from sign-in to results. New to the terminology (event, scenario, campaign, simulation, attack vector, system target)? Start with Core concepts .
Getting started takes four steps:
Go to , enter your email and password, then select . If you forgot your password, select Forgot password? on the login page, enter your email, and follow the reset link sent to you.
Users with the role can create accounts and generate API tokens to automate BlackNoise. See Administration . Enable two-factor authentication for stronger account security, through an authenticator app (preferred) or a one-time code by email. See How to activate 2FA . Before running simulations, set up two components:
Optionally, set up connectors to retrieve detection data automatically from your EDR, NDR or XDR.
- that matches the attacker behaviors you want to reproduce or create your own. See Scenarios .
- from that scenario: define its scope (network ranges and/or your system targets) and its execution settings. See steps 1 to 4 of Security validation .
Every action here is available through the web interface or the API.
The results of a simulation give you three complementary readings of your exposure:
- — the assets an attacker can reach and try to exploit within the scope: IP addresses, hostnames, open ports and the information the services behind them disclose, gathered by the campaign's network scan events. See Attack surface .
- — which offensive behaviors your tools saw, which they missed, and how fast they reacted. This reading is built from the qualification of each executed event: record whether your controls detected or responded to it, either manually or automatically via API or an EDR/NDR/XDR connector. See Event details to qualify an event, and Threat brief for the scores and KPIs it feeds.
- — the adversary actions that actually succeeded, carrying the
Exploited exploitation status. They are confirmed by the real execution of the events, not inferred from a scan. See Event statuses & severity .