Get started

Get started

Evaluate your exposure to adversarial threats through attack simulation


BlackNoise is an Adversarial Exposure Validation (AEV) platform: it validates your true exposure to real-world threats by simulating attacker behaviors directly against your own environment, then measuring the outcome.
Its Breach & Attack Simulation (BAS) capabilities let you assess how effectively your security tools detect and respond to an attack. Attack surface management (ASM) and Automated vulnerability detection modules broaden your understanding of your exposure beyond simple detection and response.
This page walks you through your first campaign, from sign-in to results. New to the terminology (event, scenario, campaign, simulation, attack vector, system target)? Start with  Core concepts .

Getting started takes four steps:

1) Sign in to the web app

Go to  https://app.blacknoise.co , enter your email and password, then select Sign in.
If you forgot your password, select Forgot password? on the login page, enter your email, and follow the reset link sent to you.
Users with the Admin role can create accounts and generate API tokens to automate BlackNoise. See  Administration .
Recommended. Enable two-factor authentication for stronger account security, through an authenticator app (preferred) or a one-time code by email. See  How to activate 2FA .

2) Deploy your environment

Before running simulations, set up two components:
  • Attack Vector: executes the technical events (the offensive actions) on your network. See  Deploy an Attack Vector .
  • System Targets: the machines that define the exact scope of your simulations. See  Add a System Target .
Optionally, set up connectors to retrieve detection data automatically from your EDR, NDR or XDR.

3) Run an attack simulation

  • Pick a scenario that matches the attacker behaviors you want to reproduce or create your own. See  Scenarios .
  • Create a campaign from that scenario: define its scope (network ranges and/or your system targets) and its execution settings. See steps 1 to 4 of  Security validation .
Every action here is available through the web interface or the API.

4) Analyze results and strengthen your defenses

The results of a simulation give you three complementary readings of your exposure:
  • Your attack surface — the assets an attacker can reach and try to exploit within the scope: IP addresses, hostnames, open ports and the information the services behind them disclose, gathered by the campaign's network scan events. See  Attack surface  .
  • The effectiveness of your detection and response — which offensive behaviors your tools saw, which they missed, and how fast they reacted. This reading is built from the qualification of each executed event: record whether your controls detected or responded to it, either manually or automatically via API or an EDR/NDR/XDR connector. See  Event details  to qualify an event, and  Threat brief  for the scores and KPIs it feeds.
  • The exploitable weaknesses confirmed on your systems — the adversary actions that actually succeeded, carrying the Exploited exploitation status. They are confirmed by the real execution of the events, not inferred from a scan. See  Event statuses & severity  .
Repeat the simulation with the same parameters to track how these three readings evolve over time. See  Continuous cyber monitoring .