Create an attack campaign to measure the effectiveness and operational readiness of your security strategy against real attack paths, going beyond a point-in-time pentest.
A single campaign feeds two complementary readings of the same results:
- are the offensive behaviors detected and blocked by your existing tools, and how fast?
- did the actions actually succeed from an attacker's standpoint, revealing an exploitable weakness?
You can build a campaign and launch a simulation in a few minutes.
From , pick a scenario. It serves as the template that generates the campaign's ordered list of events. The total number of events run depends on the number of System Targets in scope: each system-level event runs once per System Target.
The name and description are pre-filled from the scenario; you can edit them. Add the (used only to generate graphs and KPIs), then select the that will execute the events.
Depending on the scenario, enter one or both:
- IPv4 addresses or CIDR ranges targeted at network level (for example scans), separated by spaces (e.g.
192.168.1.0/24). - select from your existing System Targets, or create a new one.
A connection test checks that the remote-access method (SSH, WinRM, WMI) is enabled and that the flows are open between the Attack Vector and each System Target. You can move to the next step only if the tests pass.
- immediate (
run now) or scheduled for later. automatic (events chain on their own, with an optional delay between each) or manual (you start each event from the app). The inter-event delay is configurable from 0 (continuous) to 60 minutes; the 1-minute default makes detection data easier to analyze.- optionally attach a configured connector to enrich results with EDR/NDR/XDR data. Once active, it automatically processes results and qualifies each event's detection. See Connectors .
A summary of the campaign is shown. Click , or for a scheduled run.
Once the simulation is complete, use its results to evaluate your detection and response.
For every executed event, set the detection status and enrich it with the detection source, date & time, and evidence. This can be done manually, or automatically via API or a connector.
Scores, graphs and KPIs update in real time from the data you provide. On this axis you can identify blind spots (behaviors no tool detects), measure detection speed, and see which detection tools contribute the most and the least.
This sketch cannot currently be displayed in exports
Dashboard with detection and response evaluation
The detection axis measures whether your tools saw the attack. The same results also reveal the : for the executed actions, whether the action succeeded and an was identified. Each event carries an — Exploited, Contained or N/A — recording this outcome; see Scores & statuses . Two things to keep in mind when reading these findings:
- It may be a genuine vulnerability, or a both are reported.
- The same action can succeed or fail depending on the rights of the account used to run it (for example, an admin account provided on the target). Read exploitability findings together with the scope and credentials you set for the campaign.
This sketch cannot currently be displayed in exports