Go to the in your profile (bottom left).
Turn on .
Enter your and choose how to receive your — an authentication app (recommended) or email.
Enter the 6-digit code to confirm the setup, then save your .
When 2FA is enabled, an orange shield icon appears next to your profile picture.
The perimeter targeted by a campaign's events is defined by the user at creation, and depends on the selected scenario, which requires one or both of:
- a part — ranges and/or individual IP addresses targeted by the Attack Vector's requests, mainly for discovery scans and initial access.
- a part — the physical or virtual servers or workstations (Windows, Linux or macOS) selected as . The Attack Vector connects to each System Target to execute the campaign's events; credentials are required to connect.
Our R&D team focuses mainly on the techniques described by MITRE ATT&CK and on published detection rules (Sigma, Suricata, etc.). We prioritize common tactics, techniques and procedures (TTPs) that mimic attacker behavior, rather than individual vulnerabilities, because:
- CVEs and 0-day vulnerabilities often depend on a customer's specific environment, making detection based solely on them less useful.
- Constantly creating and updating rules for every new CVE is resource-heavy and inefficient.
- Detecting common attacker behaviors across attack stages (persistence, defense evasion, credential access, etc.) improves detection regardless of the specific vulnerability.
We make exceptions for highly impactful vulnerabilities that could bypass standard security measures — for example, significant vulnerabilities listed in the KEV (Known Exploited Vulnerabilities) catalog, which directly affect many of our customers. In those cases we develop specific simulation events to address the risk.
Topics that used to be answered here now have a dedicated home: