FAQ

FAQ

Common questions, and where to find reference details



Web app

How do I activate two-factor authentication (2FA)?

    Go to the Security settings in your profile (bottom left).
    Turn on Two-Factor Authentication.
    Enter your password and choose how to receive your OTP code — an authentication app (recommended) or email.
    Enter the 6-digit code to confirm the setup, then save your rescue codes.
When 2FA is enabled, an orange shield icon appears next to your profile picture.


How is the perimeter of a campaign defined?

The perimeter targeted by a campaign's events is defined by the user at creation, and depends on the selected scenario, which requires one or both of:
  • a Network part — ranges and/or individual IP addresses targeted by the Attack Vector's requests, mainly for discovery scans and initial access.
  • a System part — the physical or virtual servers or workstations (Windows, Linux or macOS) selected as System Targets. The Attack Vector connects to each System Target to execute the campaign's events; credentials are required to connect.
See  Security validation  for defining the scope during campaign creation, and  Core concepts  for the underlying objects.


How does BlackNoise decide which simulation events to develop?

Our R&D team focuses mainly on the techniques described by MITRE ATT&CK and on published detection rules (Sigma, Suricata, etc.). We prioritize common tactics, techniques and procedures (TTPs) that mimic attacker behavior, rather than individual vulnerabilities, because:
  • CVEs and 0-day vulnerabilities often depend on a customer's specific environment, making detection based solely on them less useful.
  • Constantly creating and updating rules for every new CVE is resource-heavy and inefficient.
  • Detecting common attacker behaviors across attack stages (persistence, defense evasion, credential access, etc.) improves detection regardless of the specific vulnerability.
We make exceptions for highly impactful vulnerabilities that could bypass standard security measures — for example, significant vulnerabilities listed in the KEV (Known Exploited Vulnerabilities) catalog, which directly affect many of our customers. In those cases we develop specific simulation events to address the risk.


Where to find reference details

Topics that used to be answered here now have a dedicated home:
  • Detection, reaction and exploitation statuses, severity, Simplified Kill Chain, score & grade →  Scores & statuses 
  • Campaign and simulation statuses →  Campaign & simulation statuses 
  • Event types →  Events 
  • Scenario formats →  Scenarios 
  • Attack Vector statuses →  Attack vectors 
  • API keys, authentication, documentation and testing →  API 
  • Attack Vector and System Target deployment and troubleshooting →  Setup & deployment