By re-running the same campaign regularly, continuous monitoring turns a one-off assessment into a trend. Every replay executes the same events against the same scope, so you can watch two things evolve together:
- which IP addresses, open ports and services are exposed, and is that exposure growing or shrinking?
- are you detecting and reacting faster, and are new rules or tools paying off?
Both come from the same replayed simulations, so you monitor your defensive effectiveness and your exposure in a single motion. Concretely, this lets you track your Mean Time to Detect (MTTD) and Mean Time to React (MTTR), spot failures in the detection chain (log loss, interrupted alerting), measure the benefit of newly deployed detection rules or tools, and follow how your exposure changes across runs.
Once a simulation is Completed and its detection data is filled in (source, date & time, and evidence if you choose), it gives you actionable results and a simulation grade. The same run also records the attack surface discovered by the Attack Vectors: the IP addresses, open ports and services found in scope. Together, these form the baseline you compare against.
Start the replay with the Create simulation button.
Adjust the new simulation's parameters as needed, these are the same settings as when creating a campaign:
- Select an . A connection test runs against each System Target.
- Configure the start and chaining conditions.
Review the summary, then click , or for a scheduled run.
This sketch cannot currently be displayed in exports
The number of simulations allowed per campaign depends on your subscription.
As with the first simulation, set the detection status for each executed event and enrich it with the detection source, date & time, and evidence.
Each new simulation is compared with the previous one, so both axes of your exposure become a trend rather than a snapshot:
- — scores, graphs and KPIs (including MTTD and MTTR) update in real time, with percentage changes showing whether your detection is improving or degrading, where the detection chain is failing, and what recent rules or tools have changed.
- — the IP addresses, open ports and services discovered by the Attack Vectors can be reviewed for each run, so you can see new or closed exposure as your environment changes.
A campaign holds several simulations, each replaying the same scenario exactly as before. When you open a campaign, the most recent simulation is selected by default, and every tab (Threat brief, Kill chain, Attack surface, ATT&CK matrix, Activity logs) uses its data. To view another run, use the Simulation list at the top of the screen.
The discovered attack surface appears in the campaign's Attack surface tab; reviewing it across simulations shows how your exposure changes over time.
This sketch cannot currently be displayed in exports