Reference for the lifecycle states of campaigns and simulations
Campaign statuses
Status
Campaign description
Active
Default status when a campaign is created. The campaign is ongoing: simulations can run, and you can record information on executed simulations (event status, detection, reaction, proof, comments).
Archived
A completed campaign with no further simulations. No simulation can run and no information can be added or changed; the campaign is kept as an archive to preserve its results.
Simulation statuses
A simulation is one execution of all the campaign's events within the intended scope; a campaign contains several.
Status
Simulation description
Scheduled
The simulation is queued; no adversary action has started yet.
Processing
Adversary actions are running; the progress bar advances as each event completes.
Paused
Manually paused after stopping the running action; execution can be resumed or skipped to the next event.
Uncompleted
Aborted because the Attack Vector went offline; the simulation cannot be resumed or completed.
Canceled
Canceled by the campaign Kill Switch or by archiving the campaign; the remaining actions will not run.
Gathering more data
All actions are done; the connectors (SIEM, EDR) are being queried for detection data before the simulation closes.
Completed
The simulation is finished: execution and detection data collection are complete, and the results are final.