Get a free audit

Field Notes / Offensive Security

Adversary simulation is not red teaming, and the difference decides whether your SOC sees the attack

Adversary simulation, red teaming, breach-and-attack simulation and purple teaming answer four different questions. Confuse them and you buy assurance you do not have. Here is what each one actually gives you, and how to stack them so your SOC catches a real campaign before the ransomware lands.

Author
Red Team Partners
Read
12 MIN READ
Filed
17 March 2026
A SOC analyst reads a threat-detection alert on a darkened server-room console at night.

01 Four disciplines, four questions

sk five security leaders to define adversary simulation and you get seven answers. That confusion is expensive. It is also why global search interest in "adversary simulation" climbed 690% between 2024 and early 2026, as mature teams stopped asking "can someone break in?" and started asking "would we see Scattered Spider's playbook before the ransomware detonates?"

Those are different questions, and each maps to a different engagement. The surge in interest tracks the maturation of SOC programmes worldwide Google Trends 2024–26 . Get the four straight and you buy the right assurance. Confuse them and you pay for a green dashboard while a real operator rehearses on your live estate.

Adversary simulation gives you a graded detection scorecard. It is the faithful reproduction of a specific threat actor's tactics, techniques and procedures against your live environment. The point is not to break in. The point is to measure whether your detection engineering, SOC workflows and incident response fire against a known threat. It is hypothesis-driven: if BlackCat's affiliate deploys its playbook here, do you catch lateral movement at T+15 minutes or T+15 days?

Red teaming gives you the board-level answer on resilience. It is objective-based adversarial testing where the operator chooses the path. Steal the CEO's mailbox. Exfiltrate the customer database. Reach the payment terminal. The operator takes whatever route works and does not care whether it matches a real actor's playbook, because the goal is to test the whole organisation, not one detection rule.

Breach-and-attack simulation (BAS) gives you continuous proof that yesterday's controls still hold. These platforms replay known attack sequences against your infrastructure on a schedule and produce a dashboard. No human operator after setup. They catch control drift and confirm your SIEM rules still fire after the last configuration change.

Purple teaming gives your detection engineers reps. It is a collaborative exercise where offensive and defensive teams work side by side. The attackers execute openly, the defenders watch, tune detections in real time and confirm that alerts fire correctly. It is a training exercise first and a test second.

02 What each approach buys you

Before you sign anything, read what each method actually delivers side by side. The table below is the decision on one screen: what you get, how faithfully it mirrors a real attacker, and what it will never do. Note the two empty cells against BAS. It has no human creativity and cannot run social engineering, and both matter more than any dashboard admits.

What you are buying Red teaming Adversary simulation BAS platform Purple teaming
Primary outcome Overall resilience, tested Detection of specific TTPs, graded Continuous control validation Detections tuned collaboratively
Threat-actor fidelity Low (operator's choice) High (mirrors a real APT) Medium (replays known signatures) Variable
MITRE ATT&CK mapping Post-hoc Pre-planned per technique ID Automated per test case Real-time, collaborative
SOC involvement Blind (no prior knowledge) Blind or informed Usually informed Active participant
Human creativity High High None High (both sides)
Continuous testing No (point-in-time) No (campaign-based) Yes (scheduled) No (workshop-based)
Social engineering Yes Yes (if the actor uses it) No Rarely
Best fit Board-level risk assessment SOC maturity, detection gaps Control-drift monitoring Detection-engineering training

Read the fidelity row again. Scattered Spider's most damaging intrusions in 2024 and 2025 opened with vishing calls to IT help desks, not with an exploit CrowdStrike 2025 . No BAS platform on earth simulates a convincing phone call to your service desk at 02:00 asking for an MFA reset. If that is the way a real actor gets in, and it is, then the only tests that cover it are the two columns with a human behind them.

RECON 14:03 A systems administrator traces node telemetry across a live monitoring console in a data centre.
A graded detection scorecard reads like this: technique fired, technique missed, minutes unseen. A pass/fail PDF does not.

03 Why simulation finds what automation misses

A traditional red team report tells you "we reached domain admin in four days." Useful for the board. Nearly useless for the SOC. Which detection rules failed? Which telemetry was missing? At which exact point in the kill chain did your blue team lose sight of the operator? The report rarely says, because the operator was optimising for the objective, not for mapping your detection coverage.

Adversary simulation inverts that. Every action maps to a MITRE ATT&CK technique ID, every technique carries an expected detection, and every gap is logged with the telemetry that was missing MITRE ATT&CK v15 . When we run a Scattered Spider simulation, the deliverable is not "we compromised Active Directory." It is a heat map: your SOC caught 14 of 23 techniques in the chain, missed T1566.004 (spearphishing via service), took 47 minutes to see lateral movement, and never alerted on T1021.001 (RDP) because your EDR telemetry excludes RDP session logs. That is a Monday-morning work list, not a verdict.

The gap has a mechanism. BAS tools replay atomic techniques in isolation. They run T1059.001 (PowerShell) with a known malicious script, your EDR catches it, green checkbox. A human operator uses PowerShell the way BlackCat's affiliate programme actually does: obfuscated, launched from a legitimate admin tool, after disabling AMSI through a method the BAS vendor has not added to its library yet Mandiant 2025 . That is a red gap your SOC has never seen, not a green tick.

Automation also cannot chain the way a real actor does. Scattered Spider does not fire 23 atomic tests in sequence. It calls your help desk, resets an MFA token, pivots into your identity provider, and deploys ransomware through a remote-management tool already trusted in your environment. The chain matters. The sequence matters. The timing matters. A dashboard full of green measures how well you defend against yesterday's attacks replayed by a script. That is worth something. It is not adversary simulation.

04 The layered programme that holds

The teams with the cleanest detection coverage do not pick one method. They layer four, each on its own cadence, so continuous assurance and human depth both stay live. What you get from the stack is a single coverage matrix that no individual test can produce.

Run your BAS platform continuously to catch control drift and confirm SIEM rule changes still fire. Treat it as a smoke detector, always on. Run purple teaming quarterly: take ten techniques your BAS flagged as gaps, execute them live with the SOC watching, and tune detections in the room. Run adversary simulation twice a year, mapped to the groups in your threat intelligence, blind against the SOC, measuring mean time to detect, mean time to respond and coverage per kill-chain phase. Run an objective-based red team annually for the board-level answer on whether a motivated attacker reaches the crown jewels CISA 2025 .

MITRE ATT&CK is the connective tissue that makes the stack pay off. Every layer maps back to the same framework, so you build one detection coverage matrix that aggregates all four. You see at a glance that T1053.005 (Scheduled Task) was tested 47 times by BAS and always caught, three times by purple team and always caught, once by simulation and caught at T+22 minutes, and once by the red team and missed, because the operator used a living-off-the-land variant your rules did not cover. That single view is where a programme moves from reactive to proactive.

Enterprise-grade adversary simulation, within reach. The question worth sitting with is simple. If Scattered Spider called your help desk tomorrow and ran the exact playbook that hit MGM Resorts, at which step in the kill chain would your SOC notice? A graded simulation answers that in weeks. A real intrusion answers it in headlines.

Detection-coverage action log
  • Run a BAS platform continuously to catch control drift and confirm SIEM rules still fire
  • Hold a quarterly purple team on the ten techniques BAS flagged as gaps
  • Commission a biannual adversary simulation mapped to the APT groups in your threat intelligence, blind against the SOC
  • Book an annual objective-based red team for the board-level resilience answer
  • Aggregate every result into one MITRE ATT&CK coverage matrix and re-test as the estate changes

References

Sources

  1. Google Trends. "Adversary simulation": global search interest, 2024 to 2026. Google, 2026. trends.google.com
  2. CrowdStrike. Threat Intelligence: Scattered Spider (UNC3944) Adversary Profile. CrowdStrike, 2025. crowdstrike.com
  3. Mandiant. BlackCat (ALPHV) Ransomware Affiliate Analysis. Mandiant (Google Cloud), 2025. cloud.google.com
  4. MITRE. ATT&CK Enterprise Matrix, version 15. The MITRE Corporation, 2024. attack.mitre.org
  5. CISA. Cybersecurity Advisory: Red Team Assessment Findings and Guidance. Cybersecurity and Infrastructure Security Agency, 2025. cisa.gov