Adversary emulation

Adversary emulation reproduces the specific behaviour of a known actor to see whether you would notice.

It is more useful than a generic penetration test for answering a specific question: if this group came for us, using what they are documented to do, would any of it be detected. It also produces an answer that is actionable, because each failed detection maps to a technique somebody can go and build.

Checked against the primary source.

More on Threat actors & ATT&CK