Resources / Workshop

Operating like APTs: Hands-on Adversary Emulation in Enterprise Environments

BSides Ahmedabad 2026 · Workshop

Ahmedabad · 26-27 September 2026

Operating like APTs: Hands-on Adversary Emulation in Enterprise Environments

Shana Buhaisa P, Associate Security Consultant at BreachSimRange, is delivering a two-day hands-on workshop at BSides Ahmedabad 2026 on how to operate like real-world APTs in enterprise environments. The workshop walks participants through adversary emulation from start to finish, not in a stripped-down lab, but in a controlled enterprise-grade environment equipped with the same defensive technologies they face in production: Anti-Virus, Web Proxies, EDR, SIEM integration, and other detection mechanisms.

Shana is co-delivering the workshop with Sreehari Haridas, Offensive Security Lead at Fintech. Together they guide attendees through step-by-step exercises that cover gathering actionable cyber threat intelligence, planning and executing adversary emulation engagements, and working with a variety of emulation tools and frameworks. Participants also learn how to map techniques to the MITRE ATT&CK framework, conduct threat hunting activities, and design custom adversary emulation plans tailored to their organization's specific needs.

By the end of the two days, attendees walk away with the practical skills needed to operationalize threat emulation efforts and strengthen their organization's cyber defense posture. Join the workshop at BSides Ahmedabad 2026 and learn to emulate a real-world APT.

Core concepts

  • MITRE ATT&CK Framework
  • Understanding threat-actors
  • Tactics, Techniques, and Procedures (TTPs)
  • Cyber threat intelligence
  • Threat emulation fundamentals

Lab exercises

  • Building threat-actor profiles
  • Single technique emulation
  • Micro emulation scenarios
  • Full adversary emulation exercises
  • Attack emulation tools and scripts

Workshop abstract

This hands-on workshop provides participants with a foundation in practical threat and adversary emulation. Designed for security professionals looking to enhance their offensive and defensive capabilities, the training takes place in a controlled, enterprise-grade lab environment equipped with real-world defensive technologies, including Anti-Virus, Web Proxies, EDR, SIEM integration, and other detection mechanisms. Participants will engage in guided step-by-step exercises to safely emulate real-world threat actors and assess the effectiveness of common security controls. BSides Ahmedabad 2026

Validate your defenses against real-world adversaries

BreachSimRange runs red teaming, threat-led breach and adversary simulation that mirror how modern threat actors operate, so you find the gaps before they do.

Talk to us about Consulting