Resources / Workshop

Threat and Adversary Emulation Operational Exercises

BSides Las Vegas 2025 · Workshop

Las Vegas ยท 5 August 2025

Threat and Adversary Emulation Operational Exercises

Abhijith B R delivered a hands-on workshop, Threat and Adversary Emulation Operational Exercises, at BSides Las Vegas 2025, giving security professionals a practical foundation in threat and adversary emulation inside a controlled, enterprise-grade lab equipped with real defensive technologies like AV, web proxies, EDR, and SIEM integration.

Through guided, step-by-step exercises, participants safely emulated real-world threat actors and tested how well common security controls actually held up. The workshop covered key areas such as gathering actionable cyber threat intelligence, planning and executing adversary emulation engagements, and working with a range of emulation tools and frameworks. Attendees also learned how to map techniques to the MITRE ATT&CK framework, carry out threat hunting activities, and design custom adversary emulation plans tailored to the needs of their organization.

By the end of the session, participants walked away with the practical skills needed to operationalize threat emulation efforts and strengthen their organization's overall cyber defense posture.

BSides Las Vegas 2025 workshop listing and the speaker profile on pretalx.

Workshop abstract

This hands-on workshop provides participants with a foundation in practical threat and adversary emulation. Designed for security professionals looking to enhance their offensive and defensive capabilities, the training takes place in a controlled, enterprise-grade lab environment equipped with real-world defensive technologies, including Anti-Virus, Web Proxies, EDR, SIEM integration, and other detection mechanisms. Participants engage in guided step-by-step exercises to safely emulate real-world threat actors and assess the effectiveness of common security controls. The workshop covers gathering actionable cyber threat intelligence, planning and executing adversary emulation engagements, and using a variety of emulation tools and frameworks. Attendees also learn how to map techniques to the MITRE ATT&CK framework, conduct threat hunting activities, and design custom adversary emulation plans tailored to organizational needs. By the end of the workshop, attendees are equipped with the practical skills needed to operationalize threat emulation efforts and strengthen their organization's cyber defense posture. BSides Las Vegas 2025 workshop abstract

Workshop outline

Through guided exercises in a controlled, enterprise-grade lab environment, attendees learn how to safely emulate real-world threat actors. All lab systems include active defenses such as Anti-Virus, Web Proxies, EDR, SIEM integration, and other detection mechanisms. Key topics covered include:

  • Gathering actionable cyber threat intelligence
  • Planning and executing adversary emulation engagements
  • Utilizing attack emulation tools and frameworks
  • Leveraging MITRE ATT&CK for mapping and execution
  • Threat hunting techniques
  • Building custom adversary emulation plans
  • An introduction to dynamic adversary simulation

Each module includes step-by-step walkthroughs of attack vectors, guiding participants through realistic attack paths across enterprise environments. The goal is to help attendees evaluate the effectiveness of security controls and better understand how to test and improve cyber defenses through adversary emulation.

Validate your defenses against real-world adversaries

BreachSimRange runs red teaming, threat-led breach and adversary simulation that mirror how modern threat actors operate, so you find the gaps before they do.

Talk to us about Consulting