Resources / Workshop

Kickstarting adversary emulation engagements

BSides San Francisco 2024 · Workshop

San Francisco ยท 5 May 2024

Kickstarting adversary emulation engagements

Abhijith B R led a hands-on workshop at BSides San Francisco 2024 on kickstarting adversary emulation engagements, opening with a thorough look at adversary emulation engagements and the fundamentals that underpin a strong defense strategy, including how cyber threat intelligence shapes defense planning. He covered cyber defense systems, the importance of blue teams, and the growing role of collaborative purple teaming, and walked participants through the MITRE ATT&CK matrix as a way to understand how threat actors operate in the real world.

BSides San Francisco 2024

The workshop then moved into the practical mechanics of emulation, covering how to turn threat intelligence into structured exercises by selecting and mimicking real tactics, techniques, and procedures. Participants got hands-on practice testing endpoint security controls with tools like Atomic Red Team and MITRE Caldera, and explored emulating specific threat actors such as APT29 and Sandworm.

The workshop closed out with ransomware emulation in safe environments, assessing its impact, and integrating purple teaming into an organization's security framework, with an emphasis on clear reporting and presentation.

See the full BSidesSF 2024 schedule for the wider program.

Validate your defenses against real-world adversaries

BreachSimRange runs red teaming, threat-led breach and adversary simulation that mirror how modern threat actors operate, so you find the gaps before they do.

Talk to us about Consulting