Abhijith B R led a hands-on workshop at BSides San Francisco 2024 on kickstarting adversary emulation engagements, opening with a thorough look at adversary emulation engagements and the fundamentals that underpin a strong defense strategy, including how cyber threat intelligence shapes defense planning. He covered cyber defense systems, the importance of blue teams, and the growing role of collaborative purple teaming, and walked participants through the MITRE ATT&CK matrix as a way to understand how threat actors operate in the real world.
The workshop then moved into the practical mechanics of emulation, covering how to turn threat intelligence into structured exercises by selecting and mimicking real tactics, techniques, and procedures. Participants got hands-on practice testing endpoint security controls with tools like Atomic Red Team and MITRE Caldera, and explored emulating specific threat actors such as APT29 and Sandworm.
The workshop closed out with ransomware emulation in safe environments, assessing its impact, and integrating purple teaming into an organization's security framework, with an emphasis on clear reporting and presentation.
See the full BSidesSF 2024 schedule for the wider program.
BreachSimRange runs red teaming, threat-led breach and adversary simulation that mirror how modern threat actors operate, so you find the gaps before they do.
Talk to us about Consulting