What Is Breach and Attack Simulation (BAS)?
Written By
Sarwat Iftikhar
Every organization invests in security controls. Endpoint detection platforms, network monitoring, SIEM rules, firewalls, intrusion prevention systems, email security gateways. The question most organizations cannot reliably answer is whether those controls would actually catch the attacks they were purchased to stop.
Traditional approaches to answering this question are periodic and retrospective. A penetration test runs once or twice a year and produces a snapshot of what was exploitable at that moment. A red team exercise runs less frequently and reveals whether a specific attack scenario succeeds against the current defensive posture. Between those events, the environment changes, new techniques emerge, security tools are updated, and configurations drift. The security program’s picture of its own effectiveness becomes less accurate every day after a test concludes.
Breach and Attack Simulation is the automated, continuous approach to this problem. BAS platforms execute known attacker techniques against an organization’s defenses on a recurring or continuous basis, measuring whether the security controls in place actually detect and block those techniques, and reporting the gaps in real time rather than in a report delivered weeks after a point-in-time assessment.
Key Takeaways
- BAS platforms continuously simulate attacker techniques drawn from the MITRE ATT&CK framework, testing whether existing security controls detect and block those techniques in the live environment rather than in a controlled assessment.
- BAS tests defensive effectiveness, not attack surface breadth. It answers whether your controls work against known attack techniques, not whether unknown vulnerabilities exist in your environment.
- BAS is not a replacement for penetration testing or red teaming. It validates the effectiveness of existing controls. Penetration testing and red teaming find the vulnerabilities and attack paths that exist regardless of whether controls are in place.
- Organizations that run BAS alongside periodic penetration testing tend to have better detection coverage than those relying on periodic testing alone, because BAS closes the visibility gap between annual assessment cycles.
- The primary output of BAS is control effectiveness data: which techniques were detected, which were blocked, which produced no alert at all, and how quickly the security team responded when an alert was generated.
What Is Breach and Attack Simulation?
Breach and Attack Simulation is a security testing methodology implemented through automated platforms that continuously or repeatedly execute known attacker techniques against an organization’s deployed defenses, measuring the detection and blocking rates of those controls against each technique and surfacing gaps where attacks would succeed without triggering a security alert or prevention response.
BAS operates by deploying agents inside the live environment, on endpoints, network segments, and email infrastructure, that execute attacker behavior in a controlled, safe manner and measure how the security stack responds. The techniques are drawn from established frameworks, primarily MITRE ATT&CK, which catalogues the tactics, techniques, and procedures that real threat actors use. By executing these known techniques against real defenses, BAS measures whether the organization’s security investments are actually performing their intended function.
The primary distinction from other security testing approaches is what BAS is measuring. Penetration testing and vulnerability assessments measure what vulnerabilities and attack paths exist in the environment. BAS measures whether the defensive controls in place would detect or block a known attack if it occurred. Both questions are important. They are not the same question, and neither assessment answers the other.
BAS is most directly analogous to testing fire suppression systems. A fire safety inspection identifies that the sprinkler infrastructure exists and appears correctly installed. A BAS-equivalent for fire safety would actually trigger the system in a controlled section to confirm the sprinklers activate, the alarms sound, and the response team is notified. The inspection tells you what is present. The simulation tells you whether it works.
How Does BAS Work?
BAS works by deploying lightweight agents across the environment that execute predefined attack simulations in a safe, reversible manner, compare the actual response of security controls against the expected response, and report any gap between what the control should have detected and what it actually detected.
Stage 1: Simulate. BAS agents deployed across the environment execute attack techniques from the test library. Techniques span the full attack lifecycle: initial access simulation, credential access, lateral movement, privilege escalation, data collection, and exfiltration. Each technique is executed in a controlled, reversible manner that exercises the detection logic of security controls without causing actual damage, data loss, or service disruption.
Stage 2: Measure. The platform compares the actual response of each security control to the expected response for each technique. For each simulated technique, the platform records whether the behavior was detected and alerted on, whether it was blocked before completing, whether it completed without generating any alert, and if an alert was generated, how long it took before the security team responded.
Stage 3: Report. Results are presented in real-time dashboards that map detection coverage against the MITRE ATT&CK framework, showing which technique categories the security stack covers well and which have significant blind spots. Reporting includes the specific tool that failed to detect each technique, enabling targeted remediation rather than a general recommendation to improve detection.
Stage 4: Remediate and re-simulate. Security operations teams use the gap data to tune detection rules, update signatures, improve monitoring coverage, and adjust response playbooks. The next simulation run validates whether the remediation was effective, completing the continuous improvement cycle.
What Does BAS Actually Test?
BAS tests defensive control effectiveness across the full attack lifecycle, measuring whether the security stack in place would detect or block specific attacker techniques at each stage of an intrusion. This is a distinct question from whether vulnerabilities exist, and it requires a distinct testing approach.
The technique categories BAS platforms typically cover include:
Endpoint behavior. Whether endpoint detection and response tools fire on behaviors such as process injection, credential dumping, suspicious scripting engine execution, and persistence mechanism installation. Many organizations discover through BAS that their EDR is deployed but not configured to alert on specific technique variants that threat actors commonly use.
Network traffic. Whether network monitoring detects command-and-control communication patterns, lateral movement between hosts, unusual data transfer volumes, and suspicious protocol usage. Network-level detection gaps are common because they require signature maintenance and configuration that degrades over time without active management.
Email security. Whether phishing simulation payloads, malicious attachment types, and spoofed sender configurations bypass email security gateways. BAS platforms typically include email simulation as a subset of the broader control validation suite.
Lateral movement. Whether security controls detect and alert on techniques used to move between hosts after initial access, including credential pass-the-hash, remote service exploitation, and administrative share traversal. Lateral movement detection is a critical gap in many environments because it is the phase where an attacker transitions from a single compromised endpoint to broader network access.
Data exfiltration. Whether data loss prevention controls and network monitoring detect and block simulated data exfiltration attempts through various protocols and channels including HTTP, HTTPS, DNS tunneling, and cloud storage services.
How Is BAS Different from Penetration Testing?
BAS and penetration testing are frequently described as competing approaches, but they answer fundamentally different questions and should not be treated as alternatives. BAS tests whether controls detect known attack techniques. Penetration testing discovers whether vulnerabilities and attack paths exist, regardless of whether controls are in place.
| Dimension | BAS | Penetration Testing |
| Primary question | Do our controls work? | What can an attacker exploit? |
| Approach | Automated technique execution | Human-driven adversarial testing |
| Frequency | Continuous or high-frequency | Annual or event-triggered |
| Technique scope | Known MITRE ATT&CK techniques | Known and novel attack paths |
| Business logic coverage | No | Yes (manual testing) |
| Compliance evidence | Limited | Accepted by most frameworks |
| Finding type | Detection gaps | Exploitable vulnerabilities |
| Required expertise | Platform operation | Offensive security expertise |
The clearest way to hold the distinction: BAS tells you whether your security tools would have caught the SolarWinds-style lateral movement technique if an attacker used it in your environment. A penetration test tells you whether an attacker could get into your environment and move laterally in the first place.
Both answers are necessary for a complete security picture. An organization can have no detectable vulnerabilities for a penetration tester to exploit but have significant detection gaps that BAS reveals. An organization can have excellent detection coverage that BAS validates but have exploitable vulnerabilities that penetration testing would surface. Our post on manual vs automated penetration testing covers the structural differences between human-driven and automated testing approaches, which applies directly to the BAS context.
Our penetration testing services provide the manual depth that BAS cannot replace, specifically covering the business logic, authorization failures, and novel attack chains that automated technique simulation does not test.
How Is BAS Different from Red Teaming?
BAS and red teaming both simulate attacker behavior in the live environment, but they differ in scope, depth, and the kind of value they deliver.
Red teaming is a human-driven exercise in which experienced security professionals simulate a specific threat actor pursuing a specific objective, using creative judgment to adapt their approach based on what they discover, finding attack paths that no predefined technique library would surface, and specifically testing whether the organization’s detection and response team would identify and stop a patient, sophisticated adversary. The output is an attack narrative demonstrating whether a realistic threat scenario succeeds against the organization’s complete defensive posture.
BAS is an automated platform that executes predefined techniques at scale and frequency. It cannot adapt mid-simulation based on what it discovers, cannot develop novel attack chains, and cannot simulate the creative adversarial judgment that makes red teaming valuable for organizations with mature security programs. What it can do is run continuously, execute hundreds of technique variations across the full kill chain, and measure control effectiveness with consistency and frequency that human-driven exercises cannot match.
The positioning is: red teaming validates whether a sophisticated adversary can succeed against your overall security program. BAS validates whether your security controls are tuned to detect the known techniques those adversaries use. Organizations that run BAS alongside red teaming use BAS to maintain continuous baseline control coverage between red team exercises and to validate that gaps identified in red team reports have been closed. Our post on red teaming covers how adversarial simulation exercises work and what they reveal that automated testing cannot.
What Are the Limitations of BAS?
BAS has significant limitations that determine where it fits in a security program and what it cannot replace. Understanding these limitations prevents the assumption that BAS coverage is equivalent to a complete security validation program.
BAS only tests known techniques. BAS platforms execute techniques from curated libraries based primarily on MITRE ATT&CK. A novel attack technique, a zero-day exploit, or an attacker who combines techniques in an unexpected way falls outside what the simulation library covers. BAS validates coverage of the known threat landscape, not resilience against unknown approaches.
BAS does not test business logic or application authorization. Automated technique simulation has no knowledge of what an application is supposed to do or how its permission model is designed. It cannot test whether a payment flow can be manipulated, whether an API endpoint exposes data it should not, or whether authorization enforcement gaps allow privilege escalation through the application layer. These require human testing with application context.
BAS does not replace social engineering assessment. BAS email simulations test whether phishing email payloads bypass technical email security controls. They do not test whether employees would recognize and report a targeted social engineering attempt, whether the help desk would comply with a vishing request to reset credentials, or whether physical security controls would stop tailgating. Social engineering testing addresses these human-layer vulnerabilities separately.
BAS depends on agent deployment and maintenance. The value of BAS coverage is proportional to how completely the agent network covers the environment. Gaps in agent deployment, whether in specific network segments, recently onboarded systems, or cloud environments, mean BAS results reflect control effectiveness only where agents are deployed. An unmonitored network segment may have completely different detection coverage characteristics than what the deployed agent network shows.
BAS findings require security team capacity to act on. BAS generates a continuous stream of gap findings. Organizations that lack the security operations capacity to tune detection rules, update signatures, and improve playbooks in response to BAS findings accumulate a gap list rather than improving their posture. BAS produces value proportional to the organization’s ability to act on what it surfaces.
Who Should Use BAS?
BAS delivers the most value to organizations with enough security tooling investment to have meaningful detection coverage to validate, and enough security operations capacity to act on the gap findings it generates. It is not the right starting point for organizations that have not yet established baseline detection and response capabilities.
The organizations for whom BAS is most appropriate:
Organizations with established security operations. A SOC team with deployed EDR, SIEM, and network monitoring, and the capacity to tune rules and respond to findings, will extract significant value from BAS continuously validating whether those tools are performing as expected. An organization without those tools has no detection infrastructure for BAS to measure.
Organizations between penetration tests. Annual penetration testing reveals vulnerabilities and attack paths at a point in time. BAS provides the continuous detection validation that keeps the security program’s picture of its defensive effectiveness current between those periodic assessments. Our post on how often businesses should run a penetration test covers the right cadence for periodic assessments, which BAS complements rather than replaces.
Organizations tracking security improvement over time. BAS provides quantitative, repeatable metrics on detection coverage against specific technique categories. This makes it particularly valuable for security programs that need to demonstrate measurable security improvement to executive leadership or board-level stakeholders over time.
Regulated industries with continuous monitoring obligations. Financial services, healthcare, and critical infrastructure organizations face regulatory requirements for continuous security monitoring. BAS contributes to satisfying these requirements by providing continuous, documented evidence of security control validation.
Our continuous penetration testing services provide the ongoing testing coverage that complements BAS by adding human-driven depth testing to the automated technique validation that BAS supplies, covering the vulnerability and attack path discovery that automated simulation cannot perform.
How Does BAS Fit Into a Complete Security Program?
BAS fits into a complete security program as the continuous control validation layer that sits between periodic penetration testing cycles and provides near-real-time feedback on whether defensive investments are working as intended. It is one component of a layered security program, not a standalone solution.
The layers of a complete security program and how BAS connects to each:
Vulnerability management identifies the vulnerabilities and misconfigurations that exist in the environment. BAS does not perform vulnerability discovery, but BAS findings that reveal detection gaps feed into the vulnerability management process as security control weaknesses requiring remediation. Our post on vulnerability management covers how findings from different sources feed into a unified vulnerability management lifecycle, which applies to BAS-sourced control gaps alongside traditional vulnerability findings.
Attack surface management maintains continuous visibility into the organization’s exposed assets and the external risk they carry. BAS validates whether the defenses protecting that attack surface would detect attacks against it. The two capabilities work together: attack surface management identifies what needs protecting, BAS validates whether the protections in place are effective. Our attack surface management service provides the continuous external discovery layer alongside which BAS validates internal defensive effectiveness.
Penetration testing provides the periodic human-driven assessment that discovers unknown vulnerabilities and novel attack paths. BAS validates whether the defenses are tuned to detect the known technique categories. Together they address both the exploitability question and the detectability question that a complete security validation program requires. Our post on vulnerability assessment vs penetration testing covers how the testing approaches in this landscape complement each other.
Red teaming validates whether a sophisticated adversary can succeed against the overall security program. BAS ensures the technical controls supporting that defense are continuously tuned and performing. Red team findings identify what to fix. BAS confirms it has been fixed.
Frequently Asked Questions
Does BAS replace annual penetration testing?
No. BAS and penetration testing answer different questions. BAS tests whether existing security controls detect known attacker techniques. Penetration testing discovers whether exploitable vulnerabilities and attack paths exist. Neither answers the other’s question. Compliance frameworks that require penetration testing evidence, including PCI DSS and SOC 2, do not accept BAS output as a substitute.
How is BAS different from a vulnerability scanner?
A vulnerability scanner identifies potential weaknesses in systems and software by comparing configurations and versions against known vulnerability databases. BAS executes attacker techniques against the live environment and measures whether security controls detect them. One finds weaknesses in what exists. The other tests whether defenses respond to attacks that exploit what exists. Both are valuable, and their output addresses different aspects of security program effectiveness.
What is MITRE ATT&CK and why does BAS use it?
MITRE ATT&CK is a publicly maintained knowledge base of the tactics, techniques, and procedures used by real threat actors, organized by attack lifecycle phase. BAS platforms use it as the technique library because it represents the actual attacker behavior that real security tools need to detect and block. Mapping BAS results against ATT&CK allows security teams to evaluate their detection coverage against specific threat actor profiles rather than against an arbitrary technique set.
Can BAS run in a production environment without causing disruption?
Yes, BAS is specifically designed to simulate attacker behavior in a way that exercises detection logic without causing data loss, system damage, or service disruption. Techniques are executed in a controlled, reversible manner. BAS vendors invest significantly in ensuring their simulations are safe for production use, because the primary value of BAS comes from testing in the live environment where real defenses are deployed rather than in an isolated test environment that may not reflect production security control configurations.
How often should BAS run?
The advantage of BAS over periodic testing is that it can run continuously. Most organizations configure BAS to run simulations on a daily or weekly schedule across different technique categories, with more frequent runs for the technique categories that have the highest business risk or that have recently shown detection gaps. The appropriate cadence depends on how quickly the environment changes, how much security operations capacity is available to act on gap findings, and how rapidly the threat landscape in the organization’s sector is evolving.
Testing That the Defense Actually Works
Security programs invest significantly in tools and controls. BAS answers the question those investments create: does it actually work?
Tools require configuration. Detection rules require maintenance. Response playbooks require updating as the threat landscape evolves. Without continuous validation that this maintenance is happening correctly, that gap goes unnoticed between the annual penetration tests and red team exercises that provide periodic snapshots.
BAS closes this visibility gap by running continuously, providing real-time feedback on control effectiveness, and generating the metrics that allow security teams to demonstrate improvement over time rather than asserting it. It is not a replacement for the human-driven testing that discovers unknown vulnerabilities and novel attack paths. It is the continuous validation layer that makes the periodic testing more valuable by ensuring the defenses it tests are performing as intended between assessment cycles.
Contact us to discuss a security validation program for your organization