Every technique lands in one of four buckets
This is the entire value of the exercise. Not a risk rating or an opinion, a factual outcome per technique, repeatable next month to see whether it changed.
The gap between logged only and detected is where most SOC improvement work comes from. The evidence was always there; nothing was watching for it.
Four assurance activities, four different questions
Simulation does not replace testing. It fills the eleven months between tests with continuous evidence about your controls.
Six things it settles
Prove the stack works
You have bought endpoint, network, email and identity controls. Simulation establishes which of them actually stop what they were purchased to stop.
Find the gaps between tools
Most misses sit in the seams: a technique the endpoint agent ignores because it assumes the network layer covers it, and vice versa.
Validate detection content
Every simulated technique that produces no alert is a detection rule your SOC does not have and did not know was missing.
Measure change over time
Run monthly, the score becomes the one security metric that improves visibly when you tune something.
Safe in production
Techniques are simulated, not weaponised. No malicious payload detonates and no production data is touched.
Evidence for the board
A percentage of known techniques prevented, trending upward, is a far better answer than a list of products owned.
Simulate, tune, re-simulate
A single run is a snapshot and a mildly uncomfortable meeting. The loop is what actually moves the number.
Baseline
The first run, against the estate as it stands. Expect the prevented figure to be lower than the tooling inventory suggests.
Analyse
Each missed and logged-only technique traced to a cause: coverage gap, policy in audit mode, missing detection content, or a tool doing less than assumed.
Tune
Policies enforced, detection rules written, coverage extended. Changes made through your change process, not around it.
Re-simulate
The same techniques run again to confirm the fix worked. This is the step that separates a report from an improvement.
Expand
New techniques added as adversary behaviour changes, so the score reflects the current threat rather than last year’s.
Point-in-time assessment
A defined simulation across the attack chain, with a scored result per technique, root cause per gap and a prioritised tuning plan for your team to work through.
Continuous programme
Run on a monthly cadence with the technique set kept current, findings triaged, detection content built and the trend reported, either alongside your SOC or as part of ours.
What the findings feed
SIEM
Every logged-only result is a correlation rule waiting to be written.
EDR and XDR
Techniques missed at the endpoint usually trace to a policy left in audit mode.
Red teaming
Once the controls score well, test whether your people would notice somebody patient.
