Glossary

Adversary Emulation

Request a Demo
Experience a live demo and learn more about RidgeBot®.

Key Cybersecurity Terms

Our glossary of software threat exposure management terms offers concise definitions of the evolving language of cybersecurity.

Adversary Emulation

An adversary emulation platform uses real-world threat intelligence to duplicate the exact tactics, techniques, behaviors, and procedures that a threat actor would use within an organization’s real environment. It tests a network’s resilience against sophisticated attackers and advanced persistent threats. The adversaries are threat groups with the intent, opportunity, and capability to harm their targets with continuous attacks. 

Adversary emulation exercises are critical for red teams, because they enable the group to conduct their offense more effectively. Red teams can focus on real-world threats that could infiltrate the network, giving them guidelines and a roadmap to follow on their mission to defeat the blue team’s defenses. 

Adversary emulation helps blue teams focus on remediation, concentrating their efforts where most needed. Adversary emulation exercises highlight security gaps, allowing a blue team to identify and fix the vulnerabilities with the greatest risk more quickly. 

Ridge Security Adversary Cyber Emulation (ACE): to measure security control effectiveness, its ACE software agents simulate real-world cyberattacks without impacting the organization’s IT environment.

Assessment Test Script: A group of scripted behaviors carried out by ACE to simulate a specific cyberattack or to confirm security controls.

Key Measurement Block Rate: The ratio of blocked scripts versus all assessment scripts executed during an ACE test.

Endpoint Security: Simulates the behavior of malicious software, or downloads malware signatures to confirm the security controls of the target endpoints.

Data Exfiltration: Simulates the unauthorized movement of data from a server.

Active Directory Information Recon: Simulates an attacker gathering useful resources in Windows Active Directory for elevated privilege, persistence, and plundering information.