Glossary

Breach and Attack Simulation

Request a Demo
Experience a live demo and learn more about RidgeBot®.

Key Cybersecurity Terms

Our glossary of software threat exposure management terms offers concise definitions of the evolving language of cybersecurity.

Breach and Attack Simulation (BAS)

Automated breach and attack simulation (BAS) technologies enable improved visibility into enterprise security weak spots by automating testing of threat vectors such as external and insider, lateral movement, and data exfiltration. BAS complements red teaming and penetration testing by detecting and confirming a portfolio of simulated attacks from SaaS platforms, software agents, and virtual machines. 

BAS technology provides automated and consistent assessment of threat vectors. It evaluates the ability of an organization’s security controls to detect and block simulated attacks, using reports that align with industry frameworks such as MITRE. BAS assessments enable organizations to locate gaps in their security posture from configuration errors, or reconsider priorities of impending security investments. 

Organizations with mature security programs use BAS technologies to ensure consistent security posture over time and across multiple locations. 

Ridge Security BAS support: its Adversary Cyber Emulation (ACE) Botlet supports BAS. The Botlet is a software agent that simulates real-world cyberattacks without causing any real harm or impact within the enterprise’s IT environment. To measure security control effectiveness, ACE uses an Assessment Test Script consisting of a group of scripted behaviors carried out to simulate a specific cyberattack, or to confirm security controls. ACE uses Block Rates to determine the ratio of blocked scripts versus all assessment scripts executed during testing; a higher Block Rate indicates better security controls.