logo

Why we love threat emulation exercises (and how to get started with one of your own)

ID: 97bbc0ab-169c-5cee-a468-a54c09427863

STIX ID: report--97bbc0ab-169c-5cee-a468-a54c09427863

Feed Name: Expel Blog

Date Published: 2019-02-05

Date Updated: 2026-04-27

Author: Jon Hencinski

...
...

This blog-style guide explains how to design and execute threat emulation exercises to sharpen SOC detection and response skills. It covers assessing team capability, mapping exercises to MITRE ATT&CK, building believable Active Directory lab environments (an “Evil Corp” example), using tools like Cobalt Strike, PowerShell Empire and Mimikatz to simulate realistic attacker behaviors, defining communications and deliverables, and iterating on exercises based on feedback to improve overall security operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.