What actually happens
when you run a campaign
- Step 1: You pick a scenario from the catalog, such as the APT29, FIN7 or LockBit threat actors, or a compliance framework like NIST 800-53.
- Step 2: SIMAPTIC plans an attack path for that scenario as a graph of techniques.
- Step 3: You run the generated payload on your own machine, and the campaign executes live.
- Step 4: You receive a report of what fired, what did not, and ranked fixes.
Your test is an evolving graph,
not a script
SIMAPTIC plans the campaign as a directed graph of techniques, layered by attack phase. One planned module runs per cycle, enforced in code. When recon finds another reachable host, the graph grows a new branch rather than following a fixed list. This is how the engine reasons; as a customer you see the timeline further down, not the graph.
- The graph is layered by phase: recon, management, privesc, collection, lateral, objectives.
- Recon runs first and all three steps succeeded: a portscan, an SPN enumeration, and a Sharphound collection.
- Management patches ETW, then privilege escalation gets SYSTEM. A competing UAC bypass is skipped because its alternative won.
- Credential collection is running a Kerberoast against the domain, with a DPAPI secrets step queued behind it.
- Sharphound found host 10.0.0.6, which injected a reachability probe.
- The probe confirmed reachability, so a lateral movement branch grew toward the newly discovered host.
- That lateral step is blocked: the defenses on the second host held, and the data exfiltration objective behind it is blocked with it.
- The ransomware simulation objective on the first host stays pending, waiting on the credential step still running.
Which controls hold,
and which don't
Pick a compliance framework instead of a threat actor and the same engine runs, scoped to the controls you need to prove. Every technique traces back to the control it exercises, and the result is evidence rather than an assertion.
- You choose a framework, such as NIST 800-53.
- The campaign is scoped to the controls that apply, for example IA-5, AC-6, and AU-6.
- Each control is exercised by the technique that genuinely tests it, and each returns its own result.
- IA-5 Authenticator Management was tested by Credential Access, and your defenses detected it.
- AC-6 Least Privilege was tested by Privilege Escalation, and your defenses missed it.
- AU-6 Audit Review was tested by Defense Evasion, and your defenses detected it.
What you see
You follow the run as a timeline. Finished steps are checked off, the one in progress is marked, and the rest are queued behind it.