Adversary Emulation with MITRE ATT&CK: Testing Detections You Assume Work
Most organizations do not know which attacks they would actually detect. Tools are deployed, rules are enabled, dashboards look healthy — and nobody has confirmed that a given technique produces an alert. Adversary emulation answers that question by executing known techniques deliberately and checking whether anything fired. The gap it exposes Detection coverage is usually assumed rather than measured. A vendor claims a product detects credential dumping, so the technique is marked covered. In practice the rule may be disabled by default, the relevant log source may not be forwarded, an exclusion added a year ago may suppress it, or the alert may fire into a queue nobody reads. Every one of those failures is invisible until a real incident, which is the worst possible time to discover it. Running the technique yourself turns an assumption into a measured result: either the alert appeared or it did not. How ATT&CK structures the problem MITRE ATT&CK catalogs observed adve...