Unlike generic penetration testing, emulation plans mirror documented adversary tradecraft — often mapped to MITRE ATT&CK — so results answer a sharper question: “Would we catch this particular adversary?” Emulation plans may come from threat intelligence, public libraries such as ATT&CK Evaluations or the Adversary Emulation Library, or internal analysis.
Key points
Relevant adversary profilesChoose emulation profiles from actors known to target the organization’s sector and environment, not the most famous name.
Detection scoringRecord which techniques were observed, alerted, and stopped — a missed early step matters even if the final objective was blocked.
Important limitationEmulation is a representation. Real adversaries adapt, combine techniques, and exploit conditions the plan did not model; passing an emulation does not mean surviving the actual actor.