# What is Breach and Attack Simulation (BAS)?

> Breach and attack simulation (BAS) is an industry term for controlled, usually automated security testing that executes predefined attack-like actions and records how selected controls, telemetry, alerts, and response processes behave.

- Canonical URL: https://yellowcube.eu/glossary/breach-and-attack-simulation/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Implementations range from isolated technique checks to multi-step emulations, so the label alone does not specify realism, depth, coverage, or operational risk.

BAS is most useful as a repeatable validation process: define an expected outcome, execute a safe test, compare actual telemetry and control behavior, correct the gap, and retest. A large library of simulations has little value if results are not connected to owners and remediation.

### Key points

- **Primary purpose:** Repeatedly verify specific defensive assumptions and identify configuration, telemetry, or coverage drift.
- **Possible outputs:** Prevention result, observed telemetry, alert creation, investigation context, automated response, and cleanup status.
- **Safety needs:** Written authorization, scope, rate controls, test accounts and data, affected third parties, provider restrictions, operational monitoring, cleanup, and stop procedures.
- **Important limitation:** A passed simulation shows only that one defined test produced the expected result under the tested conditions. It does not establish that related techniques, alternate paths, or the environment as a whole are secure.

### Related terms

[MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge)](<https://yellowcube.eu/glossary/mitre-att-and-ck-adversarial-tactics-techniques-and-common-knowledge/>) · [Penetration testing](<https://yellowcube.eu/glossary/penetration-testing/>) · [Red team](<https://yellowcube.eu/glossary/red-team/>) · [Purple team](<https://yellowcube.eu/glossary/purple-team/>) · [Detection engineering](<https://yellowcube.eu/glossary/detection-engineering/>) · [Cyber range](<https://yellowcube.eu/glossary/cyber-range/>)

### Sources

[MITRE ATT&CK: Adversary Emulation Plans](https://attack.mitre.org/resources/adversary-emulation-plans/) · [NIST SP 800-115: Security Testing and Assessment](https://csrc.nist.gov/pubs/sp/800/115/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

