Black Hat USA Aug 4-6, Mandalay Bay. Book time with us
Solutions · Breach and Attack Simulation

See what your response actually catches.

So what does Soarcery do for breach and attack simulation? When a simulated technique fires an alert, the Familiar investigates and responds exactly as it would for a real one, so your BAS results measure the whole response, not just the detection.

The problem

BAS confirms a detection fired. It rarely shows what happens next.

Simulation tools are good at proving a technique triggered an alert. They stop short of showing whether the response that followed would have been fast, correct, and defensible, which is the part that actually matters in a real breach.

Detection fired is not response worked

Proving the alert triggered is the easy half. The response that follows, its speed, its correctness, its defensibility, goes unmeasured.

The score stops at the SIEM

A simulation graded on detections alone says nothing about the minutes after, which is where a real breach is won or lost.

Practice differs from production

If the simulated alert takes a special path, you measured the drill instead of the defense.

How Soarcery does it

The simulated alert gets the real investigation loop.

1

It treats the simulated alert like a real one

The Familiar ingests it the moment it fires and works it at analyst depth, the same investigation loop it runs on every alert, no special-casing.

2

It shows the verdict and the plan

The multi-engine verdict spread and the proposed response are both visible, so you can see exactly where a real response would land, and why.

3

It stops at the same Seal it would in production

Consequential actions halt at the Seal with rationale and evidence attached, giving you a realistic measure of your actual response, not a simulated one.

4

The whole run leaves a receipt

Detection, investigation, verdict, and where the response paused: one replayable record per technique, ready to hand to the red team or into a board pack.

In the product

The response you are actually measuring.

A response plan in the Soarcery editor: each step of a containment written out and visible before the plan is ever run, demo dataA response plan in the Soarcery editor: each step of a containment written out and visible before the plan is ever run, demo data

Actual product. Demo data.

The plan

A response is a readable, reviewable object: every step written out and visible before anything runs. When you simulate a technique, you can see the exact plan your live environment would have produced, not a summary of one.

The measurement

Each run closes with a record: what was detected, what was decided, who approved it, and when. That turns a simulation result from a detection score into a measurement of the whole response.

A Soarcery receipt: an approved response action on the record, with the case it came from and who approved it, demo dataA Soarcery receipt: an approved response action on the record, with the case it came from and who approved it, demo data

Actual product. Demo data.

Where this is different

Measure the response, not just the alarm.

  • Simulated alerts take the production path: the same investigation loop, with no special casing.
  • The verdict spread and the proposed response are both visible, so you can see where a real call would land.
  • Consequential actions stop at the same Seal they would in production.
  • Every technique ends in a receipt: the whole response, replayable end to end.
Fire a technique

See the response, not just the detection.

A 30-minute walkthrough. Run a simulated technique and watch the Familiar work it end to end.