Breach and attack simulation (BAS) is software that safely imitates the techniques real attackers use, such as running suspicious commands on a laptop, moving between systems, sending test malware through email or trying to send data out, and then checks whether your security controls blocked, detected or missed each step. Because it is automated, it can be run repeatedly to show how well defenses work over time.
Not to be confused with a building automation system (BAS), another name for a building management system (BMS).
At a glance
- BAS tests controls, not just systems: it asks “would we stop or see this?” rather than “is this server unpatched?”
- Tools run scenarios from a library of known attacker techniques, often mapped to the MITRE ATT&CK framework.
- Simulations are designed to be safe for production, using harmless payloads, though scope and configuration still matter.
- Results show which controls blocked, alerted or missed each technique, and many tools suggest detection rules or configuration fixes.
- It is commonly used alongside penetration testing and as part of exposure management.
What problem it solves
Organizations spend heavily on firewalls, endpoint protection, email security and monitoring, and then assume they work as configured. In practice, controls drift. A policy change opens a gap, an agent stops reporting, a detection rule is turned off because it was noisy, or a new attack technique was never covered. Annual penetration testing finds some of these issues, but only at one moment, and the environment changes constantly.
BAS gives security teams an ongoing, evidence-based answer to whether their defenses respond to known attack behavior. It turns “we think we’re covered” into a measured result, and it helps prove to leadership, auditors and insurers that controls have actually been tested.
How it works
Agents and targets. Most BAS tools place lightweight software agents on representative systems, such as laptops, servers and cloud workloads, and some also use test mailboxes, web endpoints or cloud accounts. The agents carry out simulated actions.
Scenario library. The vendor maintains a library of attack techniques and full attack chains, typically mapped to MITRE ATT&CK, the public catalog of attacker behaviors. Libraries are updated as new threats emerge, and some tools let you build custom scenarios.
Execution. Scenarios run on demand or on a schedule. Examples include attempting credential theft techniques on an endpoint, sending test attachments past the email gateway, trying to reach known malicious domains, or simulating data being sent to an outside server.
Validation. The tool checks what happened: whether the action was blocked, whether an alert appeared in your endpoint detection and response (EDR) console or security information and event management (SIEM) platform, and whether nothing happened at all. Many products integrate with these tools directly to read the results.
Remediation and tracking. Gaps are reported with recommended fixes, and tests are rerun to confirm the fix worked. Scores and trends show whether coverage is improving.
When it matters for buyers
- After deploying or changing major security tools. BAS confirms the new controls work as expected.
- When building or evaluating a SOC or MDR service. It tests whether the people watching actually see real techniques.
- When adopting continuous threat exposure management (CTEM). BAS is a common tool for the validation stage.
- When a high-profile threat appears. Many libraries add scenarios for new campaigns, giving a quick check.
- When leadership or insurers ask for evidence. Test results are more convincing than configuration screenshots.
To compare testing and exposure services, see our penetration testing overview.
Questions to ask vendors
- Which control types can you test: endpoint, email, web, network, cloud, identity, data exfiltration?
- How do you keep simulations safe in production, and what safeguards can we configure?
- How quickly do you add scenarios for new threats, and can we create our own?
- Which security tools do you integrate with to confirm detection automatically?
- How are agents deployed and managed, and what access do they need?
- How is the product priced: per agent, per scenario, per environment?
- Do you offer services to help interpret results and fix gaps, or is it self-service?
How it differs from penetration testing and red teaming
Penetration testing uses skilled testers to find and exploit weaknesses creatively within a defined scope, usually as a periodic engagement. Red teaming pursues a realistic objective by any permitted means to test people, process and technology together. BAS is automated and repeatable: it runs known techniques against controls frequently but doesn’t improvise the way a human attacker would. Some vendors also sell automated penetration testing, which tries to chain weaknesses together more like a tester; the line between the categories varies by product. In practice, BAS checks that defenses keep working between human-led tests, and human testing finds what the scenario library doesn’t cover. Both feed vulnerability management and remediation priorities.
