What Is BAS (Breach and Attack Simulation)?

Related problems: We bought security tools but don't know if they actually stop attacks; Pen tests happen once a year and the environment changes every week; Our SOC didn't see an attack technique we assumed was covered; Leadership asks whether we're protected against the latest threat

Breach and attack simulation (BAS) is software that safely imitates the techniques real attackers use, such as running suspicious commands on a laptop, moving between systems, sending test malware through email or trying to send data out, and then checks whether your security controls blocked, detected or missed each step. Because it is automated, it can be run repeatedly to show how well defenses work over time.

Not to be confused with a building automation system (BAS), another name for a building management system (BMS).

At a glance

  • BAS tests controls, not just systems: it asks “would we stop or see this?” rather than “is this server unpatched?”
  • Tools run scenarios from a library of known attacker techniques, often mapped to the MITRE ATT&CK framework.
  • Simulations are designed to be safe for production, using harmless payloads, though scope and configuration still matter.
  • Results show which controls blocked, alerted or missed each technique, and many tools suggest detection rules or configuration fixes.
  • It is commonly used alongside penetration testing and as part of exposure management.

What problem it solves

Organizations spend heavily on firewalls, endpoint protection, email security and monitoring, and then assume they work as configured. In practice, controls drift. A policy change opens a gap, an agent stops reporting, a detection rule is turned off because it was noisy, or a new attack technique was never covered. Annual penetration testing finds some of these issues, but only at one moment, and the environment changes constantly.

BAS gives security teams an ongoing, evidence-based answer to whether their defenses respond to known attack behavior. It turns “we think we’re covered” into a measured result, and it helps prove to leadership, auditors and insurers that controls have actually been tested.

How it works

Agents and targets. Most BAS tools place lightweight software agents on representative systems, such as laptops, servers and cloud workloads, and some also use test mailboxes, web endpoints or cloud accounts. The agents carry out simulated actions.

Scenario library. The vendor maintains a library of attack techniques and full attack chains, typically mapped to MITRE ATT&CK, the public catalog of attacker behaviors. Libraries are updated as new threats emerge, and some tools let you build custom scenarios.

Execution. Scenarios run on demand or on a schedule. Examples include attempting credential theft techniques on an endpoint, sending test attachments past the email gateway, trying to reach known malicious domains, or simulating data being sent to an outside server.

Validation. The tool checks what happened: whether the action was blocked, whether an alert appeared in your endpoint detection and response (EDR) console or security information and event management (SIEM) platform, and whether nothing happened at all. Many products integrate with these tools directly to read the results.

Remediation and tracking. Gaps are reported with recommended fixes, and tests are rerun to confirm the fix worked. Scores and trends show whether coverage is improving.

When it matters for buyers

  • After deploying or changing major security tools. BAS confirms the new controls work as expected.
  • When building or evaluating a SOC or MDR service. It tests whether the people watching actually see real techniques.
  • When adopting continuous threat exposure management (CTEM). BAS is a common tool for the validation stage.
  • When a high-profile threat appears. Many libraries add scenarios for new campaigns, giving a quick check.
  • When leadership or insurers ask for evidence. Test results are more convincing than configuration screenshots.

To compare testing and exposure services, see our penetration testing overview.

Questions to ask vendors

  • Which control types can you test: endpoint, email, web, network, cloud, identity, data exfiltration?
  • How do you keep simulations safe in production, and what safeguards can we configure?
  • How quickly do you add scenarios for new threats, and can we create our own?
  • Which security tools do you integrate with to confirm detection automatically?
  • How are agents deployed and managed, and what access do they need?
  • How is the product priced: per agent, per scenario, per environment?
  • Do you offer services to help interpret results and fix gaps, or is it self-service?

How it differs from penetration testing and red teaming

Penetration testing uses skilled testers to find and exploit weaknesses creatively within a defined scope, usually as a periodic engagement. Red teaming pursues a realistic objective by any permitted means to test people, process and technology together. BAS is automated and repeatable: it runs known techniques against controls frequently but doesn’t improvise the way a human attacker would. Some vendors also sell automated penetration testing, which tries to chain weaknesses together more like a tester; the line between the categories varies by product. In practice, BAS checks that defenses keep working between human-led tests, and human testing finds what the scenario library doesn’t cover. Both feed vulnerability management and remediation priorities.

Frequently Asked Questions

Is BAS the same as penetration testing?
No. A penetration test uses skilled people to find and exploit weaknesses in a defined scope, usually at a point in time. BAS uses software to run a library of predefined attack techniques repeatedly, mainly to check whether controls detect or block them. Many organizations use both.
Is BAS safe to run in production?
BAS tools are designed to mimic attacker behavior without causing real damage, for example by using harmless test files and reversible actions. Safety still depends on the product and how it is configured, so start in a limited scope, agree what scenarios run where, and tell the teams that might respond.
How often should BAS run?
Many organizations run scenarios continuously or on a schedule, such as daily or weekly, and after significant changes like new tools, rule updates or network changes. The aim is to catch control drift quickly rather than once a year.
Does BAS replace vulnerability scanning?
No. Vulnerability scanning looks for known weaknesses in systems. BAS tests whether your defenses respond to attack behavior. They answer different questions and are often combined in an exposure management program.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.