{"id":76307,"date":"2025-02-08T18:37:25","date_gmt":"2025-02-08T18:37:25","guid":{"rendered":"https:\/\/peraltafinancing.com\/accounting\/threat-informed-defense-part-1-threat-simulation\/"},"modified":"2025-02-08T18:37:25","modified_gmt":"2025-02-08T18:37:25","slug":"threat-informed-defense-part-1-threat-simulation","status":"publish","type":"post","link":"https:\/\/fivemor.com\/?p=76307","title":{"rendered":"Threat Informed Defense (Part 1): Threat Simulation"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"\">\n<div class=\"feat-img\"><img width=\"2667\" height=\"1500\" src=\"https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2024\/03\/Webinar-Invite-Pentestv2.png\" class=\"attachment-full size-full wp-post-image\" alt=\"\" decoding=\"async\" fetchpriority=\"high\" srcset=\"https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2024\/03\/Webinar-Invite-Pentestv2.png 2667w, https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2024\/03\/Webinar-Invite-Pentestv2-750x422.png 750w, https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2024\/03\/Webinar-Invite-Pentestv2-1154x649.png 1154w, https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2024\/03\/Webinar-Invite-Pentestv2-1536x864.png 1536w, https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2024\/03\/Webinar-Invite-Pentestv2-2048x1152.png 2048w, https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2024\/03\/Webinar-Invite-Pentestv2-354x200.png 354w\" sizes=\"(max-width: 2667px) 100vw, 2667px\"\/><\/div>\n<p class=\"meta\"><img loading=\"lazy\" decoding=\"async\" data-del=\"avatar\" src=\"https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2023\/02\/Thurmond-Tori_9-27-22-300x300.jpg\" class=\"avatar pp-user-avatar avatar-30 photo \" height=\"30\" width=\"30\"\/> by Tori Thurmond \/ April 18th, 2024 <\/p>\n<p>Cyber threats pose significant risk to organizations worldwide, ranging from financial loss to reputational damage to operational disruptions. These ever-evolving threats can be intimidating, but with the right preparation, organizations can proactively mitigate risks and fortify their overall cybersecurity posture. One way to offensively protect your organization from the treat landscape is through threat simulation. \u00a0<\/p>\n<p>This week, our VP of Pen Testing, <a href=\"https:\/\/www.linkedin.com\/in\/jarowland\/\" target=\"_blank\" rel=\"nofollow noreferrer noopener external\">Jason Rowland<\/a>, kicked off our three-part Threat Informed Defense webinar series with the first session which focused on Threat Simulation.\u00a0\u00a0<\/p>\n<p><em>Note: This is a high-level overview of our webinar\u00a0Threat Informed Defense (Part 1): Threat Simulation. For more insight into this topic and what threat simulation might look like for your organization, make sure to listen to the full recording\u00a0<\/em><a href=\"https:\/\/streamyard.com\/watch\/p6ytGDmQQh4Q\" target=\"_blank\" rel=\"nofollow noreferrer noopener external\"><em>here<\/em><\/a><em>.\u00a0<\/em>\u00a0\u00a0 \u00a0<\/p>\n<h2 class=\"wp-block-heading has-medium-font-size\" id=\"h-what-is-threat-informed-defense\"><strong>What is threat informed defense? <\/strong><\/h2>\n<p>Before diving into the details, Jason took a moment to define a couple of important terms.\u00a0\u00a0<\/p>\n<p>MITRE Enginuity\u2019s Center for\u00a0Threat-Informed Defense notes that,\u00a0\u201c<strong>Threat-informed defense<\/strong> is the systematic application of a deep understanding of adversary tradecraft and technology to improve defenses.\u201d\u00a0<\/p>\n<p>In simpler terms, threat-informed defense encourages us to understand the adversaries that are most likely to impact our environment; understand the tactics, techniques, and procedures (TTPs) those adversaries employ in infiltrating our environments; and shape our defenses around those TTPs.\u00a0<\/p>\n<p>Leveraging knowledge of cyber threats to prioritize the allocation of limited resources is one of the most impactful and efficient ways to reduce overall risk.\u00a0\u00a0<\/p>\n<p>Threat-informed defense is possible because of ATT&amp;CK.<strong> MITRE ATT&amp;CK <\/strong>is a curated knowledge base for cyber adversary behavior that focuses on the why (tactic) and the how (technique) of adversary actions. Over the last ten years, as we\u2019ve learned how adversaries both break into and move through our environments as well as how they ascertain, those techniques have been captured in the ATT&amp;CK framework. The ATT&amp;CK framework also gives us a common taxonomy to talk about adversary actions. It\u2019s a way for red teams and blue teams to communicate using the same terms.\u00a0<\/p>\n<p>Follow <a href=\"https:\/\/attack.mitre.org\/\" target=\"_blank\" rel=\"nofollow noreferrer noopener external\">this link<\/a> to check out the MITRE ATT&amp;CK framework.\u00a0<\/p>\n<h2 class=\"wp-block-heading has-medium-font-size\" id=\"h-fundamentals\"><strong>Fundamentals <\/strong><\/h2>\n<p>The purpose of threat simulation is to help you understand your cybersecurity effectiveness. Organizations may ask: Are our people trained and alert when it comes to security threats? Are our internal security processes effective? Are technology investments configured correctly and delivering value? \u00a0<\/p>\n<p>If you\u2019re asking yourself these questions, you\u2019re not alone. These questions are so common that they supported an entire industry built around cybersecurity assessments. There are several different testing approaches used in offensive security, like red team engagements, vulnerability assessments, and penetration tests to name a few. All of these assessments help network owners better understand their security and make improvements in defending against threats. Threat simulation is additive to these methods. Each of these offensive security techniques has its time and place. \u00a0<\/p>\n<p>Why do new testing methods continue to be created? The reality is that while these other assessments are good to do, they are not always representative of real-world threats. For example, traditional penetration tests and vulnerability assessments often focus overwhelmingly on identifying and mitigating initial access vectors, meaning these tests say very little about the hundreds of post-exploitation TP\u2019s spanning the attack matrix. Therefore, the way that real-world adversaries operate is fundamentally different than how we operate during traditional cybersecurity assessments.\u00a0\u00a0<\/p>\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-what-is-threat-simulation\"><strong>What is threat simulation? <\/strong><\/h3>\n<p>Threat simulation is an intelligence driven discipline that entails researching, modeling, and executing cyber adversary tactics, techniques, and procedures to assess and improve cybersecurity. Threat simulation is about understanding what threats exist with the means and motive to come after your organization and the data that you\u2019re responsible for. Pen testers want to research and model those threats to understand how the threats work inside of an environment.\u00a0 \u00a0<\/p>\n<p>A primary characteristic of threat simulation is that the TTPs are meant to emulate adversary behaviors commonly seen in the wild. This method ensures that defenses can be tuned to real-world threats. Different industries are facing different threats, so threat simulation takes those real-world threats that are probable for a certain industry and works to defend against them. \u00a0<\/p>\n<p>Another main focus of threat simulation is tuning defenses around behaviors that are difficult for adversaries to alter as opposed to tuning around fragile signatures like has values and IP addresses. When threat simulation is based off of the TTPs,\u00a0testers\u00a0force the bad actors to\u00a0change the way they conduct their operations. \u00a0<\/p>\n<p>Threat simulation is also typically transparent, meaning that the testers fully disclose what the red team did in as much detail needed for the network defenders to improve their defenses. Adversary emulation is also collaborative, meaning the testers work with the defenders to effect positive improvement. \u00a0\u00a0<\/p>\n<h2 class=\"wp-block-heading has-medium-font-size\" id=\"h-threat-simulation-framework-nbsp\"><strong>Threat Simulation Framework <\/strong>\u00a0<\/h2>\n<p>The threat simulation framework is how the pen testers will conduct a threat simulation engagement. \u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"718\" height=\"669\" sizes=\"auto, (max-width: 718px) 100vw, 718px\" src=\"https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2024\/04\/s97lzpyt.png\" alt=\"\" class=\"wp-image-35454\" style=\"width:399px;height:auto\"\/><\/figure>\n<\/div>\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-1-defining-objectives\">1. <strong>Defining Objectives <\/strong><\/h3>\n<p>Defining the objectives of the simulation is an important first step in the framework. This step will be highly dependent on the industry that you\u2019re in, your business model, and the threat landscape at the time of conducting the exercise. \u00a0<\/p>\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-2-ttp-research-nbsp\">2. <strong>TTP Research<\/strong>\u00a0<\/h3>\n<p><strong>Adversary Research <\/strong>\u00a0<\/p>\n<p>In this step of the framework, you need to select adversaries and\/or TTPs to research that are relevant to your organization. It\u2019s important to align this step with your cybersecurity objectives. The requirements of adversary research are understanding the threat landscape and how it relates to your business. Researching adversaries should not be arbitrary. This step takes a lot of time, so you need to make it worth it by conducting good, relevant research. \u00a0<\/p>\n<p><strong>Internal Research\u00a0<\/strong>\u00a0<\/p>\n<p>Internal research involves discussing what cyber threats the internal teams are concerned about and reviewing past incidents. Important teams to include in this research are the threat intel team and network defenders\/system administrators. In this step, it\u2019s beneficial to look at past incidents and see how you\u2019ve remediated those issues. Many companies get attacked in the same way multiple times. \u00a0<\/p>\n<p><strong>External Research\u00a0<\/strong>\u00a0<\/p>\n<p>External research can be done by accessing publicly available information, such as ATT&amp;CK\/Tidal Cyber Community, CTI article, and industry reports (<a href=\"https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/?cmp=knc:bin:ac:ent:ea:na:8888855284_ds_cid=71700000082347690_ds_agid=58700006959926794&amp;utm_term=verizon%20data%20breach%20report&amp;utm_medium=cpc&amp;utm_source=bing&amp;utm_campaign=BNG_BND_Security_Exact&amp;utm_content=Enterprise&amp;ds_cid=71700000082347690&amp;ds_cid=&amp;&amp;msclkid=c34405ba0f161900504e63a789675b5d&amp;gclid=c34405ba0f161900504e63a789675b5d&amp;gclsrc=3p.ds\" target=\"_blank\" rel=\"nofollow noreferrer noopener external\">Verizon Data Breach Report<\/a>). However, when you\u2019re conducting external research, be wary of headline bias when selecting threats.\u00a0\u00a0<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<p>How do you know when your TTP research is complete? Initial research is usually done when you have a short list of threat actors or techniques that align with cyber security goals, and you can clearly communicate their relevance. It\u2019s important that you know how to move forward, and you know how to communicate that strategy to the organization. \u00a0<\/p>\n<p><strong>Threat Selection Considerations:<\/strong>\u00a0<\/p>\n<p>Make sure your TTPs are aligned with your business. \u00a0<\/p>\n<p>Testers\u00a0need enough CTI to replicate a certain threat. If there\u2019s not enough CTI, it may not be a threat that is eligible for this exercise. \u00a0<\/p>\n<p>Make sure you have the time, staff, and expertise to replicate a certain threat.\u00a0<\/p>\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-3-simulation-planning\">3. <strong>Simulation Planning<\/strong><\/h3>\n<p>Planning for your threat simulation is an essential step to this framework. Threat simulation can cause significant issues if not properly planned, such as disclosure of sensitive data, data loss, and unplanned downtime, not to mention that executing adversary TTPs without permission will very quickly land you in trouble. Proper planning is essential to a successful adversary emulation engagement.\u00a0\u00a0<\/p>\n<p>So, what\u2019s the best way to plan for a threat simulation? Threat simulation planning generally includes <strong>documenting<\/strong> the following: \u00a0<\/p>\n<p>It\u2019s important to be able to describe and document the relevance to your organization and why you\u2019re taking on the TTPs. \u00a0<\/p>\n<p>In this context, scope identifies organizations, users, and\/or devices upon which adversary emulation activities are permitted, like organizational units, users, and devices. In this step of the planning, testers need to work with network owners and system administrators to identify and document devices that are in scope. Network diagrams can be helpful in this step as long as they are accurate. You\u2019ll also need to identify high-value assets and the assets specifically out of scope. \u00a0<\/p>\n<p>The schedule defines dates and times in which adversary emulation activities occur and when deliverables are due. This step of planning is important for deconflicting adversary emulation activity against legitimate business operations and identifying periods in which adversary emulation activities should not occur.\u00a0\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>Rules of engagement (RoE)\u00a0<\/li>\n<\/ul>\n<p>What TTPs are permitted? What mitigations can be applied for high risk TTPs? The Rules of Engagement document defines acceptable adversary emulation behavior. This is the time to talk through sensitive situations. You\u2019ll need to discuss cohabitation of malware, deviation from approved scope, disclosure of sensitive information, and observed illegal or unauthorized activity.\u00a0\u00a0<\/p>\n<p>Pen testers <em>always<\/em> need to get explicit permission to conduct the adversary emulation activity from the network owners, but first, testers need to make sure they have sufficient authority to authorize the engagement. Testers should never assume they have the authority to practice adversary emulation in a network they don\u2019t personally own, otherwise, they risk serious legal and\/or criminal action.\u00a0\u00a0<\/p>\n<p>The communication\u2019s plan describes how the threat simulation team will communicate with the network owners. Everyone needs to agree on a time and how often that communication should occur. Another important item to discuss in this step of planning is whether the engagement will be collaborative, like a purple team, or will it be opaque\/black box?\u00a0\u00a0<\/p>\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-4-ttp-preparation\">4. <strong>TTP Preparation <\/strong><\/h3>\n<p>TTP implementations form the substance of threat simulation. This step in the framework provides a trusted means to execute adversary behaviors and enables testers to tune defenses around adversary behaviors.\u00a0<\/p>\n<p><strong>TTP Outline\u00a0<\/strong>\u00a0<\/p>\n<p>After the testers finish defining their TTPs, they want to integrate them into an adversary emulation plan. This plan will be a step-by-step procedure for emulating adversary TTPs and will package all needed scripts, binaries, and tools to execute the plan.\u00a0<\/p>\n<p>Below is an example of a TTP outline.\u00a0<\/p>\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1154\" height=\"508\" sizes=\"auto, (max-width: 1154px) 100vw, 1154px\" src=\"https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2024\/04\/image-1154x508.png\" alt=\"\" class=\"wp-image-35448\" style=\"width:872px;height:auto\" srcset=\"https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2024\/04\/image-1154x508.png 1154w, https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2024\/04\/image-750x330.png 750w, https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2024\/04\/image-1536x676.png 1536w, https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2024\/04\/image.png 1600w\"\/><\/figure>\n<p><strong>TTP Procedure\u00a0<\/strong>\u00a0<\/p>\n<p>It\u2019s important that the TTP procedure includes all resources needed to execute the TTP(s). However, this isn\u2019t a rigid format, as many projects have their own conventions.\u00a0\u00a0<\/p>\n<p>The figure below shows an example of the procedure for executing one or more adversary behaviors. \u00a0<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1025\" height=\"454\" sizes=\"auto, (max-width: 1025px) 100vw, 1025px\" src=\"https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2024\/04\/image-2.png\" alt=\"\" class=\"wp-image-35450\" srcset=\"https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2024\/04\/image-2.png 1025w, https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2024\/04\/image-2-750x332.png 750w\"\/><\/figure>\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-5-conduct-simulation\">5. <strong>Conduct Simulation<\/strong><\/h3>\n<p>By this point in the framework, the TTPs have been implemented into an adversary emulation plan. The pen testers are now ready to conduct the adversary emulation engagement, and this will look a little different for different\u00a0organizations depending on what you want to test and how.\u00a0<\/p>\n<p><strong>Execute Procedures\u00a0<\/strong>\u00a0<\/p>\n<p>Execution entails running your TTPs against target systems. The pen testers have selected the techniques, will execute the techniques, and will review\/ observe the results. \u00a0<\/p>\n<h3 class=\"wp-block-heading has-medium-font-size\" id=\"h-6-report-results\">6. <strong>Report Results<\/strong><\/h3>\n<p>Arguably, the most important aspect of adversary emulation is documenting your activities, findings, and recommendations. Documentation provides empirical proof of what you accomplished; it\u2019s the record that network owners use to make decisions. Keep in mind that a good engagement with poor documentation is of minimal value.\u00a0\u00a0<\/p>\n<p>Three forms of documentation you should expect from your threat simulation partner after the exercise occurs: \u00a0<\/p>\n<p><strong>Operational Notes\u00a0<\/strong>\u00a0<\/p>\n<p>Operational notes describe the testers\u2019 activities during an engagement. The notes should answer who, what, when, why, and how. Keep command transcripts and logs, things you would expect from a penetration test report with a bit more rigor. \u00a0<\/p>\n<p><strong>Professional Report<\/strong>\u00a0<\/p>\n<p>The professional report will include a description of<strong> <\/strong>engagement, objectives, scope, and some sort of narrative from the tester\u2019s point of view.\u00a0<\/p>\n<p><strong>Executive Presentation\u00a0<\/strong>\u00a0<\/p>\n<p>If you have all of your operational notes and you have your professional report, this presentation should be fairly simple to put together in a way that is conducive to whatever audience the presentation is being presented to. Testing teams can gear the presentation towards executives if the board is being presented to, or they can make the presentation more technical if system admins or network defenders want this information. \u00a0<\/p>\n<h2 class=\"wp-block-heading has-medium-font-size\" id=\"h-undergo-threat-simulation-with-kirkpatrickprice\"><strong>Undergo Threat Simulation with KirkpatrickPrice <\/strong><\/h2>\n<p>The threat landscape can be overwhelming to think about, especially since it\u2019s constantly evolving. And although offensive security is a great way to stay on top of today\u2019s threats, the process can feel scary because it\u2019s essential that you work with someone you can trust. At KirkpatrickPrice, we have an offensive security team full of experts who care about helping you fortify your defenses against today\u2019s threats. If you enjoyed this webinar recap, make sure to register for part two of our Threat-Informed Defense series that will cover purple teaming. Save your spot <a href=\"https:\/\/streamyard.com\/watch\/3VufaSS4Kn5v\" target=\"_blank\" rel=\"nofollow noreferrer noopener external\">here<\/a>! \u00a0<\/p>\n<p>In the meantime, if you\u2019re looking to start a threat simulation exercise of your own or have questions about your environment, <a href=\"https:\/\/kirkpatrickprice.com\/penetration-test\/\" target=\"_blank\" rel=\"noreferrer noopener\">connect with one of our experts<\/a> today. \u00a0<\/p>\n<div class=\"auth-bio grid-container\">\n<div class=\"grid-x grid-margin-x\">\n<div class=\"cell medium-3\"><img loading=\"lazy\" decoding=\"async\" data-del=\"avatar\" src=\"https:\/\/kirkpatrickprice.com\/wp-content\/uploads\/2023\/02\/Thurmond-Tori_9-27-22-300x300.jpg\" class=\"avatar pp-user-avatar avatar-96 photo \" height=\"96\" width=\"96\"\/><\/div>\n<div class=\"cell medium-9\">\n<h5>About the Author<\/h5>\n<h4> Tori Thurmond<\/h4>\n<p class=\"author_details\">Tori Thurmond has degrees in both professional and creative writing. She has over five years of copywriting experience and enjoys making difficult topics, like cybersecurity compliance, accessible to all. Since starting at KirkpatrickPrice in 2022, she&#8217;s earned her CC certification from (ISC)2 which has aided her ability to contribute to the company culture of educating, empowering, and inspiring KirkpatrickPrice&#8217;s clients and team members.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p>&#13;<br \/>\n&#13;<br \/>\n&#13;<br \/>\n&#13;<br \/>\n <!-- end #grid-x --><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>by Tori Thurmond \/ April 18th, 2024 Cyber threats pose significant risk to organizations worldwide, ranging from financial loss to reputational damage to operational disruptions. These ever-evolving threats can be intimidating, but with the right preparation, organizations can proactively mitigate risks and fortify their overall cybersecurity posture. One way to offensively protect your organization from [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":76308,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11759],"tags":[14431,21436,3341,6283,14898],"dealstore":[],"offerexpiration":[],"class_list":["post-76307","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-accounting","tag-defense","tag-informed","tag-part","tag-simulation","tag-threat"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Threat Informed Defense (Part 1): Threat Simulation - Som2ny Network<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fivemor.com\/?p=76307\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Threat Informed Defense (Part 1): Threat Simulation - Som2ny Network\" \/>\n<meta property=\"og:description\" content=\"by Tori Thurmond \/ April 18th, 2024 Cyber threats pose significant risk to organizations worldwide, ranging from financial loss to reputational damage to operational disruptions. These ever-evolving threats can be intimidating, but with the right preparation, organizations can proactively mitigate risks and fortify their overall cybersecurity posture. One way to offensively protect your organization from [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fivemor.com\/?p=76307\" \/>\n<meta property=\"og:site_name\" content=\"Som2ny Network\" \/>\n<meta property=\"article:published_time\" content=\"2025-02-08T18:37:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Webinar-Invite-Pentestv2.png\" \/>\n\t<meta property=\"og:image:width\" content=\"2667\" \/>\n\t<meta property=\"og:image:height\" content=\"1500\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fivemor.com\/?p=76307#article\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/?p=76307\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\"},\"headline\":\"Threat Informed Defense (Part 1): Threat Simulation\",\"datePublished\":\"2025-02-08T18:37:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=76307\"},\"wordCount\":2179,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=76307#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Webinar-Invite-Pentestv2.png\",\"keywords\":[\"Defense\",\"Informed\",\"PART\",\"Simulation\",\"threat\"],\"articleSection\":[\"Accounting\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fivemor.com\/?p=76307#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fivemor.com\/?p=76307\",\"url\":\"https:\/\/fivemor.com\/?p=76307\",\"name\":\"Threat Informed Defense (Part 1): Threat Simulation - Som2ny Network\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=76307#primaryimage\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=76307#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Webinar-Invite-Pentestv2.png\",\"datePublished\":\"2025-02-08T18:37:25+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/fivemor.com\/?p=76307#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fivemor.com\/?p=76307\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/?p=76307#primaryimage\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Webinar-Invite-Pentestv2.png\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Webinar-Invite-Pentestv2.png\",\"width\":2667,\"height\":1500},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fivemor.com\/?p=76307#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/fivemor.com\/?bp_activities=1\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Threat Informed Defense (Part 1): Threat Simulation\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fivemor.com\/#website\",\"url\":\"https:\/\/fivemor.com\/\",\"name\":\"Som2ny Network\",\"description\":\"Daily Deals\",\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fivemor.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/fivemor.com\/#organization\",\"name\":\"Som2ny Network\",\"url\":\"https:\/\/fivemor.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"width\":300,\"height\":86,\"caption\":\"Som2ny Network\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/fivemor.com\"],\"url\":\"https:\/\/fivemor.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Threat Informed Defense (Part 1): Threat Simulation - Som2ny Network","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fivemor.com\/?p=76307","og_locale":"en_US","og_type":"article","og_title":"Threat Informed Defense (Part 1): Threat Simulation - Som2ny Network","og_description":"by Tori Thurmond \/ April 18th, 2024 Cyber threats pose significant risk to organizations worldwide, ranging from financial loss to reputational damage to operational disruptions. These ever-evolving threats can be intimidating, but with the right preparation, organizations can proactively mitigate risks and fortify their overall cybersecurity posture. One way to offensively protect your organization from [&hellip;]","og_url":"https:\/\/fivemor.com\/?p=76307","og_site_name":"Som2ny Network","article_published_time":"2025-02-08T18:37:25+00:00","og_image":[{"width":2667,"height":1500,"url":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Webinar-Invite-Pentestv2.png","type":"image\/png"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fivemor.com\/?p=76307#article","isPartOf":{"@id":"https:\/\/fivemor.com\/?p=76307"},"author":{"name":"admin","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371"},"headline":"Threat Informed Defense (Part 1): Threat Simulation","datePublished":"2025-02-08T18:37:25+00:00","mainEntityOfPage":{"@id":"https:\/\/fivemor.com\/?p=76307"},"wordCount":2179,"commentCount":0,"publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"image":{"@id":"https:\/\/fivemor.com\/?p=76307#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Webinar-Invite-Pentestv2.png","keywords":["Defense","Informed","PART","Simulation","threat"],"articleSection":["Accounting"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fivemor.com\/?p=76307#respond"]}]},{"@type":"WebPage","@id":"https:\/\/fivemor.com\/?p=76307","url":"https:\/\/fivemor.com\/?p=76307","name":"Threat Informed Defense (Part 1): Threat Simulation - Som2ny Network","isPartOf":{"@id":"https:\/\/fivemor.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/fivemor.com\/?p=76307#primaryimage"},"image":{"@id":"https:\/\/fivemor.com\/?p=76307#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Webinar-Invite-Pentestv2.png","datePublished":"2025-02-08T18:37:25+00:00","breadcrumb":{"@id":"https:\/\/fivemor.com\/?p=76307#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fivemor.com\/?p=76307"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/?p=76307#primaryimage","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Webinar-Invite-Pentestv2.png","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/Webinar-Invite-Pentestv2.png","width":2667,"height":1500},{"@type":"BreadcrumbList","@id":"https:\/\/fivemor.com\/?p=76307#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/fivemor.com\/?bp_activities=1"},{"@type":"ListItem","position":2,"name":"Threat Informed Defense (Part 1): Threat Simulation"}]},{"@type":"WebSite","@id":"https:\/\/fivemor.com\/#website","url":"https:\/\/fivemor.com\/","name":"Som2ny Network","description":"Daily Deals","publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fivemor.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/fivemor.com\/#organization","name":"Som2ny Network","url":"https:\/\/fivemor.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","width":300,"height":86,"caption":"Som2ny Network"},"image":{"@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","caption":"admin"},"sameAs":["https:\/\/fivemor.com"],"url":"https:\/\/fivemor.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/76307","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=76307"}],"version-history":[{"count":0,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/76307\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/media\/76308"}],"wp:attachment":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=76307"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=76307"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=76307"},{"taxonomy":"dealstore","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdealstore&post=76307"},{"taxonomy":"offerexpiration","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fofferexpiration&post=76307"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}