Threat Simulator — Breach and Attack Simulation
The Keysight Threat Simulator is a breach and attack simulation platform that helps enterprise security teams improve their security posture with actionable intelligence. It simulates attacks on a company’s network, identifies vulnerabilities, and offers actionable steps for remediation. Using up-to-date threat intelligence, the simulator continuously verifies that security controls across the enterprise work optimally for maximum protection.
Key features of the Threat Simulator include:
– A flexible, cloud-based platform that scales with network growth.
– Actionable remediation recommendations to improve and optimise security controls.
– Multi-tenancy access control and segmentation.
– A library of MITRE ATT&CK techniques and threat vectors to validate network, endpoint, and email security controls.
– A scheduler for continuous security assessments.
– Visual ladder diagrams.
Delivered as a SaaS solution, Threat Simulator can also be deployed on-premise. For the SaaS version, the platform’s serverless design enables auto-scaling on demand. The on-premise version supports deployment on hypervisors like VMware ESXi™ or Linux KVM, even without internet connectivity. It includes the infrastructure component and a customized on-premises version of the Dark Cloud.
Threat Simulator integrates with an ecosystem of network security controls to provide specific, actionable recommendations for enhancing cybersecurity effectiveness. Integration with SIEM vendors ensures end-to-end validation of prevention and detection tools.
The platform performs network, endpoint, and email security assessments, offering both recurring and one-time engagements. It can simulate attacks on a production network, expose vulnerable misconfigurations, and deliver precise instructions for remediation and prioritisation of fixes. A standard assessment covers an entire defensive deployment, while tailored audits can focus on specific areas, such as branch or email security.



