BAS
Breach and Attack Simulation
BAS platforms automatically simulate real-world attack techniques against an organization's production environment to test whether security controls detect and prevent them. BAS runs continuously, providing ongoing validation rather than point-in-time testing.
Como é usado em cibersegurança
Security engineers run BAS scenarios to verify that SIEM rules, EDR policies, and firewall configurations actually block known attack chains. Penetration testers use BAS results to identify control gaps before manual testing begins. CISOs use BAS reports to measure defensive coverage against MITRE ATT&CK techniques and track improvement over time.
As definições são explicações originais escritas para fins de desenvolvimento profissional. Para definições técnicas autoritativas, consulte NIST, ISO ou o órgão de normalização correspondente.