Cymulate assessment
cymulate api → run assessment
Executes a Cymulate (BAS) assessment via the API, validating detection coverage with the continuous simulation platform.
Run it in the purple team lab when you want validation with Cymulate's BAS platform: the assessment (the attack module with its vectors) runs from the API or the interface on the agents, and the platform measures coverage — the score per vector. It's scale validation with the SaaS platform: periodic assessments (phishing, web, endpoint) and the coverage metric. In purple teaming, Cymulate (and BAS) automate validation: the assessment runs, coverage is measured, and gaps are worked — the API enables integration with the team's flow.
Don't use it without deployment: Cymulate needs the agents (the connectors) and the subscription — infrastructure and license are the requirement. Assessments generate real attacks: the lab is the place. And watch out: the platform measures coverage of its vectors — environment-specific ones require custom assessments. Cymulate's API requires credentials (the API key) — handle them with care. For a tight budget, open-source alternatives cover the ground.