SafeBreach playbook

safebreach → playbook → execute

Executes a SafeBreach (BAS) playbook on the simulators, validating detection and prevention coverage with the platform.

Run it in the purple team lab when you want validation with the SafeBreach BAS platform: the playbook groups attack methods (techniques with their variations) and execution launches them on the simulators (the agents) — the platform measures coverage per method: detected, prevented, or no coverage. It's scale validation with the commercial platform: adversary playbooks executed and the metric. In purple teaming, SafeBreach (and BAS) automate continuous validation with granularity per attack method.

Don't use it without the deployment: SafeBreach needs the simulators (the agents) and the platform — infrastructure and license are the requirement. Playbooks generate real attacks: the lab is the place. And watch out: the platform measures coverage of its methods — environment-specific ones require your own playbooks. The metric (detected vs. prevented) is interpreted with context: prevention (blocking) and detection are distinct coverages. For a reduced budget, open source alternatives (Atomic, CALDERA, Prelude) cover the ground.