Bishop Fox
Adversarial Controls Testing Methodology
Pages
6
Time to read
8 mins
Publication
Language
English
Pages
6
Time to read
8 mins
Publication
Language
English
This document is a technical report detailing the Adversarial Controls Testing (ACT) methodology employed by Bishop Fox. The ACT methodology assesses the effectiveness of email, endpoint, and network security controls through an attack-based approach tailored to specific client environments. The process begins with a pre-assessment phase that includes an engagement kickoff meeting to establish rules of engagement, gather security controls information, and develop a testing plan. The testing phase involves the creation and deployment of tailored injects or payloads, active testing of security controls, and real-time feedback on detection capabilities. Finally, the reporting phase culminates in a comprehensive report that includes test results, assessment scores, and recommendations for improving security controls. The collaborative nature of the engagement allows the client's security team to participate actively throughout the process, ensuring a thorough evaluation of the security posture against real-world attack behaviors mapped to the MITRE ATT&CK framework.