Defense Guides
11 min read
September 24, 2026

APT Emulation with MITRE ATT&CK: Choosing a Group, Techniques, and Metrics

APT Emulation with MITRE ATT&CK: Choosing a Group, Techniques, and Metrics

APT emulation is a controlled attack in which a red team reproduces the tactics and techniques of one real threat group, as documented in MITRE ATT&CK and in reports on its campaigns. You pick the group from CERT Polska and CSIRT GOV reports that match your sector, take its techniques from its ATT&CK v19 profile, and measure the outcome for every technique: blocked, detected, only logged, or missed. Both sources cover campaigns by APT28, APT29, and UNC1151, among others.

Below we show how those reports and the ATT&CK v19 matrix become a scenario, how TIBER-EU turns threat intelligence into scenarios, and what gets measured at the end. We list techniques only by name, ID, and attack stage, without procedures or tools.

TL;DR - Key takeaways

  • APT emulation simulates one real threat group, not just any attacker
  • MITRE ATT&CK v19 has 15 tactics, with Defense Evasion split in two
  • CERT Polska and CSIRT reports tell you whom to emulate in Poland
  • Pick the group by sector and the techniques by attack stage

APT emulation simulates one real threat group, not just any attacker

Adversary emulation reproduces the behavior of one real threat group, not a generic attacker. The MITRE Center for Threat-Informed Defense (CTID) defines it as replicating the behaviors of real-world threat groups in a safe, repeatable way.

A penetration test looks for as many vulnerabilities as possible within an agreed scope and ends with a list of them. A classic red team engagement has an objective, such as access to the payment system, and can reach it by any route. APT emulation also has an objective, but it narrows the route to the techniques the chosen group uses. The result is specific: not whether your SOC would notice some attacker, but whether it would notice APT29.

Emulation sits on the testing and evaluation side of the triangle that CTID calls threat-informed defense. The other two sides are threat intelligence and defensive measures. That is why our APT attack simulation starts with intelligence and only then moves on to testing.

MITRE ATT&CK v19 has 15 tactics, with Defense Evasion split in two

The Enterprise matrix in MITRE ATT&CK v19 has 15 tactics, and Defense Evasion has been replaced by two new tactics: Stealth and Defense Impairment. This is the biggest change in the April 28, 2026 release. Stealth kept the TA0005 identifier, while Defense Impairment received TA0112. Older reports, SIEM rules, or Navigator layers labeled Defense Evasion therefore need to be remapped.

ATT&CK is an open, free knowledge base of adversary behavior built from observations of real-world attacks. A tactic answers why the attacker does something; a technique describes how. The current order of Enterprise tactics is Reconnaissance, Resource Development, Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Defense Impairment, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, and Impact.

According to the Enterprise techniques page, as of September 24, 2026 (ATT&CK v19.2, released August 6, 2026), the matrix contains 222 techniques and 475 sub-techniques. The v19 release notes list 174 groups for Enterprise. The Groups page shows 180, but that count also covers the Mobile and ICS domains.

CERT Polska and CSIRT reports tell you whom to emulate in Poland

CERT Polska, CSIRT GOV, and CSIRT MON document the groups that target Polish organizations. ATT&CK profiles are global: we found no mention of Poland in the profiles of APT28, APT29, Mustang Panda, or Dragonfly (versions of July 31, 2026). Polish reports say whom to emulate; ATT&CK says how the group operates.

The CERT Polska 2025 annual report has a dedicated chapter on APT groups. CERT Polska recorded increased activity by groups linked to foreign states and notes that it describes only part of what it observes, not always with attribution. Posts on individual campaigns fill in the picture, such as the one on the APT28 campaign against Polish government institutions from May 2024.

The 2025 report by CSIRT GOV, run by the Internal Security Agency (ABW), groups threats into Russian, Belarusian, Chinese, and other vectors, and calls APT28 the dominant source of threats in Polish cyberspace. The CSIRT KNF publications we reviewed do not attribute attacks to APT groups. For the financial sector, the Polish Financial Supervision Authority (KNF) matters mainly because it designates, by administrative decision, the entities required to perform TLPT under DORA (Article 18zk of the Act on Financial Market Supervision).

None of these reports gives a total number of APT incidents in Poland.

APT groups in Polish reports and their MITRE profiles (as of September 24, 2026)
GroupPolish source and dateTarget sectorsMITRE ID
APT28 (Fancy Bear)CERT Polska and CSIRT MON, May 8, 2024; CSIRT GOV report for 2025Central government; according to the CSIRT GOV report for 2024, as covered by CyberDefence24, also energy and transportationG0007
APT29 (NOBELIUM)CERT Polska and SKW (military counterintelligence), April 13, 2023Foreign ministries and diplomatic missions, mainly in NATO and EU countries; according to the CSIRT GOV report for 2024, as covered by CyberDefence24, central government and the militaryG0016
Static Tundra / Berserk Bear / Ghost Blizzard / Dragonfly clusterCERT Polska incident report, January 30, 2026Energy: at least 30 wind and solar farms, a manufacturing company, and a combined heat and power plantG0035 Dragonfly (closest profile)
Mustang PandaCSIRT GOV report for 2025 (file dated September 18, 2026)Campaigns with lures impersonating entities linked to foreign ministries and diplomatic missions; the report also describes Chinese groups targeting the government sectorG0129
UNC1151 (Ghostwriter)CERT Polska, June 5, 2025 and June 12, 2026; CERT Polska and CSIRT GOV reports for 2025Mailboxes of politicians, officials, academics, and journalists; small businesses in the agricultural sectorNo profile
CERT Polska writes that the infrastructure used in the energy sector attack overlaps to a large extent with this cluster's infrastructure. Dragonfly G0035 is the closest profile in ATT&CK, not an attribution by CERT Polska. The phrase "as covered by" marks a secondary source.

Pick the group by sector and the techniques by attack stage

Choose the group by whom it targets, and the techniques by the attack stage at which you want to test your defenses. Our threat intelligence team compares the client's sector with the target sectors in CERT Polska and CSIRT reports. For a ministry or government agency, APT28 and APT29 are the natural choice. For an energy company, the cluster linked to the December 2025 attacks. For a company that serves the diplomatic sector, Mustang Panda. We then select techniques from the group's ATT&CK profile and map each one to a tactic. Examples from four profiles follow at the end of this section.

The profile and the Polish report do not always line up. The APT28 campaign CERT Polska described in 2024 started with an email containing a link, yet the G0007 profile does not include T1566.002 Spearphishing Link. The closest matches are T1204.001 Malicious Link and T1598 Phishing for Information. CERT Polska does not publish ATT&CK IDs, so a mapping like this is an analyst's interpretation, and we label it that way in the plan.

A group without a profile, such as UNC1151, has to be mapped from reports on its campaigns. CERT Polska described two of its campaigns, and each began differently. In 2025, the email had an urgent subject line, and simply opening it in an outdated Roundcube instance triggered an exploit for CVE-2024-42009. After obtaining credentials, the attacker logged into the mailbox and sometimes sent further messages from it. In 2026, the email posed as a notice from Gmail administrators, and the link led to a fake login page. The attackers also phished SMS codes and authenticator app codes. We tag these stages manually as ATT&CK techniques, for example the link from the 2026 campaign as T1598.003 Spearphishing Link under Reconnaissance.

We assemble it all in ATT&CK Navigator, MITRE's layer-based tool, where each layer is a custom view of the matrix. Each group gets its own layer, and overlaying them shows the techniques several groups share. The last layer shows what the client already detects. If you only want to test the post-compromise stages, the scenario becomes an assumed breach test from inside the network.

  • APT28 (G0007): T1598 Phishing for Information (Reconnaissance), T1566.001 Spearphishing Attachment and T1190 Exploit Public-Facing Application (Initial Access), T1204.001 Malicious Link (Execution), T1110 Brute Force (Credential Access).
  • APT29 (G0016): T1566.002 Spearphishing Link and T1195.002 Compromise Software Supply Chain (Initial Access), T1110.003 Password Spraying and T1621 Multi-Factor Authentication Request Generation (Credential Access).
  • Mustang Panda (G0129): T1598.003 Spearphishing Link (Reconnaissance), T1566.001 and T1566.002 (Initial Access), T1091 Replication Through Removable Media (Initial Access and Lateral Movement), T1003 OS Credential Dumping (Credential Access).
  • Dragonfly (G0035): T1598.003 Spearphishing Link (Reconnaissance), T1189 Drive-by Compromise and T1566.001 Spearphishing Attachment (Initial Access), T1187 Forced Authentication and T1110 Brute Force (Credential Access).

How TIBER-EU builds scenarios from threat intelligence

In TIBER-EU, scenarios come from the Targeted Threat Intelligence (TTI) report, prepared by an external threat intelligence provider, not by the red team. Under the 2025 framework, this phase takes roughly 4-6 weeks. The provider gathers information about the entity (attack surface, digital footprint) and its threats (actors, likely scenarios).

The output is a long list of scenarios that differ in actors and techniques and together cover all critical or important functions in scope. They are fictional but based on real attackers' methods. TIBER-EU recommends combining techniques from several relevant actors rather than copying past scenarios, which differs from pure single-group emulation.

The control team lead picks at least three. The TTI report develops them into end-to-end scenarios, one each for service availability, data integrity, and information confidentiality. At most one selected scenario may fall outside the threat analysis (TIBER-EU calls it scenario-X). TLPT under DORA is governed by Delegated Regulation (EU) 2025/1190 (the RTS on TLPT), which also provides for a control team, an external threat intelligence provider, and a red team.

Test objectives are defined as flags. For every system in scope, the control team sets at least one flag: a goal the red team must reach, such as compromising that system's confidentiality, integrity, or availability. A red team that gets stuck can receive a leg-up, such as access to the internal network. A leg-up can never mean handing over the flag itself or disabling security controls. Active testing lasts at least 12 weeks. We collected the deadlines for every TLPT phase and published price ranges in how much red teaming costs and how long TLPT takes.

In Poland, TLPT under DORA is mandatory for entities designated by a KNF decision, while TIBER-EU remains voluntary. In January 2025, the KNF Office (UKNF) announced plans for TIBER-PL, but as of September 24, 2026, Poland was not on the ECB's list of TIBER-EU jurisdictions. When one provider covers both roles, the RTS requires its threat intelligence staff to be separate from, and not report to, the red team. We run them as two separate teams. We meet the DORA Article 27 requirements for TLPT testers and carry professional liability insurance.

What an emulation plan looks like: the CTID library as an example

An emulation plan is the document that turns intelligence about a group into the flow of an operation. As of our check on September 24, 2026, the MITRE CTID library holds 11 full plans: APT29, Blind Eagle, Carbanak, FIN6, FIN7, menuPass, OceanLotus, OilRig, Sandworm, Turla, and Wizard Spider. It also has 12 micro emulation plans.

A full plan models one adversary from initial access through exfiltration. It has three parts: an intelligence summary on the group, an operational flow outlining the scenario, and step-by-step procedures in human-readable and machine-readable form. Micro plans cover a few techniques usually executed together, such as web shells, and can be automated in breach and attack simulation (BAS) tools.

The plans may be used only with prior, explicit authorization to test, and only for security assessment or research. In Poland, the APT29 plan is the most useful, since CERT Polska and SKW documented this group. There is no UNC1151 plan, so we write our own in the same structure: intelligence, operational flow, and techniques mapped to attack stages.

What we measure during APT emulation

Measurement starts with an outcome for every technique executed: did the defenses block it, detect it, only log it, or miss it? The TIBER-EU purple teaming guidance distinguishes actions with no telemetry, actions logged but not detected, mishandled alerts, and ineffective responses. The Blue Team report must also show which controls (for example, EDR or SIEM) detected a step and which stopped it.

The second dimension is time. The TIBER-EU Blue Team report has a timeline placing red team and defender actions side by side, with evidence for every defensive action, such as a ticket number and its creation time. From it you can reconstruct time to detect and time to respond.

The third is coverage on the ATT&CK map, which calls for caution. CTID points out that two organizations can show the same technique in green with very different detection capabilities. If a technique has eight known ways of being executed and your rules detect two, coverage is 2/8. So we mark on the map what your defenses caught during the test, not what the tool vendor promises.

After the test come the replay and purple teaming. The red team and Blue Team walk through the timeline together, then repeat selected techniques and check in real time what the defenders see. In TIBER-EU, both must take place within 10 weeks of the end of active testing.

Our report includes a timeline with detection points, an ATT&CK map of what your defenses caught, and SIEM and EDR recommendations. Then comes a workshop with your Blue Team and one retest included in the price. Outside TLPT, a typical engagement takes 4-8 weeks. We apply the same measurement in our ransomware attack simulation. For how such an attack plays out in practice, see our analysis of a ransomware attack on the Polish healthcare sector.

A green cell on the map doesn't mean detection works

According to the Atomic Red Team FAQ, a technique's color on the project's coverage map in ATT&CK Navigator only means that a test exists for it. Only executing the technique in your environment shows whether detection works.

Emulation in your environment vs. MITRE ATT&CK Evaluations

MITRE ATT&CK Evaluations test security products in MITRE's environment, while emulation in your environment tests your configuration, people, and processes. In Evaluations, MITRE teams reproduce an adversary's full chain of behaviors in a controlled environment, based on vetted and attributed intelligence. The assessments cover detection, prevention, and investigation (the DQI, PQI, and IQI metrics). Enterprise 2025, the seventh round, was based on the behaviors of Scattered Spider and Mustang Panda.

The results cannot be read as an EDR ranking. MITRE's FAQ states that Evaluations do not pick winners and that participation does not imply endorsement, ranking, or certification. A strong product result also won't tell you whether the agent runs on all your servers or whether anyone will handle an alert at night.

To work out which group to emulate in your organization, book a 30-minute call with our team. You will receive a quote within 2 business days.

Summary

Choose the group for APT emulation from Polish reports that match your sector, and the techniques from ATT&CK v19 profiles, where Stealth and Defense Impairment have replaced Defense Evasion. Groups without a profile, such as UNC1151, are mapped from campaign reports. Results are measured for every technique, over time, and on a coverage map, then reviewed with the Blue Team in the replay. MITRE ATT&CK Evaluations assess products, but they won't tell you how your defenses perform on your own network.

Frequently asked questions

How is APT emulation different from a penetration test?

A penetration test looks for as many vulnerabilities as possible within an agreed scope and ends with a list of them. APT emulation reproduces the techniques of one real threat group, as documented in MITRE ATT&CK and in reports on its campaigns. What counts is not how many gaps you find, but whether your defenses detect and stop a specific adversary at each stage of the attack. Results are reported for every technique, together with time to detection.

How do you know which APT groups target Polish companies and institutions?

From reports by CERT Polska, CSIRT GOV, and CSIRT MON. The CERT Polska 2025 annual report has a dedicated chapter on APT groups, and the CSIRT GOV report for 2025 covers the Russian, Belarusian, and Chinese threat vectors. APT28, APT29, and UNC1151 recur across these sources, and CSIRT GOV also describes Mustang Panda. The MITRE ATT&CK profiles of APT28, APT29, Mustang Panda, and Dragonfly do not mention Poland, so choosing a group starts with Polish reports.

What if a group from a CERT Polska report is not in MITRE ATT&CK?

You map its techniques from campaign reports. UNC1151 has no ATT&CK profile, but CERT Polska described the stages of two of its campaigns. In 2025, the email exploited a Roundcube vulnerability, and compromised mailboxes sometimes sent further messages. In 2026, a link led to a fake Gmail login page, and the attackers phished second-factor codes. Each stage is assigned to an ATT&CK technique and tactic and marked in the plan as an analyst's interpretation. For the December 2025 energy sector attack, the closest profile is Dragonfly G0035.

Why is there no Defense Evasion tactic in MITRE ATT&CK anymore?

In the v19 release of April 28, 2026, MITRE split Defense Evasion into two tactics: Stealth, which kept the TA0005 identifier, and Defense Impairment, identified as TA0112. The Enterprise matrix now has 15 tactics. If your SIEM rules, reports, or ATT&CK Navigator layers refer to Defense Evasion, remap them. Otherwise you will not be able to compare coverage from a test against the current matrix.

Do MITRE ATT&CK Evaluations results show which EDR is best?

No. MITRE states in its FAQ that Evaluations do not produce a ranking or pick winners, and that participation does not imply endorsement or certification. The assessments show how a product handles detection, prevention, and investigation in MITRE's test environment. They do not show how the same product performs on your network, with your configuration and your team. Only emulation in your own environment can answer that question.

How long does APT emulation take?

A typical engagement we run takes 4-8 weeks. Narrower variants, such as an assumed breach test from inside the network, usually take 2-4 weeks. Regulatory tests take longer: under DORA TLPT and TIBER-EU, the active red team phase alone lasts at least 12 weeks. It is preceded by a threat intelligence phase, which takes roughly 4-6 weeks under TIBER-EU and usually about 4 weeks according to recital 18 of Delegated Regulation (EU) 2025/1190.

Bibliography

1
Adversary Emulation Library

MITRE Center for Threat-Informed Defense. Definition of adversary emulation, list of full plans and micro plans, accessed September 24, 2026

2
Adversary Emulation Library - README

MITRE Center for Threat-Informed Defense, GitHub. Plan structure and terms of use, accessed September 24, 2026

3
Micro Emulation Plans

MITRE Center for Threat-Informed Defense, accessed September 24, 2026

4
Our Mission: What is Threat-Informed Defense?

MITRE Center for Threat-Informed Defense, accessed September 24, 2026

5
Beyond the Heatmap: Summiting the Pyramid 2026

MITRE Center for Threat-Informed Defense, September 10, 2026, accessed September 24, 2026

6
MITRE ATT&CK

MITRE ATT&CK, home page. Description of the knowledge base, accessed September 24, 2026

7
Enterprise Tactics

MITRE ATT&CK. Tactic definitions and their order, accessed September 24, 2026

8
ATT&CK v19 - updates April 2026

MITRE ATT&CK, April 28, 2026, accessed September 24, 2026

9
ATT&CK v19.2 - updates August 2026

MITRE ATT&CK, August 6, 2026, accessed September 24, 2026

10
Enterprise Matrix

MITRE ATT&CK, accessed September 24, 2026

11
Enterprise Techniques

MITRE ATT&CK, accessed September 24, 2026

12
Groups

MITRE ATT&CK, accessed September 24, 2026

13
APT28, G0007

MITRE ATT&CK, profile dated July 31, 2026, accessed September 24, 2026

14
APT29, G0016

MITRE ATT&CK, profile dated July 31, 2026, accessed September 24, 2026

15
Dragonfly, G0035

MITRE ATT&CK, profile dated July 31, 2026, accessed September 24, 2026

16
Mustang Panda, G0129

MITRE ATT&CK, profile dated July 31, 2026, accessed September 24, 2026

17
ATT&CK Navigator

MITRE ATT&CK, GitHub, accessed September 24, 2026

18
MITRE ATT&CK Evaluations

MITRE, accessed September 24, 2026

19
MITRE ATT&CK Evaluations - FAQ

MITRE, accessed September 24, 2026

20
APT28 campaign targeting Polish government institutions

CERT Polska, May 8, 2024 (in Polish), accessed September 24, 2026

21
CERT Polska and SKW warn of activity by Russian spies

CERT Polska, April 13, 2023 (in Polish), accessed September 24, 2026

22
UNC1151 campaign exploiting a Roundcube vulnerability to steal credentials

CERT Polska, June 5, 2025 (in Polish), accessed September 24, 2026

23
UNC1151/Ghostwriter phishing campaign targeting Gmail accounts

CERT Polska, June 12, 2026 (in Polish), accessed September 24, 2026

24
Energy sector incident report (December 2025)

CERT Polska, January 30, 2026 (in Polish), accessed September 24, 2026

25
CERT Polska Annual Report 2025

CERT Polska (NASK), April 8, 2026 (in Polish), accessed September 24, 2026

26
Report on the State of Security of Poland's Cyberspace in 2025

CSIRT GOV (Internal Security Agency, ABW), file dated September 18, 2026 (in Polish), accessed September 24, 2026

27
Polish government and military targeted by Russian intelligence: CSIRT GOV report

CyberDefence24, May 30, 2025 (coverage of the CSIRT GOV report for 2024, in Polish), accessed September 24, 2026

28
TLPT tests: a new approach

Polish Financial Supervision Authority (KNF), updated July 14, 2025 (in Polish), accessed September 24, 2026

29
TIBER-EU framework implementations in Europe and its rollout in Poland

Polish Financial Supervision Authority (KNF), updated January 27, 2025 (in Polish), accessed September 24, 2026

30
Journal of Laws 2025, item 1069: Article 18zk of the Act on Financial Market Supervision

Journal of Laws of the Republic of Poland (Dziennik Ustaw), August 6, 2025. Article 8(6) adds Article 18zk(1) to the Act on Financial Market Supervision (designation of an entity for TLPT by a KNF decision), in Polish, accessed September 24, 2026

31
TIBER-EU Framework

European Central Bank, January 2025, accessed September 24, 2026

32
TIBER-EU Purple Teaming Guidance

European Central Bank, January 2025, accessed September 24, 2026

33
TIBER-EU Blue Team Test Report Guidance

European Central Bank, January 2025, accessed September 24, 2026

34
TIBER-EU - list of jurisdictions

European Central Bank, accessed September 24, 2026

35
Commission Delegated Regulation (EU) 2025/1190 (RTS on TLPT)

Official Journal of the European Union, June 18, 2025, accessed September 24, 2026

36
Regulation (EU) 2022/2554 (DORA), Article 27

Official Journal of the European Union, December 27, 2022. Requirements for TLPT testers, accessed September 24, 2026

37
Atomic Red Team - FAQ

Red Canary, accessed September 24, 2026

Want to know whether your defenses would detect APT28 or APT29?

We select the group and techniques based on CERT Polska and CSIRT reports and MITRE ATT&CK profiles. You get a timeline with detection points, an ATT&CK map, SIEM and EDR recommendations, a workshop with your Blue Team, and one retest included in the price.

Explore APT attack simulation