APT emulation is a controlled attack in which a red team reproduces the tactics and techniques of one real threat group, as documented in MITRE ATT&CK and in reports on its campaigns. You pick the group from CERT Polska and CSIRT GOV reports that match your sector, take its techniques from its ATT&CK v19 profile, and measure the outcome for every technique: blocked, detected, only logged, or missed. Both sources cover campaigns by APT28, APT29, and UNC1151, among others.
Below we show how those reports and the ATT&CK v19 matrix become a scenario, how TIBER-EU turns threat intelligence into scenarios, and what gets measured at the end. We list techniques only by name, ID, and attack stage, without procedures or tools.
TL;DR - Key takeaways
- APT emulation simulates one real threat group, not just any attacker
- MITRE ATT&CK v19 has 15 tactics, with Defense Evasion split in two
- CERT Polska and CSIRT reports tell you whom to emulate in Poland
- Pick the group by sector and the techniques by attack stage
APT emulation simulates one real threat group, not just any attacker
Adversary emulation reproduces the behavior of one real threat group, not a generic attacker. The MITRE Center for Threat-Informed Defense (CTID) defines it as replicating the behaviors of real-world threat groups in a safe, repeatable way.
A penetration test looks for as many vulnerabilities as possible within an agreed scope and ends with a list of them. A classic red team engagement has an objective, such as access to the payment system, and can reach it by any route. APT emulation also has an objective, but it narrows the route to the techniques the chosen group uses. The result is specific: not whether your SOC would notice some attacker, but whether it would notice APT29.
Emulation sits on the testing and evaluation side of the triangle that CTID calls threat-informed defense. The other two sides are threat intelligence and defensive measures. That is why our APT attack simulation starts with intelligence and only then moves on to testing.
MITRE ATT&CK v19 has 15 tactics, with Defense Evasion split in two
The Enterprise matrix in MITRE ATT&CK v19 has 15 tactics, and Defense Evasion has been replaced by two new tactics: Stealth and Defense Impairment. This is the biggest change in the April 28, 2026 release. Stealth kept the TA0005 identifier, while Defense Impairment received TA0112. Older reports, SIEM rules, or Navigator layers labeled Defense Evasion therefore need to be remapped.
ATT&CK is an open, free knowledge base of adversary behavior built from observations of real-world attacks. A tactic answers why the attacker does something; a technique describes how. The current order of Enterprise tactics is Reconnaissance, Resource Development, Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Defense Impairment, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, and Impact.
According to the Enterprise techniques page, as of September 24, 2026 (ATT&CK v19.2, released August 6, 2026), the matrix contains 222 techniques and 475 sub-techniques. The v19 release notes list 174 groups for Enterprise. The Groups page shows 180, but that count also covers the Mobile and ICS domains.
CERT Polska and CSIRT reports tell you whom to emulate in Poland
CERT Polska, CSIRT GOV, and CSIRT MON document the groups that target Polish organizations. ATT&CK profiles are global: we found no mention of Poland in the profiles of APT28, APT29, Mustang Panda, or Dragonfly (versions of July 31, 2026). Polish reports say whom to emulate; ATT&CK says how the group operates.
The CERT Polska 2025 annual report has a dedicated chapter on APT groups. CERT Polska recorded increased activity by groups linked to foreign states and notes that it describes only part of what it observes, not always with attribution. Posts on individual campaigns fill in the picture, such as the one on the APT28 campaign against Polish government institutions from May 2024.
The 2025 report by CSIRT GOV, run by the Internal Security Agency (ABW), groups threats into Russian, Belarusian, Chinese, and other vectors, and calls APT28 the dominant source of threats in Polish cyberspace. The CSIRT KNF publications we reviewed do not attribute attacks to APT groups. For the financial sector, the Polish Financial Supervision Authority (KNF) matters mainly because it designates, by administrative decision, the entities required to perform TLPT under DORA (Article 18zk of the Act on Financial Market Supervision).
None of these reports gives a total number of APT incidents in Poland.
| Group | Polish source and date | Target sectors | MITRE ID |
|---|---|---|---|
| APT28 (Fancy Bear) | CERT Polska and CSIRT MON, May 8, 2024; CSIRT GOV report for 2025 | Central government; according to the CSIRT GOV report for 2024, as covered by CyberDefence24, also energy and transportation | G0007 |
| APT29 (NOBELIUM) | CERT Polska and SKW (military counterintelligence), April 13, 2023 | Foreign ministries and diplomatic missions, mainly in NATO and EU countries; according to the CSIRT GOV report for 2024, as covered by CyberDefence24, central government and the military | G0016 |
| Static Tundra / Berserk Bear / Ghost Blizzard / Dragonfly cluster | CERT Polska incident report, January 30, 2026 | Energy: at least 30 wind and solar farms, a manufacturing company, and a combined heat and power plant | G0035 Dragonfly (closest profile) |
| Mustang Panda | CSIRT GOV report for 2025 (file dated September 18, 2026) | Campaigns with lures impersonating entities linked to foreign ministries and diplomatic missions; the report also describes Chinese groups targeting the government sector | G0129 |
| UNC1151 (Ghostwriter) | CERT Polska, June 5, 2025 and June 12, 2026; CERT Polska and CSIRT GOV reports for 2025 | Mailboxes of politicians, officials, academics, and journalists; small businesses in the agricultural sector | No profile |
Pick the group by sector and the techniques by attack stage
Choose the group by whom it targets, and the techniques by the attack stage at which you want to test your defenses. Our threat intelligence team compares the client's sector with the target sectors in CERT Polska and CSIRT reports. For a ministry or government agency, APT28 and APT29 are the natural choice. For an energy company, the cluster linked to the December 2025 attacks. For a company that serves the diplomatic sector, Mustang Panda. We then select techniques from the group's ATT&CK profile and map each one to a tactic. Examples from four profiles follow at the end of this section.
The profile and the Polish report do not always line up. The APT28 campaign CERT Polska described in 2024 started with an email containing a link, yet the G0007 profile does not include T1566.002 Spearphishing Link. The closest matches are T1204.001 Malicious Link and T1598 Phishing for Information. CERT Polska does not publish ATT&CK IDs, so a mapping like this is an analyst's interpretation, and we label it that way in the plan.
A group without a profile, such as UNC1151, has to be mapped from reports on its campaigns. CERT Polska described two of its campaigns, and each began differently. In 2025, the email had an urgent subject line, and simply opening it in an outdated Roundcube instance triggered an exploit for CVE-2024-42009. After obtaining credentials, the attacker logged into the mailbox and sometimes sent further messages from it. In 2026, the email posed as a notice from Gmail administrators, and the link led to a fake login page. The attackers also phished SMS codes and authenticator app codes. We tag these stages manually as ATT&CK techniques, for example the link from the 2026 campaign as T1598.003 Spearphishing Link under Reconnaissance.
We assemble it all in ATT&CK Navigator, MITRE's layer-based tool, where each layer is a custom view of the matrix. Each group gets its own layer, and overlaying them shows the techniques several groups share. The last layer shows what the client already detects. If you only want to test the post-compromise stages, the scenario becomes an assumed breach test from inside the network.
- APT28 (G0007): T1598 Phishing for Information (Reconnaissance), T1566.001 Spearphishing Attachment and T1190 Exploit Public-Facing Application (Initial Access), T1204.001 Malicious Link (Execution), T1110 Brute Force (Credential Access).
- APT29 (G0016): T1566.002 Spearphishing Link and T1195.002 Compromise Software Supply Chain (Initial Access), T1110.003 Password Spraying and T1621 Multi-Factor Authentication Request Generation (Credential Access).
- Mustang Panda (G0129): T1598.003 Spearphishing Link (Reconnaissance), T1566.001 and T1566.002 (Initial Access), T1091 Replication Through Removable Media (Initial Access and Lateral Movement), T1003 OS Credential Dumping (Credential Access).
- Dragonfly (G0035): T1598.003 Spearphishing Link (Reconnaissance), T1189 Drive-by Compromise and T1566.001 Spearphishing Attachment (Initial Access), T1187 Forced Authentication and T1110 Brute Force (Credential Access).
How TIBER-EU builds scenarios from threat intelligence
In TIBER-EU, scenarios come from the Targeted Threat Intelligence (TTI) report, prepared by an external threat intelligence provider, not by the red team. Under the 2025 framework, this phase takes roughly 4-6 weeks. The provider gathers information about the entity (attack surface, digital footprint) and its threats (actors, likely scenarios).
The output is a long list of scenarios that differ in actors and techniques and together cover all critical or important functions in scope. They are fictional but based on real attackers' methods. TIBER-EU recommends combining techniques from several relevant actors rather than copying past scenarios, which differs from pure single-group emulation.
The control team lead picks at least three. The TTI report develops them into end-to-end scenarios, one each for service availability, data integrity, and information confidentiality. At most one selected scenario may fall outside the threat analysis (TIBER-EU calls it scenario-X). TLPT under DORA is governed by Delegated Regulation (EU) 2025/1190 (the RTS on TLPT), which also provides for a control team, an external threat intelligence provider, and a red team.
Test objectives are defined as flags. For every system in scope, the control team sets at least one flag: a goal the red team must reach, such as compromising that system's confidentiality, integrity, or availability. A red team that gets stuck can receive a leg-up, such as access to the internal network. A leg-up can never mean handing over the flag itself or disabling security controls. Active testing lasts at least 12 weeks. We collected the deadlines for every TLPT phase and published price ranges in how much red teaming costs and how long TLPT takes.
In Poland, TLPT under DORA is mandatory for entities designated by a KNF decision, while TIBER-EU remains voluntary. In January 2025, the KNF Office (UKNF) announced plans for TIBER-PL, but as of September 24, 2026, Poland was not on the ECB's list of TIBER-EU jurisdictions. When one provider covers both roles, the RTS requires its threat intelligence staff to be separate from, and not report to, the red team. We run them as two separate teams. We meet the DORA Article 27 requirements for TLPT testers and carry professional liability insurance.
What an emulation plan looks like: the CTID library as an example
An emulation plan is the document that turns intelligence about a group into the flow of an operation. As of our check on September 24, 2026, the MITRE CTID library holds 11 full plans: APT29, Blind Eagle, Carbanak, FIN6, FIN7, menuPass, OceanLotus, OilRig, Sandworm, Turla, and Wizard Spider. It also has 12 micro emulation plans.
A full plan models one adversary from initial access through exfiltration. It has three parts: an intelligence summary on the group, an operational flow outlining the scenario, and step-by-step procedures in human-readable and machine-readable form. Micro plans cover a few techniques usually executed together, such as web shells, and can be automated in breach and attack simulation (BAS) tools.
The plans may be used only with prior, explicit authorization to test, and only for security assessment or research. In Poland, the APT29 plan is the most useful, since CERT Polska and SKW documented this group. There is no UNC1151 plan, so we write our own in the same structure: intelligence, operational flow, and techniques mapped to attack stages.
What we measure during APT emulation
Measurement starts with an outcome for every technique executed: did the defenses block it, detect it, only log it, or miss it? The TIBER-EU purple teaming guidance distinguishes actions with no telemetry, actions logged but not detected, mishandled alerts, and ineffective responses. The Blue Team report must also show which controls (for example, EDR or SIEM) detected a step and which stopped it.
The second dimension is time. The TIBER-EU Blue Team report has a timeline placing red team and defender actions side by side, with evidence for every defensive action, such as a ticket number and its creation time. From it you can reconstruct time to detect and time to respond.
The third is coverage on the ATT&CK map, which calls for caution. CTID points out that two organizations can show the same technique in green with very different detection capabilities. If a technique has eight known ways of being executed and your rules detect two, coverage is 2/8. So we mark on the map what your defenses caught during the test, not what the tool vendor promises.
After the test come the replay and purple teaming. The red team and Blue Team walk through the timeline together, then repeat selected techniques and check in real time what the defenders see. In TIBER-EU, both must take place within 10 weeks of the end of active testing.
Our report includes a timeline with detection points, an ATT&CK map of what your defenses caught, and SIEM and EDR recommendations. Then comes a workshop with your Blue Team and one retest included in the price. Outside TLPT, a typical engagement takes 4-8 weeks. We apply the same measurement in our ransomware attack simulation. For how such an attack plays out in practice, see our analysis of a ransomware attack on the Polish healthcare sector.
A green cell on the map doesn't mean detection works
According to the Atomic Red Team FAQ, a technique's color on the project's coverage map in ATT&CK Navigator only means that a test exists for it. Only executing the technique in your environment shows whether detection works.
Emulation in your environment vs. MITRE ATT&CK Evaluations
MITRE ATT&CK Evaluations test security products in MITRE's environment, while emulation in your environment tests your configuration, people, and processes. In Evaluations, MITRE teams reproduce an adversary's full chain of behaviors in a controlled environment, based on vetted and attributed intelligence. The assessments cover detection, prevention, and investigation (the DQI, PQI, and IQI metrics). Enterprise 2025, the seventh round, was based on the behaviors of Scattered Spider and Mustang Panda.
The results cannot be read as an EDR ranking. MITRE's FAQ states that Evaluations do not pick winners and that participation does not imply endorsement, ranking, or certification. A strong product result also won't tell you whether the agent runs on all your servers or whether anyone will handle an alert at night.
To work out which group to emulate in your organization, book a 30-minute call with our team. You will receive a quote within 2 business days.
Summary
Choose the group for APT emulation from Polish reports that match your sector, and the techniques from ATT&CK v19 profiles, where Stealth and Defense Impairment have replaced Defense Evasion. Groups without a profile, such as UNC1151, are mapped from campaign reports. Results are measured for every technique, over time, and on a coverage map, then reviewed with the Blue Team in the replay. MITRE ATT&CK Evaluations assess products, but they won't tell you how your defenses perform on your own network.
Frequently asked questions
How is APT emulation different from a penetration test?
A penetration test looks for as many vulnerabilities as possible within an agreed scope and ends with a list of them. APT emulation reproduces the techniques of one real threat group, as documented in MITRE ATT&CK and in reports on its campaigns. What counts is not how many gaps you find, but whether your defenses detect and stop a specific adversary at each stage of the attack. Results are reported for every technique, together with time to detection.
How do you know which APT groups target Polish companies and institutions?
From reports by CERT Polska, CSIRT GOV, and CSIRT MON. The CERT Polska 2025 annual report has a dedicated chapter on APT groups, and the CSIRT GOV report for 2025 covers the Russian, Belarusian, and Chinese threat vectors. APT28, APT29, and UNC1151 recur across these sources, and CSIRT GOV also describes Mustang Panda. The MITRE ATT&CK profiles of APT28, APT29, Mustang Panda, and Dragonfly do not mention Poland, so choosing a group starts with Polish reports.
What if a group from a CERT Polska report is not in MITRE ATT&CK?
You map its techniques from campaign reports. UNC1151 has no ATT&CK profile, but CERT Polska described the stages of two of its campaigns. In 2025, the email exploited a Roundcube vulnerability, and compromised mailboxes sometimes sent further messages. In 2026, a link led to a fake Gmail login page, and the attackers phished second-factor codes. Each stage is assigned to an ATT&CK technique and tactic and marked in the plan as an analyst's interpretation. For the December 2025 energy sector attack, the closest profile is Dragonfly G0035.
Why is there no Defense Evasion tactic in MITRE ATT&CK anymore?
In the v19 release of April 28, 2026, MITRE split Defense Evasion into two tactics: Stealth, which kept the TA0005 identifier, and Defense Impairment, identified as TA0112. The Enterprise matrix now has 15 tactics. If your SIEM rules, reports, or ATT&CK Navigator layers refer to Defense Evasion, remap them. Otherwise you will not be able to compare coverage from a test against the current matrix.
Do MITRE ATT&CK Evaluations results show which EDR is best?
No. MITRE states in its FAQ that Evaluations do not produce a ranking or pick winners, and that participation does not imply endorsement or certification. The assessments show how a product handles detection, prevention, and investigation in MITRE's test environment. They do not show how the same product performs on your network, with your configuration and your team. Only emulation in your own environment can answer that question.
How long does APT emulation take?
A typical engagement we run takes 4-8 weeks. Narrower variants, such as an assumed breach test from inside the network, usually take 2-4 weeks. Regulatory tests take longer: under DORA TLPT and TIBER-EU, the active red team phase alone lasts at least 12 weeks. It is preceded by a threat intelligence phase, which takes roughly 4-6 weeks under TIBER-EU and usually about 4 weeks according to recital 18 of Delegated Regulation (EU) 2025/1190.
Bibliography
MITRE Center for Threat-Informed Defense. Definition of adversary emulation, list of full plans and micro plans, accessed September 24, 2026
MITRE Center for Threat-Informed Defense, GitHub. Plan structure and terms of use, accessed September 24, 2026
MITRE Center for Threat-Informed Defense, accessed September 24, 2026
MITRE Center for Threat-Informed Defense, accessed September 24, 2026
MITRE Center for Threat-Informed Defense, September 10, 2026, accessed September 24, 2026
MITRE ATT&CK, home page. Description of the knowledge base, accessed September 24, 2026
MITRE ATT&CK. Tactic definitions and their order, accessed September 24, 2026
MITRE ATT&CK, April 28, 2026, accessed September 24, 2026
MITRE ATT&CK, August 6, 2026, accessed September 24, 2026
MITRE ATT&CK, accessed September 24, 2026
MITRE ATT&CK, accessed September 24, 2026
MITRE ATT&CK, accessed September 24, 2026
MITRE ATT&CK, profile dated July 31, 2026, accessed September 24, 2026
MITRE ATT&CK, profile dated July 31, 2026, accessed September 24, 2026
MITRE ATT&CK, profile dated July 31, 2026, accessed September 24, 2026
MITRE ATT&CK, profile dated July 31, 2026, accessed September 24, 2026
MITRE ATT&CK, GitHub, accessed September 24, 2026
MITRE, accessed September 24, 2026
MITRE, accessed September 24, 2026
CERT Polska, May 8, 2024 (in Polish), accessed September 24, 2026
CERT Polska, April 13, 2023 (in Polish), accessed September 24, 2026
CERT Polska, June 5, 2025 (in Polish), accessed September 24, 2026
CERT Polska, June 12, 2026 (in Polish), accessed September 24, 2026
CERT Polska, January 30, 2026 (in Polish), accessed September 24, 2026
CERT Polska (NASK), April 8, 2026 (in Polish), accessed September 24, 2026
CSIRT GOV (Internal Security Agency, ABW), file dated September 18, 2026 (in Polish), accessed September 24, 2026
CyberDefence24, May 30, 2025 (coverage of the CSIRT GOV report for 2024, in Polish), accessed September 24, 2026
Polish Financial Supervision Authority (KNF), updated July 14, 2025 (in Polish), accessed September 24, 2026
Polish Financial Supervision Authority (KNF), updated January 27, 2025 (in Polish), accessed September 24, 2026
Journal of Laws of the Republic of Poland (Dziennik Ustaw), August 6, 2025. Article 8(6) adds Article 18zk(1) to the Act on Financial Market Supervision (designation of an entity for TLPT by a KNF decision), in Polish, accessed September 24, 2026
European Central Bank, January 2025, accessed September 24, 2026
European Central Bank, January 2025, accessed September 24, 2026
European Central Bank, January 2025, accessed September 24, 2026
European Central Bank, accessed September 24, 2026
Official Journal of the European Union, June 18, 2025, accessed September 24, 2026
Official Journal of the European Union, December 27, 2022. Requirements for TLPT testers, accessed September 24, 2026
Red Canary, accessed September 24, 2026

