Damage caused by cyberattacks in the German economy (2025)
Ransomware Emulation
We simulate a real ransomware attack in your environment under controlled conditions, challenging your SOC and SIEM. This allows you to see under realistic conditions whether your detection and response truly hold up in an emergency.
Request Attack SimulationThreatSimulator
€202 Billion
34 %
of companies were affected by ransomware (2022: 12%)
14 Days
attackers remain undetected in the network on median
14 %
only notice the attack when the ransom demand arrives
The Real Threat Landscape
Most security leaders know that cyberattacks have become costly and commonplace. The true asymmetry lies elsewhere: Defense must succeed every single time, while an attacker only needs one successful attempt.
Detection and response are usually established, but rarely tested under real-world conditions. This is precisely where ransomware emulation comes in: It tests whether your SOC detects and stops a genuine attack before the attacker achieves their goal.
Alarming Figures
Attackers remain undetected in the network for a median of 14 days, and the trend is rising.
14% of victims only notice the attack when the ransom demand is made.
Sources: Bitkom Cyber Security Survey 2025; Mandiant M-Trends 2026.
The Problem:
A Plan That Has Never Been Tested
You have invested in detection and response: a SOC, a SIEM, and defined processes for an emergency. On paper, it specifies who gets notified by when for which alert, and how to respond.
The open question is whether this plan holds up under pressure. In practice, we repeatedly observe that even mature processes fail in an actual emergency. Sometimes critical alerts get lost among false positives, sometimes the threat level is misjudged, and sometimes no one knows the details of their own playbook at the decisive moment.
As long as a real attack does not occur, this gap goes unnoticed. The SOC runs, dashboards are green, and that creates a false sense of security that has never been put to the test.
The Solution:
Real Threat, Zero Damage
We start right where a real attack becomes dangerous: after the initial breach. Assuming an already compromised system in your network provided by you, we simulate the subsequent attack stages from there.
This directly answers the open question of your current readiness. Instead of hoping that detection and response hold up in an emergency, you see it under real-world conditions—in a safe framework where failure is merely an insight, not a disaster.
The emulation is realistic because we replicate the actual techniques used by real ransomware groups such as Black Basta or LockBit. And it is safe because the software we use cannot harm your actual data or production systems.
Your Benefits at a Glance
Certainty Instead of Hope
You see under real-world conditions whether your detection and response work instead of assuming they do. Transforming “it should work” into “it does work.”
Actionable Insights
You learn not just whether your SOC passed, but exactly where along the attack chain friction occurred and what to improve first.
Robust Verification
You can prove to executive management, auditors, or cyber insurance providers that your resilience has been tested and verified, not merely assumed.
Training Effect for the Team
Your SOC experiences a realistic attack in a safe environment, sharpening their readiness for an actual emergency.
Verifiable Progress & Actionability
The recommendations are practical and directly actionable. We recommend validating the improvements with a retest after about three months, ensuring progress is measured, not just claimed.
Who Is This Service For?
Suitable if you already operate detection and response.
This service is designed for organizations with an internal or outsourced SOC and SIEM and defined incident response processes. The decisive factor is having active detection capabilities that can be challenged.
You are in the right place if you, as a CISO, Head of Security, or IT Director, are accountable for ensuring that these detection capabilities hold up in an emergency.
Emulation is not yet the right service if detection and response are not yet established in your organization. In that case, a penetration test or information security consulting is the more sensible first step.
Also suitable for: Many clients use the emulation for targeted SOC team training, as a purple teaming exercise, or as evidence to meet compliance requirements.
Clear Scope & Boundaries of Our Service
This service has a sharp focus: It verifies whether your SOC detects and halts an active attack. From this, several intentional boundaries follow:
- We test detection, not the initial breach vector. How an attacker initially gets in is intentionally excluded here. For that, we offer classic penetration tests.
- We challenge your SOC, not your disaster recovery. Whether your backups hold up in an emergency is a separate question not answered by this service (not a recovery test).
- Are you currently experiencing an active ransomware attack? Then emulation is not the right choice. In an acute emergency, immediate incident response is required.
Choose the Right Scenario
We don’t offer a one-size-fits-all simulation, but a comprehensive selection. You choose the emulation that matches your industry and threat profile.
Black Basta
Replication of the notorious ransomware group (Windows).
LockBit
The world’s most active RaaS group (Windows).
SPECTR “SickSync”
Specialized data theft (Windows).
Individual techniques across the entire attack chain
In addition to full threat group emulations, individual techniques can be deployed selectively and combined per engagement: PyPI Supply Chain Attack (Linux, macOS, Windows), HTA Downloader, GrayFox Loader, Crossway Agent (Go), Process Injection (indirect/direct syscalls), Privilege Escalation.
The catalog is continuously expanded. Further scenarios are available upon request.
Process & Timeline
A project follows a clear sequence from initial alignment to completion:
Kick-off & Planning
Dogether, we determine the scenario, attack type, and timeframe.
Access & Preparation
You provide an internal test system and an unprivileged account; we configure the emulation.
Execution & Observation
We execute the attack in a controlled manner; your SOC and SIEM respond according to your playbooks.
Analysis & Evaluation
We analyze alerts and responses to identify optimization potential.
Report & Debriefing
You receive the structured final report; we address open questions and provide recommendations.
Methodology & Standards
Our approach is structured and aligned with recognized industry standards.
Simulation Variants
Realistic (Black-Box)
Your SOC team is unaware that a simulation is taking place. We execute the phases independently and observe the authentic response. Ideal for the most candid evaluation.
Guided (Purple Teaming)
We walk through the attack collaboratively with your informed SOC team, pausing after each phase. Ideal as a training or purple teaming exercise.
Scope of Services
- Initial consultation and scenario selection
- Controlled execution on the provided internal system
- Observation and assessment of SOC/SIEM behavior
- Identification and prioritization of optimization opportunities
- Final report with actionable recommendations
- Debriefing meeting to clarify next steps
- Optional: Implementation support for tuning detection rules.
Prerequisites
What you should bring:
- A SOC and SIEM, operated in-house or via a service provider.
- Defined incident response processes.
What you provide to us:
- An internal test system and an unprivileged account.
- A designated point of contact.
- The necessary organizational authorizations.
Ransomware Emulation
You provide an internal system, we simulate an attack. In the initial consultation, we select the scenario and attack type.
- Zero damage to real data and production systems
- Real threat groups like Black Basta & LockBit
- Documented according to MITRE ATT&CK
- Measured detection and response of your SOC
Results & Compliance
You receive a structured final report detailing our findings and prioritized recommendations. This serves as reliable evidence for:
Confidentiality & Data Protection
Results & Compliance
We conduct in-house security research and publish findings through responsible disclosure processes (e.g., vulnerabilities in federal systems, path traversal in surveillance software).
Case Study: Reality Check for the SOC
Initial situation: A major financial services provider wanted to know whether their outsourced SOC would detect an attack in time.
Approach: Realistic emulation (assumed breach) on an internal system without alerting the SOC.
Result: The infection and data exfiltration remained undetected for weeks. The EDR only triggered on very noisy tools. The emulation revealed an actual blind spot, which the client was then able to remediate in a targeted manner.
Frequently Asked Questions
Answers to frequently asked questions about our Ransomware Emulation service.
Can actual damage occur?
No. The software used mimics the behavior of real ransomware but intentionally encrypts and destroys nothing. Where encryption is part of the scenario, it only targets specially placed demo files.
Will ongoing operations be disrupted?
No. We operate on a dedicated internal system within clearly defined boundaries. Production operations continue normally.
Does our SOC need to be informed in advance?
No, and that is typically the default. In the realistic variant, the SOC responds without prior notice, providing the most candid assessment. If maximizing the learning effect is the priority, the guided variant is chosen.
What is the difference compared to a penetration test?
A penetration test broadly looks for vulnerabilities. In ransomware emulation, how an attacker initially gained entry is not relevant. We assume a successful breach and evaluate whether the SOC detects the ongoing attack and responds properly.
Do we need a specific maturity level?
Yes, essentially. The assessment focuses on detection and response, so an active SOC and SIEM or comparable detection capabilities should be present. Organizations just starting out are better served with a penetration test or security consulting.
What is specifically simulated?
A real ransomware strain as agreed upon, such as Black Basta or LockBit, following documented threat actor tactics.
What happens after the evaluation?
Upon request, we assist with implementing recommendations, such as fine-tuning detection rules or adjusting playbooks. Additionally, we recommend a retest after approximately three months to verify that the improvements are effective.
Ready for the Stress Test?
Find out if your SOC withstands a real attack before an actual attacker tests it for you. The initial consultation is completely non-binding.

