๐ŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
Attack Path Simulator ยท paid plan

Watch a kill chain move through your industry

Pick an industry and a threat actor and the simulator generates a realistic, multi-tier enterprise network, then animates that actor's ATT&CK-mapped kill chain hop by hop โ€” from the entry point to the crown jewel and back out on exfil. It's a generated teaching model, not a scan of a real environment.

What it gives you

Generated enterprise network

A multi-tier map โ€” internet edge, DMZ, partner links, identity, endpoints, internal network, intranet, Kubernetes, cloud, OT/ICS and the data tier โ€” sized to the industry you pick.

12 threat-actor archetypes

Ransomware crews, nation-state APTs, insiders, access brokers, supply-chain and cloud-native attackers, OT/ICS specialists and more, each with a sophistication level, motive and preferred entry points.

ATT&CK-mapped kill chain

Every step in an actor's playbook is tagged with a MITRE ATT&CK technique ID and phase, from initial access through credential access, lateral movement, collection and impact.

Hop-by-hop animated playback

Play, pause, step or scrub through the timeline while nodes light up and edges animate the path the actor takes across the network.

30+ named scenarios

Curated industry ร— actor pairings โ€” like a wire-day ransomware hit on a bank or a nation-state pre-positioning on the grid โ€” each with a one-line hook.

Customisable topology

Toggle zones on or off to reshape which layers of the enterprise are in play and see the generated map and kill chain change accordingly.

How it works

  1. 1Pick an industry โ€” its zones and crown jewels seed the generated enterprise map.
  2. 2Pick a threat actor. Actors realistically likely to target that industry are shown as primary; others are marked "also possible".
  3. 3Optionally toggle zones on or off to customise which layers of the enterprise are modelled.
  4. 4Press play and watch the kill chain animate hop by hop, or step and scrub through the timeline manually โ€” each step names its ATT&CK technique and phase.

Honest about what this is

  • A teaching model that shows how a kill chain plausibly moves through a realistic enterprise topology.
  • Useful for building intuition about attack paths, briefing non-technical stakeholders, or discussing where a control would break a chain.
  • โœ• Not a scan, import, or model of your actual network โ€” nothing connects to your systems, and the ATT&CK IDs are indicative, not a live threat-intel feed.

FAQ

What does the Attack Path Simulator show?

Pick an industry and a threat-actor archetype and it generates a multi-tier enterprise network โ€” internet edge through DMZ, identity, endpoints, internal network, cloud/Kubernetes or OT, down to the data tier โ€” then animates that actor's kill chain hop by hop across it, from initial access to impact.

Is this built from my company's actual network?

No. The network is generated from an industry's reference architecture, not a scan or import of your environment. Nothing connects to your systems.

How many industries and threat actors are covered?

12 industries (fintech, healthcare, SaaS, retail, manufacturing/OT, energy, public sector, telecom, defense, education, media, logistics) and 12 threat-actor archetypes โ€” ransomware crews, nation-state APTs, insiders, access brokers, supply-chain attackers, OT/ICS specialists, cloud-native attackers and more โ€” across 30+ named scenarios with a one-line real-world hook each.

Are the ATT&CK IDs accurate threat intelligence?

They're indicative, not a live feed. Each step in an actor's chain is tagged with a MITRE ATT&CK (or ATT&CK for ICS) technique ID chosen to illustrate that phase of a plausible attack โ€” useful for teaching how a kill chain moves through an environment, not as a CTI source.

Is it free?

The interactive simulator is part of a paid plan. Any PlayCISO plan unlocks it, along with the other security-architect studios.

Attack Path Simulator ยท PlayCISO