DETECTION CAPABILITY TEST

KNOW WHAT YOUR DEFENCES CATCH, AND WHAT THEY MISS

A hands-on detection exercise that measures how well your team detects, investigates, escalates, and responds to realistic attacks, scenario by scenario.
Blind Spots Eye Chart v3-selection3
DETECTION AND RESPONSE

Know Your Blind Spots

Your security defences can only act on what it sees, which makes detection the foundation of every other security capability. And many organisations fall at this first hurdle.

Even if you see the attack how you respond is equally critical with attackers moving from break-in to spread across the network in an average of 29 minutes, and as little as 27 seconds (CrowdStrike 2026 Global Threat Report). Response effectiveness decides whether an alert becomes a contained event or a full breach.

The Detection Capability Test is a simulation-based, purple-team style exercise designed to show, with evidence, how effectively your organisation can detect, alert, and respond to realistic cyberattacks.

OBJECTIVES

A Clear, Evidence-Based View of Your Detection Capability

The test is run in close collaboration between our Offensive Security team and your Blue Team/SOC, using representative scenarios spanning the main stages of an attack, mapped to MITRE ATT&CK techniques where relevant. The focus is on detection and response, not stealth or maximum compromise.

Through a series of realistic scenarios, the exercise assesses how well your existing controls and SOC processes:

  • generate meaningful alerts and useful telemetry
  • support effective triage and investigation
  • enable timely escalation and response

You come away with a clear understanding of your strengths and gaps in monitoring, plus practical recommendations to improve detection coverage, alert quality, and SOC workflows.

WHAT WE TEST

Scenarios Across the Attack Lifecycle

A typical one-day workshop covers around 40 attack scenarios across the relevant ATT&CK tactics, including:

person in a frame with alert sign icon
Initial Access
magnifying glass with eye icon
Discovery and Reconnaissance
laptop with checkmark icon
Execution
Account tree icon
Lateral Movement
clock icon
Persistence
Finance_v3
Impact

Attacks are launched from a customer-provided workstation or foothold inside your environment, so both endpoint and network-level detection are exercised.

AI methodology
METHODOLOGY

A Repeatable, Collaborative Loop

Each scenario follows the same transparent pattern, run side by side with your team:

  1. Scenario launch - an attack is executed from an agreed internal workstation, or another approved starting point inside your environment.

  2. Notification - your Blue Team is told a scenario window has begun with enough context (approximate time, host, and vector) to investigate so the exercise can focus on validating visibility, triage, and response rather than covert compromise.

  3. Investigation - your team checks whether the scenario raised an alert in your monitoring tools, and whether it is visible in logs and telemetry, even if no alert was raised.

  4. Review & feedback - together we review what was detected, what was missed, what evidence was available, and what improvements can be made to address the shortfalls.

  5. Next scenario - the loop repeats until the planned set is complete.

The workshop runs on-site or remotely. Remote delivery simply requires access to the workstation and monitoring tools to be arranged and tested in advance.

Detection Capability Test
DELIVERABLES

Outcomes Designed for Action

The engagement answers the central question, can your team see and stop a real attack, and gives you a practical route to closing the gaps, delivered in three parts.

Technical Report: detailed findings for your SOC and security team. A description of each scenario executed and whether it was prevented, detected with sufficient context, partially detected, or missed, together with the alerts, events, or log evidence observed in each case. Includes concrete, practical recommendations for improving detection rules, logging and telemetry, and SOC processes.

Business Impact Report: an executive report for leadership that sets out your overall detection capability, where your biggest blind spots are, and what they would mean for the business if a real attacker exploited them. It gives clear, prioritised conclusions, an overview of the recommended improvements, and any executive decisions or investment needed to strengthen detection and response.

Assessment Debrief: a live walkthrough of the findings with our consultants. We talk your team through what was detected, what was missed, and why, answer questions, and set out the specific steps that will strengthen the areas we identified. You leave with a shared understanding of your detection gaps and a prioritised, practical action plan.

WHY CSIS SECURITY GROUP

Detection is Our Day Job

A detection test is only as good as the people building the scenarios and reading the results. We manage the detection capabilities for our customers and respond to live incidents daily, so we know what real attacks look like, and we know how to spot them.

The test is built on more than 20 years of managed detection and response, incident response, and threat intelligence. The attacks we simulate are drawn from techniques used against organisations today and mapped to MITRE ATT&CK, not a generic script. The gaps we surface are the ones that matter against a real adversary.

team
Informed by 20+ years of MDR, incidence response, and threat intelligence
exclamation mark message icon
Scenarios custom built from real life attacks and the latest threat insights
Account tree icon
Scenarios mapped to MITRE ATT&CK where possible, the industry-standard framework for attacker behaviour
certified supplier
ISO 27001 certified
REST ASSURED

Ready to Test Your Detection and Response?

Request a call to learn more about how our Detection Capability Test measures how well your tooling and SOC recognise and respond to real attacks.

Frequently Asked Questions

01

What is a detection capability test?

A detection capability test is a purple team exercise that measures what a security operations centre detects and what it misses. An attacker executes realistic techniques inside the environment, the defending team checks whether each one raised an alert or left usable evidence, and both sides review the result together. CSIS Security Group maps scenarios to MITRE ATT&CK.

 

02

How is this different from a red team exercise?

In a red team exercise the defending team is not told, because the point is to see whether an attack goes unnoticed. A detection capability test is the opposite: your team knows a scenario has begun and is given the approximate time, host and vector. That removes stealth from the equation so the exercise can measure visibility, triage and response rather than testing whether one attacker can stay hidden.

 

03

How many scenarios does a test cover?

A typical one-day workshop covers around 40 scenarios across the relevant MITRE ATT&CK tactics, spanning initial access, discovery, execution, lateral movement, persistence and impact.

 

04

Does it have to be run on site?

No. The workshop runs on site or remotely. Remote delivery requires access to the workstation and your monitoring tools to be arranged and tested in advance.

 

05

What does it involve for our team?

Your blue team or SOC analysts take part throughout the workshop, since the investigation step is theirs. Beyond the day itself we need a few hours for preparation and someone to arrange access to the monitoring tools. The debrief is a virtual walkthrough of the findings and recommendations that normally lasts 1 hour.

 

06

What if a scenario is missed?

The report records whether each scenario was prevented, detected with sufficient context, partially detected, or missed. Where something was missed, the recommendations set out what would need to change in detection rules, logging and telemetry, or SOC processes to catch it next time.