---
title: Mapping Adversary Emulation Plans
description: These adversary emulation plans outline the actual actions of an adversarial attack, down to the commands executed.
---

[Skip to content](https://blog.reconinfosec.com/adversary-emulation-mapping#main-content)

[![recon\_infosec.png](https://blog.reconinfosec.com/hs-fs/hubfs/recon-logo-full-on-white.png?width=7680&height=2304&name=recon-logo-full-on-white.png "recon_infosec.png")](http://reconinfosec.com)

- [Website Home](https://www.reconinfosec.com/)

- [Website Home](https://www.reconinfosec.com/)

# Mapping Adversary Emulation Plans

[Brian Greunke](https://blog.reconinfosec.com/author/brian-greunke)

The [Center for Threat-Informed Defense](https://mitre-engenuity.org/center-for-threat-informed-defense/) at MITRE recently [released](https://medium.com/mitre-engenuity/introducing-the-all-new-adversary-emulation-plan-library-234b1d543f6b) their [Adversary Emulation Plans Library](https://github.com/center-for-threat-informed-defense/adversary_emulation_library) on Github.

This is exciting news for anyone who conducts adversary emulation (something we do extensively as part of our [Network Defense Range engagements](https://reconinfosec.com/training.html)) or studies adversary actions (which is fairly applicable to most everyone in Information Security).

These adversary emulation plans outline the actual **actions** of an adversarial attack, down to the commands executed. And better yet, presribes a thoughtful framework and schema for describing the procedures executed. Each procedure is mapped to applicable MITRE ATT&CK technique(s), which further provides the ability to analyze defenseive posture against a specific adversary.

Here is a short snippet of the *fin6* [emulation plan](https://github.com/center-for-threat-informed-defense/adversary_emulation_library/blob/master/fin6/Emulation_Plan/FIN6.yaml):

```
# Phase 1: Discovery

- id: e44a39ce-0651-3ddd-8f05-f83aa2ffd657
  name: Enumerate AD person objects
  description: Find all person objects and output the results to a text file.
  tactic: discovery
  technique:
    attack_id: T1087.002
    name: "Account Discovery: Domain Account"
  cti_source: https://www.fireeye.com/blog/threat-research/2019/04/pick-six-intercepting-a-fin6-intrusion.html
  procedure_group: procedure_discovery
  procedure_step: "2.1"
  platforms:
    windows:
      cmd:
        command: |
          'adfind.exe -f (objectcategory=person) > ad_users.txt'
        payload: adfind.exe
...
```

This is a goldmine of information about adversary behaviors and gives us a way to automate this information into our SOC processes. Additionally, having common designs and frameworks to communicate adversary behavior, can event clarify discussions about defensive capabilities.

## Use Case

In a previous post, [we oulined](https://blog.reconinfosec.com/automating-coverage-analysis-with-att-ck-navigator/) how we use MITRE ATT&CK Navigator to visualize our defenseive posture. Specifically...

> we can quickly respond to a new adversarial TTP and focus on improving our coverage

ATT&CK Navigator has an awesome feature which allows us to dynamically build "calculated" layers from other, existing layers. So, if we can build a Navigator layer from the Adversary Emulation Plan, and compare it against our [real-time](https://blog.reconinfosec.com/automating-coverage-analysis-with-att-ck-navigator/#whyautomateit) defensive capability map, we can quickly, and visually, identify where our gaps may exist in identifying this particular adversary.

![calculated-layers-1](https://blog.reconinfosec.com/hs-fs/hubfs/Imported%20sitepage%20images/calculated-layers-1.png?width=711&name=calculated-layers-1.png)

At the time of writing, layer ***images*** exist for the emulation plans, but no actual layers exist. So, like any good haxors, we wrote something. Enter: [*adversary-emulation-map*](https://github.com/ReconInfoSec/adversary-emulation-map), a Python script which reads emulation plans and generates an ATT&CK Navigator layer based on the techniques recorded in the plan of your choosing.

Here is the output of the "*fin6*" plan:  
![fin6-map](https://blog.reconinfosec.com/hs-fs/hubfs/Imported%20sitepage%20images/fin6-map.png?width=5958&name=fin6-map.png)

Now, we can build a calculated layer against both our Data Sources map and our Identifiable Techniques map to quickly visualize the techniques we are best suited to utilize.

## Final Thoughts

If you check out this [post on the OpenSOC blog](https://blog.opensoc.io/validation-in-depth/) you will notice that we love yaml and automation. The [contributors](https://github.com/center-for-threat-informed-defense/adversary_emulation_library/graphs/contributors) to the Adversary Emulation Library were thoughtful enough to build out a [JSON schema](https://json-schema.org/) which we can use in an IDE of our choosing (in this case: VS Code) to assist in building additional emulation plans in the same, awesome format:

```
"yaml.schemas": {
  "./.plans/format_schema.json": "*/Emulation_Plan/*.yaml"
}
```

Check out the source code for the Adversary Emulation Mapping tool on Github: [https://github.com/ReconInfoSec/adversary-emulation-map](https://github.com/ReconInfoSec/adversary-emulation-map)

 

 

 

[Automation](https://blog.reconinfosec.com/tag/automation), [Threat Hunting](https://blog.reconinfosec.com/tag/threat-hunting), [NDR](https://blog.reconinfosec.com/tag/ndr), [Defense](https://blog.reconinfosec.com/tag/defense), [MITRE ATT&CK](https://blog.reconinfosec.com/tag/mitre-attck)

## Read On

### [Plan for When...](https://blog.reconinfosec.com/plan-for-when)

According to [Forbes](https://www.forbes.com/advisor/education/it-and-tech/cybersecurity-statistics/), there was a 72% increase in cyber breaches from 2021 to 2023. Based on the...

### [Automating Detection Coverage Analysis with ATT&CK Navigator](https://blog.reconinfosec.com/automating-coverage-analysis-with-att-ck-navigator)

Staying on-top of the latest adversarial methodologies means quickly adjusting to new TTPs and...

### [Endpoint Logging For The Win!](https://blog.reconinfosec.com/endpoint-logging-for-the-win)

Whether you're on the Defensive or Offensive side of security, it's important to understand how...

© 2026 All rights reserved. [RSS Feed](https://blog.reconinfosec.com/rss.xml)