From assumption to evidence

Validation & Frameworks

Test whether security controls work as intended, then use a shared framework to describe coverage, gaps, and improvement priorities.

2learning routes 2practical tools 1clear first step
01

Validate with evidence

Select each stage to see how a safe test becomes a measurable security improvement.

Stage 1 Define the question and boundary

Select one security control, a representative behaviour, the authorised systems, and the evidence that will demonstrate success or failure.

Ask: What exactly are we testing, and what result should the control produce?
02

Find your learning path

Choose your goal. The page will highlight the most useful place to begin.

Best match Learn the foundations

Understand validation, BAS, adversary emulation, scope, safety, and evidence before running a test.

03

Build your foundation

Learn what to test and how to describe it before choosing an automation platform.

04

Choose a tool by outcome

Choose CALDERA to execute a controlled test or ATT&CK Navigator to communicate a focused mapping.

Best starting point for controlled adversary emulation MITRE CALDERA

Plan and execute authorised ATT&CK-aligned behaviours, then compare the resulting telemetry and control response with your expected outcome.

Also consider ATT&CK Navigator when the immediate goal is mapping or communicating technique coverage.
Explore CALDERA
05

Check your validation readiness

Complete these checks before executing adversary behaviour, even in a lab.

!
Preparation requiredComplete all five safety checks before starting.