Containing the Simulated Adversary: Safety for Autonomous Attack Simulation
Breach-and-attack simulation is going autonomous: agents that pick and detonate real ATT&CK techniques with no human in the loop. The frameworks already run the attack. The unsolved problem is containing the attacker, and the discipline that contains it is what makes its measurements honest.