Most companies buy endpoint protection and assume it works. This project tests that assumption.
You run a client on a machine, it inventories exactly what protection is installed and how it is
configured, then it performs a series of controlled, deliberately suspicious actions —
mimicking known malware, signatures and attacker behaviour — and records what the machine
detected, blocked, or quietly let through.
Everything is a test. Nothing is real malware and nothing persists. The point is
measurement, not damage.
The second half of the test is human: while the client runs, you watch your own SOC. Did they see
it? Did they raise an alert? Did the right process trigger — major incident management,
escalation, contact paths? The client cannot measure that for you, but it gives you a precise
timeline to hold your response against.