This section documents adversary-emulation scenarios as repeatable validation cases.

Each experiment is intended to answer four practical questions:

  1. What behavior is being tested?
  2. What telemetry should make it visible?
  3. Which detections should respond?
  4. What changed after the validation run?