Best Breach and Attack Simulation (BAS) Software - Page 3

How Many Breach and Attack Simulation (BAS) Software Products Does G2 Track?

Total Products under this Category: 59

Category Stats (Sep 2026)

  • Average Rating: 4.56/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Right-Hand Cybersecurity (+0.27%) - Among all products in this category, Right-Hand Cybersecurity recorded the largest rating increase compared to last month

Last updated: September 06, 2026

How Does G2 Rank Breach and Attack Simulation (BAS) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 1,300+ Authentic Reviews
  • 59+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Breach and Attack Simulation (BAS) Software

G2 Grid® for Breach and Attack Simulation (BAS) Software plotting products by satisfaction and market presence

Highlighted products: Picus Security, Cymulate, Adaptive Security, Pentera, Sophos PhishThreat, HTB CTF & Threat Range, vPenTest, and Right-Hand Cybersecurity.

Underlying data: [Grid® JSON](https://www.g2.com/categories/breach-and-attack-simulation-bas/grids.json?focus%5B%5D=picus-security&focus%5B%5D=cymulate&focus%5B%5D=adaptive-security&focus%5B%5D=pentera&focus%5B%5D=sophos-phishthreat&focus%5B%5D=htb-ctf-threat-range&focus%5B%5D=vpentest&focus%5B%5D=right-hand-cybersecurity)

AttackIQ Enterprise

AttackIQ Enterprise is a comprehensive breach and attack simulation platform designed to proactively identify and remediate security gaps within an organization's defenses. By continuously validating security controls against real-world adversary behaviors, it ensures that enterprises can detect vulnerabilities before they are exploited, thereby enhancing overall security posture. The platform offers deep, continuous security control validation, providing actionable insights and detailed reports that facilitate collaboration across security, risk, and audit teams. Key Features and Functionality: - Continuous Security Validation: Operates 24/7 to identify and close security gaps before adversaries can exploit them. - Adversary Emulations and Threat Intelligence: Utilizes cutting-edge adversary emulations and threat intelligence from AttackIQ’s Adversary Research Team to test security programs. - Data-Driven Analysis: Provides data-driven analysis to improve team and technology operations across various security controls, including endpoint detection and response, next-generation firewalls, micro-segmentation, and cloud security. - Resource Optimization: Proven to save teams time and financial resources by enhancing security analyst and operations team performance, identifying redundancies in security controls, and decreasing the impact of breaches. - Enterprise Intelligence and Reporting: Offers a portal for security teams to interact with the co-managed service, deploy emulations, review detailed assessments, and access tools like JupyterHub for in-depth analysis. Primary Value and Problem Solved: AttackIQ Enterprise addresses the critical need for organizations to proactively measure and enhance the effectiveness of their cybersecurity controls. By continuously validating security measures against real-world threats, it enables enterprises to identify and remediate vulnerabilities before they can be exploited by adversaries. This proactive approach not only strengthens the organization's security posture but also optimizes resource allocation, reduces potential financial losses from breaches, and ensures compliance with industry standards. Ultimately, AttackIQ Enterprise empowers organizations to stay ahead of evolving cyber threats through continuous readiness testing and expert guidance.

Who Is the Company Behind AttackIQ Enterprise?

  • Seller: AttackIQ
  • Year Founded: 2013
  • HQ Location: Los Altos, US
  • Twitter: @AttackIQ
    7,101 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    168 employees on LinkedIn®

Axiom Breach

Axiom Breach is an advanced attack simulation platform designed to help organisations understand whether real-world attacks would succeed against their people and security controls. The platform enables security teams to create and run realistic attack scenarios including phishing, credential capture, MFA and session-based attacks, payload delivery, ClickFix, and other social engineering techniques. Simulations can be tracked at both campaign and individual target level, providing visibility into user interactions, technical control effectiveness, captured attack paths, and areas requiring remediation. Axiom Breach combines advanced adversary simulation with centralised campaign management, reporting, findings, remediation tracking, and security awareness capabilities through Audeclaris, helping organisations move beyond basic phishing metrics and assess their actual exposure to attack.

Who Is the Company Behind Axiom Breach?

BlackNoise

Validate the effectiveness of your cyber defenses with BlackNoise, the European leader in multi-environment Breach and Attack Simulation and Security Validation (cloud, networks, endpoints). Measure your detection times and response capabilities to attacks. Continuously manage your cyber scoring and share an objective view of the field effectiveness of your defense strategy. All in one, easy-to-use, SaaS or On-Premise platform.

Who Is the Company Behind BlackNoise?

  • Seller: Erium
  • Year Founded: 2012
  • HQ Location: Paris, FR
  • LinkedIn® Page: www.linkedin.com
    38 employees on LinkedIn®

BlackNoise

BlackNoise is the first European cyber defense validation platform, available SaaS and On-Premise. It helps users across all industries to continuously validate and enhance cyber defense capabilities against advanced threats, including APTs, ransomware, and state-sponsored attacks. By delivering real-world performance metrics, it enables precise tracking and improvement of Mean Time to Detect and Respond (MTTD/R), offering visibility into critical KPIs to support effective cyber risk management. Partners and customers benefit from the BlackNoise platform SaaS or On-Premise in order to solve three major use cases : Detection and Reaction improvement ; Cyber compliance automation ; and Testing and Training of their SOC.

Who Is the Company Behind BlackNoise?

Breach+

Cytomate's Breach+ is a Breach and Attack Simulation (BAS) solution designed to rigorously assess and strengthen an organization's security posture. By emulating real-world attack scenarios using a comprehensive threat library, it identifies and addresses potential vulnerabilities and attack paths before they can be exploited by malicious actors.

Who Is the Company Behind Breach+?

Cracken

Cracken is the world’s first Uncensored Vibe Hacking platform for safe, AI-driven, adversarial-grade, proactive cybersecurity. Built by cyber warfare-experienced operators and AI researchers, deployed by the world’s most critical global enterprises.

Who Is the Company Behind Cracken?

  • Seller: Cracken
  • Year Founded: 2023
  • HQ Location: Palo Alto, US
  • LinkedIn® Page: www.linkedin.com
    23 employees on LinkedIn®

Cyttack.ai

Cyttack.ai is a cybersecurity SaaS platform that specializes in realistic DDoS attack simulations, allowing organizations to test and enhance their digital defenses without real-world disruption. The platform offers customizable simulation packages tailored to various testing needs, including volumetric, protocol-based, and application-layer attacks. Intended clients include businesses seeking to validate their security measures, improve incident response, and ensure compliance with regulatory requirements. With an intuitive interface and multi-channel support, Cyttack.ai simplifies the process of conducting advanced DDoS simulations for security teams.

Who Is the Company Behind Cyttack.ai?

Dreadnode

Dreadnode is a pioneering company specializing in offensive machine learning, dedicated to advancing the field of offensive security by developing methodologies, tools, and research that enable more effective evaluation, testing, and deployment of AI models.

Who Is the Company Behind Dreadnode?

Elasticito

Help companies to identify and manage cyber threats that affect their business.

Who Is the Company Behind Elasticito?

  • Seller: Elasticito
  • Year Founded: 2017
  • HQ Location: London, GB
  • Twitter: @elasticito
    42 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    10 employees on LinkedIn®

Exploit Pack

Exploit Pack is a multiplatform exploitation framework including zero-days from own lab, a growing collection of 39.000+ exploits and post-exploitation modules. It has been designed by an experienced team of software developers and exploit writers to automate processes so that security professionals can focus on what's really important: Uncover threats and reduce the attack surface. Exploit Pack replicates real attack scenarios and discovers potential threats in your secure environment before hackers do.

Who Is the Company Behind Exploit Pack?

FortiTester

FortiTester is an enterprise-grade solution designed for performance testing and validating network security infrastructures. It offers a comprehensive range of application test cases to evaluate equipment and right-size infrastructure, ensuring optimal network performance and security. All test functionalities are included in a single, device-based license, making it a cost-effective choice for organizations. Key Features and Functionality: - Continuous Security Validation: Regularly assesses security controls, especially after system updates, patches, or network changes. - Vulnerability Detection: Identifies weaknesses in networks, applications, and endpoints to proactively discover vulnerabilities. - Security Posture Improvement: Provides simulation results to prioritize and implement security enhancements, improving overall efficiency. - Security Investment Justification: Offers tangible evidence of security gaps, demonstrating the need for additional resources or tools. - Network Performance Testing: Conducts stress and load testing, RFC-based testing of latency and throughput, and generates HTTP/HTTPS/HTTP2 traffic. - MITRE ATT&CK Simulation: Emulates campaigns on Windows, macOS, and Linux devices to validate endpoint security solutions. Primary Value and Problem Solved: FortiTester enables organizations to proactively identify and address vulnerabilities, misconfigurations, and performance bottlenecks within their network security infrastructure. By simulating real-world cyberattacks and network traffic, it ensures that security measures are effective and that the network can handle expected loads. This proactive approach helps prevent potential breaches and ensures optimal network performance, providing organizations with confidence in their security posture.

Who Is the Company Behind FortiTester?

  • Seller: Fortinet
  • Year Founded: 2000
  • HQ Location: Sunnyvale, CA
  • Twitter: @Fortinet
    151,422 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    16,564 employees on LinkedIn®
  • Ownership: NASDAQ: FTNT

HTB Crisis Control

Hack The Box is the leading cyber readiness platform for the human-AI cyber workforce, helping organizations develop and measure the capabilities of the people and AI agents responsible for modern defense. Hack The Box delivers live-fire simulations that build and validate offensive, defensive and AI-enabled cyber capabilities. Trusted by the Fortune 500, government agencies, managed security service providers (MSSPs) and Frontier Labs, Hack The Box supports more than 800 enterprise customers and a global community of over 4 million cybersecurity professionals. For more information, visit hackthebox.com

Who Is the Company Behind HTB Crisis Control?

  • Seller: Hack The Box
  • Year Founded: 2017
  • HQ Location: Folkestone, GB
  • Twitter: @hackthebox_eu
    246,095 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,313 employees on LinkedIn®

Mandiant Security Validation

Security Validation Continuously measure and validate your security effectiveness against today’s adversaries

Who Is the Company Behind Mandiant Security Validation?

  • Seller: Google
  • Year Founded: 1998
  • HQ Location: Mountain View, CA
  • Twitter: @google
    31,899,995 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    301,144 employees on LinkedIn®
  • Ownership: NASDAQ:GOOG

ModelRed

ModelRed is an automated security testing platform for AI models. It runs adversarial tests against LLMs to identify vulnerabilities including prompt injection, jailbreaks, data leakage, hallucinations, and compliance violations. The platform includes 200+ pre-built probe packs covering domain-specific scenarios (medical, financial, legal) and a marketplace where security researchers can contribute specialized test methodologies. Users receive security scores, detailed vulnerability reports, and remediation guidance. ModelRed integrates with CI/CD pipelines for continuous testing and provides API access for programmatic security assessments.

Who Is the Company Behind ModelRed?

  • Seller: ModelRed
  • Year Founded: 2025
  • HQ Location: Seattle, US
  • LinkedIn® Page: www.linkedin.com
    3 employees on LinkedIn®
Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 3, 2024