Best Breach and Attack Simulation (BAS) Software - Page 4

How Many Breach and Attack Simulation (BAS) Software Products Does G2 Track?

Total Products under this Category: 59

Category Stats (Sep 2026)

  • Average Rating: 4.56/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Right-Hand Cybersecurity (+0.27%) - Among all products in this category, Right-Hand Cybersecurity recorded the largest rating increase compared to last month

Last updated: September 06, 2026

How Does G2 Rank Breach and Attack Simulation (BAS) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 1,300+ Authentic Reviews
  • 59+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Breach and Attack Simulation (BAS) Software

G2 Grid® for Breach and Attack Simulation (BAS) Software plotting products by satisfaction and market presence

Highlighted products: Picus Security, Cymulate, Adaptive Security, Pentera, Sophos PhishThreat, HTB CTF & Threat Range, vPenTest, and Right-Hand Cybersecurity.

Underlying data: [Grid® JSON](https://www.g2.com/categories/breach-and-attack-simulation-bas/grids.json?focus%5B%5D=picus-security&focus%5B%5D=cymulate&focus%5B%5D=adaptive-security&focus%5B%5D=pentera&focus%5B%5D=sophos-phishthreat&focus%5B%5D=htb-ctf-threat-range&focus%5B%5D=vpentest&focus%5B%5D=right-hand-cybersecurity)

Nemesis

Nemesis by Persistent Security Industries is a Breach & Attack Simulation (BAS) platform that lets organizations emulate real-world cyberattacks in a controlled environment. Stay ahead of cyber threats with our continuous, automated security testing and proactive breach simulation. Nemesis Breach and Attack Simulation exposes the issues that really matter. • Ransomware Simulation Library. Run safe emulations of tactics used by top ransomware groups. • End-to-End Attack Chains. Validate each layer of your defense from initial access to data encryption attempts. • Cloud Security Testing. Validate configurations and controls in dynamic cloud environments • Detection & Response Insights. Understand where your EDR/SIEM picks up the threat (and where it does not). SOC Validation. Objectively measure the detection and response capabilities of your SOC (vendor).

Who Is the Company Behind Nemesis?

NeSSi2

NeSSi² is an open source project developed at the DAI-Labor and sponsored by Deutsche Telekom Laboratories. NeSSi (Network Security Simulator) is a novel network simulation tool which incorporates a variety of features relevant to network security distinguishing it from general-purpose network simulators. Its capabilities such as profile-based automated attack generation, traffic analysis and support for the detection algorithm plugins allow it to be used for security research and evaluation purposes.

Who Is the Company Behind NeSSi2?

  • Seller: NeSSi2
  • Year Founded: 2006
  • HQ Location: Brussels, BE
  • LinkedIn® Page: www.linkedin.com
    4 employees on LinkedIn®

OFFENSAI

OFFENSAI delivers a new paradigm in cloud security with its autonomous cloud security testing solution. Utilizing proprietary generative adversarial techniques, unpublished attack vectors, and internal offensive security research, OFFENSAI conducts real adversary behavior, continuously probing environments like an intelligent attacker evading detection. Unlike tools that merely flag misconfigurations, OFFENSAI specializes in Adversarial Exposure Validation—identifying real, exploitable paths and delivering detailed kill-chain steps with precise, one-click remediation guidance. The solution integrates natively with cloud environments, running safe, production-friendly simulations and producing exportable, compliance-ready reports. The result is actionable insight and continuous validation that prioritizes exploitable paths over theoretical alerts, enabling security teams to prove and strengthen defenses.

Who Is the Company Behind OFFENSAI?

  • Seller: OFFENSAI
  • Year Founded: 2024
  • HQ Location: Los Angeles, US
  • LinkedIn® Page: www.linkedin.com
    11 employees on LinkedIn®

ReliaQuest GreyMatter

ReliaQuest’s agentic AI security operations platform, GreyMatter, allows security teams to detect threats at the source, contain them in under 5 minutes, and eliminate Tier 1 and Tier 2 work for faster investigation and response. GreyMatter orchestrates 6 agentic AI personas with 200+ agent skills and 400+ AI tools to exponentially scale security operations and help organizations predict what's next.

Average Rating: 4.6/5.0

Total Reviews: 19

Who Is the Company Behind ReliaQuest GreyMatter?

  • Seller: ReliaQuest
  • Company Website:
  • Year Founded: 2007
  • HQ Location: Tampa, Florida, United States
  • Twitter: @ReliaQuest
    2,577 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,106 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Consumer Services
  • Company Size: 37% Medium, 26% Small

What Do G2 Reviewers Say About ReliaQuest GreyMatter?

AI-generated summary from verified user reviews

Pros
  • Users value the exceptional visibility and integration capabilities of ReliaQuest GreyMatter, enhancing security operations across environments.
  • Users value the centralized management of ReliaQuest GreyMatter, enhancing visibility and streamlining security operations effectively.
  • Users highlight the exceptional customer support of ReliaQuest GreyMatter, enhancing satisfaction and streamlining security operations.
  • Users praise the ease of use of ReliaQuest GreyMatter, highlighting its straightforward setup and seamless integrations.
  • Users highlight the seamless integration with existing tools, streamlining security operations and enhancing overall efficiency.
Cons
  • Users note UX improvement needs in ReliaQuest GreyMatter, citing alert delays, slow report loading, and clunky Android app experience.
  • Users find the complexity of configurations in ReliaQuest GreyMatter can hinder usability and require significant fine-tuning.
  • Users experience an inefficient alert system with delays, duplicates, and slow report loading, affecting overall usability.
  • Users find the learning curve steep for advanced workflows, though documentation and support help eventually.
  • Users find login issues with the ReliaQuest GreyMatter app, particularly on Android, making the sign-in process frustrating.

What Are Recent G2 Reviews of ReliaQuest GreyMatter?

Seceon aiBAS360

Seceon aiBAS360 is a standalone AI-powered Breach and Attack Simulation (BAS) platform that continuously validates security controls against real-world attack techniques before adversaries can exploit them. Unlike periodic red team exercises that provide a point-in-time assessment, aiBAS360 continuously automates adversary simulations across the live security environment, providing an evidence-backed view of security effectiveness. Mapped to the MITRE ATT&CK framework (v14+), aiBAS360 evaluates security controls across the full attack lifecycle, from initial access and execution to persistence, privilege escalation, lateral movement, command and control, and exfiltration. It validates controls across endpoints, networks, cloud environments, email, identity, and web applications to identify gaps in prevention and detection capabilities. Each simulation automatically updates the organization's MITRE ATT&CK coverage heatmap, highlights detection and control gaps, and provides prioritized remediation guidance. After fixes are implemented, aiBAS360 can re-run relevant attack simulations to verify whether the controls are working as expected and provide measurable evidence of improved security effectiveness. Purpose-built for security teams looking to move from assumed security coverage to continuously validated protection, Seceon aiBAS360 enables continuous purple teaming and automated security validation at scale while minimizing disruption to production environments.

Who Is the Company Behind Seceon aiBAS360?

  • Seller: Seceon
  • Year Founded: 2015
  • HQ Location: Westford, Massachusetts, United States
  • Twitter: @Seceon_Inc
    1,209 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    177 employees on LinkedIn®

Secure.com

Governed Defense, Powered by Offense. Security work is growing faster than security teams. More alerts. More tools. More evidence to collect. More remediation to coordinate. More burnout. Secure.com augments security teams with governed AI Teammates that attack your defenses, harden what they find, and prove the outcome, while your team stays in control. Unlike AI copilots that stop at recommendations or point solutions that create another queue, Secure.com operates above the security stack you already own. AI Teammates continuously: • Validate real attack paths • Prioritize exploitable risks • Execute governed remediation • Produce auditable evidence • Return hundreds of hours to security teams Every action runs within customer-defined permissions, approvals, and governance. Your team sets the rules. AI Teammates do the work.

Who Is the Company Behind Secure.com?

  • Seller: Secure.com
  • HQ Location: Wilmington, Delaware 19801, USA
  • Twitter: @Securedotcom
  • LinkedIn® Page: www.linkedin.com
    19 employees on LinkedIn®
  • Ownership: Secure.com Teams

simler

simler is the AI-native platform for cyber crisis simulations; tabletop exercises, reinvented. Consultant-led exercises cost tens of thousands and happen once a year, so the human side of incident response goes untested until a real attack. simler makes it continuous: simulations generated in minutes, grounded in your own policies, systems, and this week's real threats, played in a digital war room where AI agents fill every role you can't staff. Every session ends in an audit-ready debrief, findings become verified fixes, and the next exercise proves they hold — readiness that compounds instead of an annual snapshot. We're building the simulation layer for the AI threat era. Try it at simler.ai/tour.

Who Is the Company Behind simler?

  • Seller: simler
  • Year Founded: 2026
  • HQ Location: Amsterdam, NL
  • LinkedIn® Page: www.linkedin.com
    2 employees on LinkedIn®

SimSpace

Allied governments, militaries, commercial and enterprises worldwide trust SimSpace as the AI Proving Grounds where human operators and AI agents train and test together in a realistic replica of their production environments to outperform and outsmart any adversary in any terrain.

Who Is the Company Behind SimSpace?

  • Seller: SimSpace
  • Company Website:
  • Year Founded: 2015
  • HQ Location: New Boston, Massachusetts, United States
  • LinkedIn® Page: www.linkedin.com
    193 employees on LinkedIn®

SOCSimulator

SOCSimulator is an advanced AI-powered platform designed for realistic cybersecurity training and threat simulation. Enhance your Security Operations Center (SOC) efficiency with immersive attack scenarios, real-time threat detection, and comprehensive incident response testing in a secure, virtualized environment. FEATURES AI Threat Simulation: Runs realistic cyberattacks so your team can practice defending against them. Training Environments: Provides a safe, virtual space to learn without putting your actual network at risk. Incident Response Testing: Helps you walk through exactly how to handle a breach from start to finish. Real Time Detection: Tests how fast your team can spot and react to threats as they happen. Performance Analytics: Tracks your progress so you can see exactly where your team needs to improve. Security Efficiency: Gives you the tools to sharpen your skills and make your daily operations much smoother.

Who Is the Company Behind SOCSimulator?

Threatcare

Threatcare is a cybersecurity platform that allows organizations to simulate intrusions on their network to help improve their people's performance, their processes, and their product utilization.

Who Is the Company Behind Threatcare?

  • Seller: Threatcare
  • HQ Location: N/A
  • Twitter: @threatcare
    3,944 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1 employees on LinkedIn®

Threat Simulator

Threat Simulator is a SaaS-based breach and attack simulation (BAS) platform built on 20+ years of leadership in network security testing. Threat Simulator enables you to safely simulate attacks on your production network, identify gaps in coverage, and remediate potential vulnerabilities before attackers can exploit them. * Safely emulate attacks on your production network. * Find and fix misconfigurations and gaps. * Measure security posture on a continuous basis. * Prove you're safer than you were yesterday. * Prevent past incidents and attacks from happening again. * Save money by maximizing existing security controls and processes before purchasing new tools.

Who Is the Company Behind Threat Simulator?

  • Seller: Keysight Technologies
  • Year Founded: 2014
  • HQ Location: Santa Rosa, California, United States
  • Twitter: @Keysight
    13,585 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    13,900 employees on LinkedIn®
  • Ownership: NYSE: KEYS

TrojAI Detect

TrojAI Detect is an AI security solution designed to identify and mitigate risks in AI models before deployment. By conducting automated penetration testing, it assesses vulnerabilities and deficiencies, ensuring models behave as intended and are safeguarded against potential threats.

Who Is the Company Behind TrojAI Detect?

  • Seller: TrojAI
  • Year Founded: 2019
  • HQ Location: Saint John, New Brunswick, Canada
  • LinkedIn® Page: www.linkedin.com
    26 employees on LinkedIn®

WhiteHaX

WhiteHaX currently is the only solution that provides an in-depth, real-life simulation verification for this purpose. WhiteHaX helps the businesses identify security holes in their detection/prevention infrastructure and then help them re-verify as issues are fixed when right security solutions at right place in the infrastructure.

Who Is the Company Behind WhiteHaX?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 3, 2024