FAQs

We've compiled a list of common questions about our cloud security platform with clear and helpful answers to address your concerns.
Table of Contents
Understanding The Mitigant Platform
This is some text inside of a div block.
Getting Started - General
This is some text inside of a div block.
Cloud Attack Emulation (CAE) - Getting Started
This is some text inside of a div block.
Cloud Attack Emulation (CAE) - Safety Measures
This is some text inside of a div block.
Cloud Security Posture Management (CSPM)
This is some text inside of a div block.
Kubernetes Security Posture Management (KSPM)
This is some text inside of a div block.
Technical Capabilities - Platform Wide
This is some text inside of a div block.
Platform Capabilities - All Products
This is some text inside of a div block.
Use Cases & Benefits
This is some text inside of a div block.
Business & Pricing
This is some text inside of a div block.
Mitigant versus Breach & Attack Simulation
This is some text inside of a div block.
Mitigant versus CNAPPs
This is some text inside of a div block.
Security & Trust
This is some text inside of a div block.
Implementation & Operations
This is some text inside of a div block.
Advanced Topics
This is some text inside of a div block.
Bring Your Own Role (BYOR) - Deep Dive
This is some text inside of a div block.

Mitigant versus Breach & Attack Simulation

Mitigant is a cloud-native Adversarial Exposure Validation (AEV) platform. This section explains how AEV differs from traditional Breach and Attack Simulation (BAS), and where Mitigant fits for teams evaluating BAS tools or cloud alternatives.

Is Mitigant a breach and attack simulation (BAS) tool?

Mitigant is an Adversarial Exposure Validation (AEV) platform, the category Gartner coined to consolidate breach and attack simulation, penetration testing, and red teaming into continuous, evidence-based exploitation validation. It delivers what BAS promises but is built cloud-native and goes further: it executes real, safe attacks in your cloud rather than simulations in a sandbox.

What is the difference between Adversarial Exposure Validation (AEV) and traditional BAS?

BAS is one of the three older categories, alongside penetration testing and red teaming, that AEV consolidates. Traditional BAS grew out of endpoint and network testing, and cloud support was added later as a thin set of predefined checks. AEV as Mitigant implements it is cloud-native by design: attack emulation across cloud identity, the control plane, and the data plane, validating exploitability continuously.

How is Mitigant different from traditional BAS tools?

  • Run real, safe, reversible attacks in your cloud, with built-in guardrails and automatic cleanup. No residual impact, no false positives.
  • Cover the cloud control plane and data plane across AWS, Azure, and Google Cloud, rather than cloud checks bolted onto endpoint and network testing.
  • Deploy agentless, connecting directly to the cloud API, with no software agents or virtual appliances to install and maintain.
  • Build attacks as code in the Cloud Attack Language, a readable, version-controllable format you can chain, automate, and reproduce.

Does Mitigant run real attacks or simulated ones?

Mitigant runs real, safe, reversible attacks in your cloud, with guardrails and automatic cleanup that leave no residual impact and no false positives. Traditional BAS typically simulates against deployed agents or isolated sandboxes rather than your cloud environment, which makes its results vulnerable to false positives and short on realism.

How is Mitigant deployed, and how long does it take to get value?

Deployment is agentless and connects directly to the cloud API. That reduces management overhead and makes it straightforward to scale across multiple cloud accounts. Traditional BAS mostly relies on installing software agents on VMs or standing up virtual appliances, which makes deployment time-consuming, adds maintenance overhead, and makes scaling across cloud accounts challenging.

Does Mitigant work alongside the rest of our security stack?

Yes. Mitigant is built to integrate and exposes APIs for pushing reports into your other tools and automating workflows. Traditional BAS is more often sold as an all-in-one platform, designed to be your single tool rather than a component that slots into a best-of-breed stack.

Do organizations still need a separate BAS tool alongside Mitigant?

For cloud, Mitigant covers what BAS provides and extends it: real attack execution in your cloud, multi-cloud coverage, exploitability validation, and continuous operation. Teams typically consolidate cloud validation onto Mitigant. See the platform.

BAS vendors also claim CTEM. How is Mitigant's approach to CTEM different?

For many BAS tools, CTEM is typically limited to the validation step, without the native cloud discovery, prioritization, and compliance context the full cycle requires. Mitigant delivers the full CTEM cycle for the cloud: native CSPM for discovery, scoping, and prioritization; attack emulation to validate real exploitability and cut false positives; results aligned to compliance benchmarks; and findings pushed into other security and collaboration tools to facilitate mobilization.

Why choose a cloud-native platform over adapting a traditional BAS tool for the cloud?

Cloud attacks target identity, the control plane, and the data plane, layers a tool built for endpoints and networks reaches only at the surface. A cloud-native platform validates those depths directly, with 500+ cloud-native attacks across AWS, Azure, and Google Cloud plus AI red teaming, and evidence captured for every step. AI-powered validation is built into the platform rather than layered onto on-premises-era engines. Mitigant is also EU-based and built in Germany, aligned with European digital sovereignty and GDPR; data residency details are on the Security & Trust FAQ.

This is some text inside of a div block.

Mitigant vs Traditional Breach and Attack Simulation

Most BAS platforms were built for on-premises and retrofitted to the cloud. Mitigant is purpose-built for cloud-native environments, validating real exploitability with depth and evidence, and interoperable enough to run alongside whatever covers the rest of your estate.

Mitigant

CLOUD-NATIVE AEV

Traditional BAS

Approach
Adversarial Exposure Validation (AEV), the category Gartner coined to consolidate breach and attack simulation, penetration testing, and red teaming into continuous, evidence-based exploitation validation.
Breach and attack simulation, one of the three older categories AEV now consolidates.
Built for the Cloud
Cloud-native by design. Attack emulation across the cloud control plane and data plane, spanning AWS, Azure, and Google Cloud.
Endpoint and network heritage. Cloud support added later as a thin set of predefined checks, not deep attack execution across cloud identity, control plane, and data plane.
Attack Execution
Real, safe, reversible attacks with built-in guardrails and automatic cleanup. No residual impact, no false positives.
Simulations run against deployed agents or isolated sandboxes, not the live cloud environment, which makes results vulnerable to false positives and short on realism.
Chained, Reproducible Attacks
Attack-as-code based on the Cloud Attack Language, a readable, version-controllable format. Chain techniques into realistic multi-step attacks that are reproducible, automatable, and ready for agentic workflows.
Attacks come as predefined scenarios selected from the vendor's library and run through its console, not portable, version-controlled code you can chain, automate, or build on.
Cloud Coverage & Evidence
500+ cloud-native attacks across AWS, Azure, and Google Cloud, spanning identity, control plane, and data plane, plus AI red teaming, with evidence captured for every step.
Cloud capabilities layered onto network and endpoint libraries, with limited breadth and depth across cloud providers.
Deployment & Time to Value
Deployment is agentless and directly connects with the cloud API. This reduces management overhead and allows easy scalability across multiple cloud accounts.
Mostly based on installation of software agents on VMs or use of virtual appliances. This makes deployment time-consuming, adds maintenance overhead and scaling across cloud accounts challenging.
Exposure Management (CTEM)
Delivers full CTEM for the cloud. Leverages native CSPM for discovery, scoping, and prioritization; attack emulation validates real exploitability to cut false positives; results align to compliance benchmarks; and findings push into other security and collaboration tools to facilitate mobilization.
CTEM typically limited to the validation step, without the native cloud discovery, prioritization, and compliance context.
AI-Powered Validation
AI-powered validation built into the platform, applying AI to surface and validate exploitable cloud exposures.
AI features layered onto on-premises-era engines.
Interoperability
Built to integrate. Exposes APIs for pushing reports to other tools and also automating workflows to enhance productivity.
Sold as an all-in-one platform, designed to be your single tool rather than a component that slots into a best-of-breed stack.
Data Sovereignty
EU-based and built in Germany. Aligned with European digital sovereignty and GDPR
Predominantly US-based. Data residency and EU alignment vary.

About Mitigant

Mitigant is a German cybersecurity company pioneering cloud security validation through adversarial exposure validation and cloud attack emulation. Founded by researchers from Hasso Plattner Institute with over 20 years of combined cloud security experience, Mitigant provides an integrated security platform combining CSPM, KSPM, and Cloud Attack Emulation.

The platform enables organizations of all sizes to proactively verify the readiness and resilience of their cloud-native infrastructures across AWS, Azure, and Kubernetes against potential cyber threats. By combining continuous posture management with attack validation based on MITRE ATT&CK and ATLAS frameworks, Mitigant helps detect and remediate security blind spots within cloud security strategies, tools, and teams.

Contact Information

Partnerships & Recognition

  • Strategic partner with German Federal Office for Information Security (BSI)
  • Selected for Google for Startups Growth Academy: AI for Cybersecurity
  • Member of Digital Hub Bonn
  • Strategic partnerships with GlobalDots, Future Spirits, Syself, and Fogbyte
This FAQ is regularly updated to reflect the latest platform capabilities and industry best practices.
Last Updated: July 2026

Expose Threats with AI-Powered Adversary Emulation

Safely run controlled cloud attacks and validate your real defensive capabilities in minutes. No credit card required.