Simulation of Espionage and Defense Scenarios
Garbo enables controlled, repeatable simulations of targeted surveillance and intrusion campaigns so defenders can evaluate procedures without depending on physical devices. These exercises are explicitly designed as defensive validation: they let organisations stress-test detection pipelines, assess incident response readiness and validate mitigations in a fully isolated, auditable environment.
Capabilities used (high-level, non-actionable)
- multi-device orchestration to emulate attacker campaigns across many targets;
- isolated device farms to run scenarios without risk of contamination;
- synchronized telemetry capture (network, process, and system traces) for comparative analysis;
- reproducible snapshots to iterate on mitigations and measure effectiveness.
Single example scenario — defensive simulation of a targeted surveillance campaign
Objective: measure detection coverage and response time of an enterprise telemetry stack against a sophisticated, multi-stage surveillance campaign.
High-level flow:
- design a realistic threat scenario (entry vector, lateral steps, persistence goals) in collaboration with blue-team stakeholders.
- provision a device farm that mirrors the organisation’s device inventory (OS versions, configurations).
- execute the scenario inside Garbo’s isolated environment while capturing all relevant telemetry.
- evaluate alerts, false positives/negatives and the effectiveness of containment playbooks.
- refine detection rules and repeat the scenario to validate improvements.
This approach mirrors how national labs and large SOCs validate detection capabilities after public revelations of sophisticated spyware; for context see published analyses such as the Pegasus coverage described in other use cases and broader reporting on targeted surveillance investigations. These public reports illustrate why an organisation must be able to reproduce complex campaigns safely and measure defensive effectiveness.
