
Join us for Adversary Village at Black Hat USA 2026!
Adversary Village is a community initiative focused on adversary simulation, offensive cyber security tradecraft and purple teaming. At Black Hat USA 2026, Adversary Village takes over
Station 1 and Station 3 of "The Interface" in the Business Hall, along with sessions in the CTF Arena. Expect gamified table-top exercises, guided breach and attack
simulation on live cyber ranges, an adversary simulation capture-the-flag competition and hands-on APT technique challenges.
Adversary Adventure is a story-driven, interactive cyber war-gaming experience built on a choose-your-own-adventure model. It is a gamified take on tabletop exercises, where participants
pick their role. An attacker working through post-exploitation, a defender responding to an active cyber threat actor, or a CISO managing an adversarial situation such as a ransomware incident.
The adversary adventure plays out as a storyboard. If you make the right set of choices, you will win; make the wrong ones and it's game over for you.
This area will feature guided breach simulation exercises for participants to engage with. There will be two activities, "Breach-the-Hospital" and "Breach-the-City," based on two
LEGO sets. A simulated cyber range will be available for each scenario, providing an exact replica of an enterprise production environment. We will provide a detailed walkthrough of the attack
scenarios, including Tools, Techniques, and Procedures (TTPs), commands, and how-to guides that show how to attack and breach the hospital's infrastructure or the office environment. The exercises
use enterprise red team tooling, including Cobalt Strike C2, the same kind of tooling used in real world engagements.
Both scenarios include basic and advanced exercises, so everyone from hands-on hackers to senior executives can take part at the right level for them.
Participants who complete the exercises and place at the top will be rewarded with exciting goodies.
Adversary CTF is a capture-the-flag competition hosted by Adversary Village at Black Hat USA, built around adversary simulation. Participants play as the attacker. The challenge
scenarios are built around real enterprise environments, and the TTPs you will be using are the same ones that nation-state groups, APTs and advanced adversaries use in actual operations.
Players work through challenges that cover every stage of an attack lifecycle. That means identifying footholds, moving laterally across systems, evading defenses, establishing persistence,
and exfiltrating data, all within a simulated target organization. Challenges are drawn from real-world attack simulation methodologies and cover areas like threat actor TTP replication, malware
behavior analysis, C2 tradecraft, APT emulation, and breach simulation scenarios. Every flag you capture represents a stage in an adversary's operation, not just a standalone puzzle.
Challenges range from medium to hard severity, so come prepared. It is built for red teamers, threat hunters, malware analysts, and incident responders who want to test their offensive skills
against scenarios that reflect how attacks actually happen.
Curious about how real APTs operate? Come find out at Attack of the APTs, a hands-on hacking challenge hosted by Adversary Village at Black Hat USA.
The name is inspired by the Star Wars movie, Attack of the Clones, and so is the challenge setup. Expect a Star Wars themed environment where every challenge ties back to the galaxy far, far
away, but the techniques are very much real world.
Each challenge is built around an attack technique used by real threat actors, pulled straight from threat intel reports on known APTs and adversary groups. The players will be working through
techniques like credential access, recon, persistence, and exfiltration, the same ones that show up in actual breach investigations and threat intel reports. No long attack chains, no rabbit holes,
just you, a laptop, and one technique to work through at a time.
Laptops are provided on-site, so you can walk up and start playing with zero setup. All the tools you need are already there. Challenges are easy to medium and designed to be solved in 15 to
20 minutes, so you can stop by, try a challenge or two in between sessions, and walk away having learned something cool.
This is open to everyone. Whether you are an offensive security specialist, a threat intel analyst who wants to get hands-on, a developer curious about how attackers think, a security leader
who wants to understand what your team is up against, or a business executive who wants to see it for real there is something here for you.
Stop by, pick a challenge, and experience the attack of the APTs.
Participants will use pre-configured devices to compromise a vulnerable cyber range with the assistance of a locally hosted AI model. The entire environment will operate offline
on a closed internal network, with all devices physically connected to the cyber range infrastructure. No external connectivity will be provided.
The objective is to demonstrate how modern AI models can execute attacks against a lab environment. Participants will first move to the adjacent area, where they will perform the same attack
chain manually in a guided exercise. They will then proceed to Frontier Breach, where they can observe how a locally hosted AI model compromises the same Active Directory cyber range. This side-by-side
experience highlights the difference between traditional hands-on techniques and AI-assisted offensive operations while reinforcing the underlying concepts.
Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!