Emulate the attack. Measure the defense.
GothamCity is my private adversary-emulation platform. It turns threat profiles and ATT&CK techniques into controlled campaigns, keeps execution context visible, and shows exactly where defensive coverage held—or where the operator still has a blind spot.
Coverage that explains itself.
This synthetic preview mirrors a local, agent-free validation run. All fourteen techniques completed in simulation; nine were marked as detected, leaving five explicit gaps for review.
Real screens. Sanitized data.
These images were captured from the local Docker build. The account area and environment details are excluded; the remaining content uses built-in threat profiles and a target-free simulation.


Plan, execute, challenge, repeat.
GothamCity keeps campaign composition and defensive interpretation in one loop, without pretending that a queued command and a verified endpoint execution are the same event.
Compose with context
Start from actor profiles or focused templates, then narrow the plan by platform, tactic, prerequisites, cleanup needs, and risk—not by a flat list of technique IDs.
Make execution honest
Staged, simulated, queued, dispatched, and agent-executed states stay distinct. The console shows the assigned agent and execution mode so a simulation never masquerades as endpoint proof.
Measure what defended
Results roll into tactic-level coverage, ATT&CK Navigator output, Sigma-oriented analysis, and a repeatable retest path. Undetected activity remains a named gap, not a buried log line.
A control plane with visible limits.
The platform is designed for authorized labs and purple-team work. Its public page describes the decision model while operational components remain private.
GothamCity owns
- Threat-profile, template, and technique-based campaign planning
- Atomic Red Team and LOLBAS execution context with cleanup metadata
- Explicit simulated-versus-live agent state and campaign history
- Detection coverage, blind-spot review, reporting, and retest workflow
GothamCity does not claim
- A simulated result proves a command ran on a real endpoint
- An ATT&CK mapping alone proves detection quality or impact
- A registered agent authorizes activity outside an approved scope
- The private repository, deployment, or operator payloads are public
