Unified security for MSPs

Test your EDR in minutes

Test one layer of your security with 9 safe attack simulations. See exactly what your EDR blocks, and misses.

*Desktop only. Complete the form 
and we’ll email you the simulation link.

A computer security dashboard in the V2 interface shows 1/3 Attacks Blocked. Two scenarios, labeled as S1 Simulation, are marked undetected and one as protected, with options to run again or go back to home.

Trusted by Leading Partners

SentinelOne
SuperOps
V2 Version
Syncro
CONNECTWISE
pax8
Manage Protect
MULTIPOINT
RESILIUM.ai
Checkpoint
SentinelOne
SuperOps
V2 Version
Syncro
CONNECTWISE
pax8
Manage Protect
MULTIPOINT
RESILIUM.ai
Checkpoint
SentinelOne
SuperOps
V2 Version
Syncro
Checkpoint
SentinelOne
SuperOps
V2 Version
Syncro
Checkpoint
CONNECTWISE
pax8
Manage Protect
MULTIPOINT
RESILIUM.ai
CONNECTWISE
pax8
Manage Protect
MULTIPOINT
RESILIUM.ai
A white background transitions into soft, gradient shades of pale purple on the left side, creating a smooth, calming abstract design reminiscent of a V2,S1 Simulation.
A man with long dark hair pulled back, wearing a black shirt, looks at the camera with a neutral expression against a plain gray background, resembling an S1 Simulation in style.

Elli Shlomo

Head of Security Research

“We built this test so MSPs can see precisely where their EDR falls short, from missed detections to response gaps, measured against real-world attacks”.

"We built this test so MSPs can see precisely where their EDR falls short, from missed detections to response gaps, measured against real-world attacks"
Black and white portrait of a person with long hair pulled back, wearing a dark shirt, looking directly at the camera with a neutral expression—captured with the clarity and precision of a V2 S1 Simulation.
Elli Shlomo
Head of Security Research

Three easy steps

Run the simulation

Install

Large, bold purple characters 01, styled in a modern sans-serif font on a light background—perfect for S1 Simulation branding or visuals.

Run the simulation

Install the tool on a Windows endpoint
with your EDR currently enabled and active.
No configuration or account required.

See how your EDR responds

Scan

The image shows the number 02 in large, bold, purple font on a light gray background, representing a step in the S1 Simulation process.

See how your EDR responds

Click “Run Full Scan.” All 9 attack simulations execute automatically in sequence, completing
in under 5 minutes.

Review what was missed

Verdict

Purple number 03 on a light gray background, inspired by S1 Simulation.

Review what was missed

Get a clear report of which techniques
were detected and which were missed.
Use it in your next client conversation or QBR.

A soft, white and pale purple gradient background with faint vertical and horizontal grid lines, reminiscent of a V2, S1 Simulation—giving the image a subtle, abstract, and minimalist appearance.

One platform.
Every signal connected.

See how MSPs using Guardz achieve measurable outcomes.

Attack Simulations
0
Full Scan
< 0 m
Risk to Endpoint
0
No Account Needed
Free
Capterra logo above a 4.9 out of 5 star rating, with the numbers and star icon in purple—trusted by MSPs for Secure & Insure CyberSecurity solutions.
A badge displaying the G2 logo, the text Users Love Us, and a 4.7 out of 5 stars rating, highlighting CyberSecurity excellence for MSPs.
A SourceForge badge showing five gold stars for user reviews, with a large 4.7 out of 5 rating and a star icon below it—trusted by MSPs for top CyberSecurity performance.
Attack Simulations
0
Full Scan
< 0 m
Risk to Endpoint
0
No Account Needed
Free 0
A faint, light blue grid pattern is set against a plain white background, reminiscent of a V2, S1 Simulation. The grid consists of evenly spaced horizontal and vertical lines, forming uniform squares.
A blurred gradient background transitioning from light lavender on the left to a deeper blue-purple on the right, with faint vertical lines and a soft, smooth appearance.

Mimic Real-world attacks

A blurred gradient background transitioning from deep blue on the left to light purple on the right.

Cloud ITDR

Identity Threat Detection & Response (ITDR) proactively verifies MFA and security settings, while actively benchmarking and analyzing user behavior to flag suspicious activity.

Endpoint Security

Stop malware, ransomware, and advanced threats at the source. AI-native EDR (with SentinelOne embedded) and Managed AV (with Windows Defender) ensure real-time protection across devices.

Email Security

Block sophisticated phishing and email-based attacks before they reach users with an API-based and AI-native engine to prevent credential theft, ransomware, and impersonation threats in real time.

Cloud Data Protection

Lock down sensitive business data with seamless cloud protection, without the need for complex policies, ensuring secure file collaboration while preventing unauthorized access and data leaks.

Security Awareness Training

Transform employees into a strong line of defense against cyber threats with pre-scheduled security awareness training that alters behavior and limits human-driven cyber risks before they escalate.

Phishing Simulation

Identify security weaknesses before attackers do by using generative AI and branded templates to automate phishing simulations to measure employee resilience and reinforce cybersecurity awareness.

Secure Browsing

Web security through a browser extension that escalates risk around employees exposed to malicious sites, web redirects, unsafe extensions, and more during their day-to-day internet activity.

External Footprint

Scan the digital footprint of businesses to discover exposures and eliminate vulnerabilities across domains, IPs, and cloud assets; closing security gaps before they’re exploited.

Dark Web

Knowledge of the dark corners of the internet can be exposed by scraping, analyzing and continuously monitoring the dark web for malicious activity targeting businesses and user credentials.

SAM Dump

Attempts to extract credential hashes from the local SAM database.

Modifies registry to quietly enable Remote Desktop Protocol access.

Attempts to patch the Anti-Malware Scan Interface in memory.

Requests suspicious access rights to the LSASS process memory.

Establishes an outbound connection to simulate C2 communication.

Creates a persistent task designed to evade standard detection.

Executes an obfuscated PowerShell payload directly in memory.

Abuses built-in Windows binaries to download external payloads.

Performs aggressive LDAP queries to map domain infrastructure.

A laptop displays a security alert reading Threat Detected Not Blocked as a red digital line breaches its screen, symbolizing a cyberattack in progress. Set against a dark purple, futuristic background, the scene evokes the intensity of an S1 Simulation environment.
A laptop displays a security alert reading Threat Detected Not Blocked as a red digital line breaches its screen, symbolizing a cyberattack in progress. Set against a dark purple, futuristic background, the scene evokes the intensity of an S1 Simulation environment.
A laptop displays a security alert reading Threat Detected Not Blocked as a red digital line breaches its screen, symbolizing a cyberattack in progress. Set against a dark purple, futuristic background, the scene evokes the intensity of an S1 Simulation environment.
A laptop displays a security alert reading Threat Detected Not Blocked as a red digital line breaches its screen, symbolizing a cyberattack in progress. Set against a dark purple, futuristic background, the scene evokes the intensity of an S1 Simulation environment.
A laptop displays a security alert reading Threat Detected Not Blocked as a red digital line breaches its screen, symbolizing a cyberattack in progress. Set against a dark purple, futuristic background, the scene evokes the intensity of an S1 Simulation environment.
A laptop displays a security alert reading Threat Detected Not Blocked as a red digital line breaches its screen, symbolizing a cyberattack in progress. Set against a dark purple, futuristic background, the scene evokes the intensity of an S1 Simulation environment.
A laptop displays a security alert reading Threat Detected Not Blocked as a red digital line breaches its screen, symbolizing a cyberattack in progress. Set against a dark purple, futuristic background, the scene evokes the intensity of an S1 Simulation environment.
A laptop displays a security alert reading Threat Detected Not Blocked as a red digital line breaches its screen, symbolizing a cyberattack in progress. Set against a dark purple, futuristic background, the scene evokes the intensity of an S1 Simulation environment.
A laptop displays a security alert reading Threat Detected Not Blocked as a red digital line breaches its screen, symbolizing a cyberattack in progress. Set against a dark purple, futuristic background, the scene evokes the intensity of an S1 Simulation environment.
A laptop displays a security alert reading Threat Detected Not Blocked as a red digital line breaches its screen, symbolizing a cyberattack in progress. Set against a dark purple, futuristic background, the scene evokes the intensity of an S1 Simulation environment.

Attempts to extract credential hashes from the local SAM database.

A laptop displays a warning with the message “Threat Detected Not Blocked,” as digital red lines and particles breach the screen in a dramatic V2 S1 Simulation, symbolizing a cybersecurity threat bypassing protection.

Modifies registry to quietly enable Remote Desktop Protocol access.

A laptop displays a warning with the message “Threat Detected Not Blocked,” as digital red lines and particles breach the screen in a dramatic V2 S1 Simulation, symbolizing a cybersecurity threat bypassing protection.

Attempts to patch the Anti-Malware Scan Interface in memory.

A laptop displays a warning with the message “Threat Detected Not Blocked,” as digital red lines and particles breach the screen in a dramatic V2 S1 Simulation, symbolizing a cybersecurity threat bypassing protection.

Requests suspicious access rights to the LSASS process memory.

A laptop displays a warning with the message “Threat Detected Not Blocked,” as digital red lines and particles breach the screen in a dramatic V2 S1 Simulation, symbolizing a cybersecurity threat bypassing protection.

Establishes an outbound connection to simulate C2 communication.

A laptop displays a warning with the message “Threat Detected Not Blocked,” as digital red lines and particles breach the screen in a dramatic V2 S1 Simulation, symbolizing a cybersecurity threat bypassing protection.

Creates a persistent task designed to evade standard detection.

A laptop displays a warning with the message “Threat Detected Not Blocked,” as digital red lines and particles breach the screen in a dramatic V2 S1 Simulation, symbolizing a cybersecurity threat bypassing protection.

Executes an obfuscated PowerShell payload directly in memory.

A laptop displays a warning with the message “Threat Detected Not Blocked,” as digital red lines and particles breach the screen in a dramatic V2 S1 Simulation, symbolizing a cybersecurity threat bypassing protection.

Abuses built-in Windows binaries to download external payloads.

A laptop displays a warning with the message “Threat Detected Not Blocked,” as digital red lines and particles breach the screen in a dramatic V2 S1 Simulation, symbolizing a cybersecurity threat bypassing protection.

Performs aggressive LDAP queries to map domain infrastructure.

A laptop displays a warning with the message “Threat Detected Not Blocked,” as digital red lines and particles breach the screen in a dramatic V2 S1 Simulation, symbolizing a cybersecurity threat bypassing protection.

FAQ

Yes. Every simulation is engineered to trigger EDR detections while remaining completely benign:

  • No malware is deployed
  • No data is exfiltrated
  • No system changes persist after the scan

Any EDR running on Windows endpoints, including SentinelOne. Common use cases:

  • Validate coverage before onboarding a new client
  • Verify detection after EDR configuration changes
  • Guardz Ultimate customers can use it to confirm MDR coverage is active

Yes, and this is the primary use case. Run it on a client or prospect’s endpoint to show exactly which techniques their current stack misses. Typical scenarios:

  • Pre-sales: demonstrate what legacy AV misses vs. EDR
  • Onboarding: verify the client’s endpoint is fully protected before going live
  • QBR: show concrete detection data, not just status dashboards

Legacy AV detects known malware by signature. EDR detects attack techniques by behavior. Three techniques this tool runs are consistently missed by AV and caught by properly configured EDR:

  • AMSI Bypass — disables PowerShell-level defenses before script execution
  • LOLBin Proxy — abuses legitimate Windows tools to evade allowlists
  • Base64 Execution — runs obfuscated payloads in memory with no file on disk
A soft, gradient background with pale purple fading into white, creating a smooth and calming abstract effect reminiscent of the S1 Simulation&apos;s serene aesthetic.

Ready to test your defenses?

A blue circular logo for AICPA SOC, featuring text that reads AICPA SOC and aicpa.org/soc4so, with SOC for Service Organizations | Service Organizations along the outer edge, emphasizing trust and compliance.
Badge design features WINTER 2026 at the top, the G2 logo in the corner, and High Performer bold in the center. The badge has red, orange, and yellow stripes near the bottom, adding flair to your collection of standout badges.
Orange letter C with an extended arm forming an abstract circular shape against a transparent background.
×
Step 1 of 4 - About you
1About you
2Business type
3Endpoints
4Contact

Tell us about yourself

Please enter a valid work email.
Please enter your first name (English letters only).
Please enter your last name (English letters only).

Which best describes you?

Select one option*
MSP
(Managed Service Provider)
In-house
IT Manager
Distributor,
or Reseller
Other
Please select an option.

Number of users
(endpoints) to protect?*

1-100 Users
100-300 Users
300-500 Users
500-1K Users
1K-2.5K Users
2.5K+ Users
Please select the number of users.

Phone number

Please enter a valid phone number.

How did you hear about us?

Select all that apply (Optional)
Facebook
Instagram
LinkedIn
Google
Colleague / Friend
Community (Reddit)
Partner
ChatGPT / AI
Other
Scroll for more

Check your inbox

We’ve emailed you a link to download the EDR simulation on your desktop.
Next steps
  • Open the email on your desktop
  • Download the simulation
  • Run it against your SentinelOne environment

Don’t see the email?Check your spam folder or wait a few minutes.

Want a guided
platform walkthrough?

Thank You

Your submission has been received.
Click below to download the EDR simulation.
Download for Windows

Want a guided walkthrough?

Your download is ready

Click below to download the EDR simulation
and run it against your SentinelOne environment.
Download for Windows

Want a guided walkthrough?

Open this on your desktop

The EDR Attack Simulator is a Windows executable, so it can only be downloaded and run on a desktop.

Paste it into your desktop browser, or just open this email on your computer.

Want a guided
platform walkthrough?

Slack
Slack
Got questions
about the simulation?