Advanced Malware Detection TechniquesInformation and Cyber SecurityNetwork Security and Intrusion Detection

Suresh K. Damodaran, Paul D. Rowe

2026.5.23Digital Threats: Research and Practice

DOI: 10.1145/3816043

Abstract

The emulation of multi-step attacks attributed to advanced persistent threats is valuable for training defenders and evaluating defense tools. In this paper, we present Effects Language (EL), a novel directly executable visual coordination programming language for such attack emulation, and its operational semantics. EL supports reactive orchestration of an attack graph including lazy precondition evaluation to emulate realistic attack scenarios. EL also enables separation of roles and responsibilities for the threat emulation workflow, and programming for attack resilience. Through a case study we demonstrate how EL can be utilized to bring efficiencies in time and resources in automated threat emulation.

Citation format

DAMODARAN, Suresh K.; ROWE, Paul D. Automated repeatable adversary threat emulation with effects language (EL). Digital Threats: Research and Practice, 2026, 7(3): 1–37.