> For the complete documentation index, see [llms.txt](https://106-sam.gitbook.io/ejptv2-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://106-sam.gitbook.io/ejptv2-notes/crto/getting-started/adversary-emulation-vs-simulation/stealth-and-opsec.md).

# Stealth and OPSEC

* 'Operations security', aka OPSEC, was originally a military term but subsequently adopted by the Information security community. It's used to describe the likelihood of actions being observed by enemy intelligence.
* From the perspective of a red team, this would be a measure of how likely their actions can be observed and subsequently interrupted by a blue team.
* OPSEC only becomes a significant concern during adversary simulation, rather than emulation.
  * As while emulating an adversary, the red team is constrained to specific set of TTPs.&#x20;
  * However, during a simulation, the red team's goal is to achieve the operational objective before getting caught by the blue team, so OPSEC becomes a lot more important.

> Note:  Therefore, its crucial that a red teamer understands what indicators they leave behind when carrying out their TTPs.&#x20;
