# Threat Information Warfare

**R-2A activity** of project 976 — Army Threat Sim (ATS)  
**Program element:** 0604256A — Threat Simulator Development  
**Component:** U.S. Army · **Budget Activity:** 6  
**Vintage:** President's Budget PB2027  
**Canonical URL:** https://hitchintel.com/programs/0604256A/976/a0  
**Parent:** https://hitchintel.com/programs/0604256A

## Summary

This activity requests $11.4M in FY2027, 19% of project 976, down 60% on FY2026. The R-2A exhibit describes it across FY2025–FY2027, including what the FY2027 money is planned to buy.

## What the FY2027 request buys

**FY2027 planned work.** Sustainment of existing threat-based Red Team capabilities, including previously developed toolsets and distributed operations infrastructure. Maintain Red Team Certification and Accreditation (C&A) required for on-network operations. Continued development of state and non-state threat targeting packages that are current, accurately profiling attack trends and timelines, intent, levels of sophistication, and threat training. These threat packages represent state and non-state level forces using both active and passive network attack to selectively degrade or disrupt Command, Control, Communications, Computers (C4) Intelligence, Surveillance and Reconnaissance (C4ISR) and Enterprise Business Systems. Development of threat targets and networks as new real-world targets sets and capabilities evolve.

**FY2026 to FY2027 change.** Funding decrease reduces planned threat assessments to focus on the highest priorities.

## Before the request year

**FY2026 plans — current year.** Execute information and decision advantage threat simulation to support Army critical program information protection. Provide Army Programs with quantifiable information regarding risks to critical information within the public domain. Assess effectiveness of measures and countermeasures employed within OPSEC and program protection plans. Plan, execute and provide threat assessments to prioritized systems and activities spanning key areas of concern across Army. Advancement of existing threat-based Red Team capabilities, including previously developed toolsets and distributed operations infrastructure. Maintain Red Team Certification and Accreditation required for on-network operations. Continued development of state and non-state threat targeting packages that are current, accurately profiling attack trends and timelines, intent, levels of sophistication, and threat training. These threat packages represent state and non-state level forces using both active and passive network attack to selectively degrade or disrupt Command, Control, Communications, Computers Intelligence, Surveillance and Reconnaissance and Enterprise Business Systems. Development of threat targets and networks as new real-world targets sets and capabilities evolve. Continued development and employment of intelligence validated LVC dynamic Commercial, Multi-National & Military (Red and Gray) Environments required for Army and Joint Offensive Cyber Operations and Defensive Cyber Operations-Response Actions program development; Test and Evaluation (e.g., Joint Common Access Platform OT); and mission rehearsal/capabilities assessments in support of Army and Joint Multi-Domain Operations ranges. Conduct Foreign Commercial Aquisition and Foreign Commercial Purchase actions.

**FY2025 accomplishments.** Development of existing threat-based Red Team capabilities, including previously developed toolsets and the Red Team Shared Infrastructure (RTSI) - a distributed operations infrastructure. Infrastructure hardware refresh. Maintain Red Team Certification and Accreditation required for on-network operations. Continued development of state and non-state threat targeting packages that are current, accurately profiling attack trends and timelines, intent, levels of sophistication, and threat test and evaluation. These threat packages represent state and non-state level forces using both active and passive network attack to selectively degrade or disrupt Command, Control, Communications, Computers (C4), Intelligence, Surveillance and Reconnaissance (C4ISR), and Enterprise Business Systems. Persistently replicates Advance Persistent Threats from near-peer actors across the materiel enterprise (into operations) which threaten Army modernization and readiness. Development of threat targets and networks as new real-world targets sets and capabilities evolve.

## Funding

| Fiscal Year | Estimate Type | Amount ($M) |
|---|---|---|
| FY2025 | Actual | 21.4 |
| FY2026 | Enacted | 28.8 |
| FY2027 | Request | 11.4 |

> Prior, current and budget year only — an R-2A activity carries no five-year plan. It sums exactly into its project in the request year and not necessarily in any other.

## Other activities in project 976

- [Threat Electronic Warfare](https://hitchintel.com/programs/0604256A/976/a1) — FY2027 36.9
- [Threat Network and Mission Command](https://hitchintel.com/programs/0604256A/976/a2) — FY2027 12.0

## Source & machine access

- **Source:** FY2027 Department of the Army RDT&E Budget Justification, Exhibit R-2A, PE 0604256A project 976 (PB PB2027). Narrative is the government's own text.
- **No marks, no contractors at this grain** — congressional marks land on the program element and R-3 performers on the project.
- **MCP:** `mcp.hitchintel.com` — `budget_get_activity`.

*HitchAI is an independent intelligence service, not affiliated with the U.S. Department of Defense. Budget figures are requests/estimates, not obligations.*