All services
03 / 03
Red team engagement
We define an objective with you, such as reaching a sensitive asset or exercising a specific business capability, then work towards it using the tradecraft of a real adversary. The answer you get is measured and unambiguous: can you get there, how long does it take, and what did the attacker have to cross to do it.
When this engagement applies
This is for you if
- You want to test your detection and response, not only your preventive controls
- You suspect a critical asset is reachable and want proof rather than a list of theoretical issues
- You need to validate a blue team, a SOC or a new alert before a real incident forces the test
- You want to know whether your Active Directory tiering actually contains an attacker who already has a foothold
What is out of scope
- Destructive actions or denial-of-service, which require explicit written approval
- Social engineering of named individuals without written consent
- Any action that compromises data integrity without an agreed rollback plan
Work and deliverables
What is in scope
- Objective setting and rules of engagement, with a written plan and a go/no-go checkpoint
- External and internal reconnaissance, including open source intelligence
- Initial access through realistic attack paths
- Lateral movement, persistence and privilege escalation
- Exfiltration simulation and control bypass attempts
- Detection evaluation: what was logged, what was missed, what triggered a response
Deliverables
- A written report with the attack narrative from reconnaissance to objective
- A timeline of techniques, entry points and control failures
- A detection review: what was logged, what was missed, what would have alerted
- Prioritised hardening and detection recommendations
- A debrief session with both offensive and defensive stakeholders
- One follow-up session once the recommended changes are deployed
How we run it
- 01
Objectives and rules
The target, the forbidden actions and the stop conditions are written down before the first packet leaves.
- 02
Reconnaissance
Passive collection first, then active probing only inside the agreed perimeter.
- 03
Adversary simulation
We pursue the objective, documenting every technique, credential and gap used to get there.
- 04
Debrief and detection review
A timeline of the operation, the controls that held, the ones that did not, and the detection gaps to close.
Standards and references
- MITRE ATT&CK
- NIST SP 800-115
- PTES
- OSSTMM
- CVSS v4.0