Red Teaming
Adversary simulation, against a real threat model.
Not a checklist. We pick a real threat actor, model how they would come after you, and rehearse the breach end to end, reaching a crown jewel and proving it, without breaking anything.
Case study · anonymized under NDA
One phishing pretext. Most of the company.
A finance-and-insurance group asked us to test the human layer. From a single targeted phishing campaign, one foothold opened a path to roughly four in five endpoints across the estate, no malware detonated, no customer data taken. Just proof of how far a real crew would get, and the detection gaps that let them.
of endpoints reachable from one foothold
phishing pretext · zero malware
bytes of customer data taken
mapped, reported, closed on retest
Methodology
How an engagement runs.
Every engagement is scoped to your real risk and run by hand. The shape stays the same each time, the adversary and the objective are yours.
Scope and threat model
We agree the adversary to emulate, the objectives worth proving, a domain controller, a production database, a source repository, an executive mailbox, the cloud management plane, and where we start: internet-only, a pre-approved phish, an assumed-breach laptop, or an insider role. We also agree who on your side knows (the white cell) and the rules of engagement.
Initial access
We get in the way the chosen adversary would: targeted phishing, vishing or smishing against the helpdesk, or exploitation of an exposed edge service or public-facing app, or the agreed assumed-breach start. Public-disclosure techniques only; no 0-days by default.
Foothold and movement
We establish a foothold and move laterally using tradecraft that matches the named adversary's known toolkit. Operator-built tooling only, never leaked commercial kits.
Reach the objective
We go only as far as needed to make the point: reach the crown jewel, document it, stage data inside the perimeter, or push placeholder bytes through the egress path to show a data-loss gap. Never real customer data out of the perimeter, never ransomware run at scale.
Debrief and report
We walk your SOC and leadership through exactly what happened, hand over the evidence and detection guidance, and confirm in writing that every implant and access path has been removed.
Hard limits, always: no denial-of-service against production, no real exfiltration of customer data, no ransomware executed beyond a single sentinel-file capability demo, and no persistence left behind once the engagement ends.
What you get
Evidence your team can act on.
Adversary storyboard
A narrative timeline of the operation, written for the board.
Detection-gap report
Every technique your monitoring didn't catch, mapped to your SIEM.
Detection rule pack
Production-grade Sigma and KQL rules, ready to deploy.
IR playbook notes
Where your runbook held and where it didn't, prioritised.
Live SOC debrief
An after-action session with the operator who ran the engagement.
Implant-removal letter
Signed confirmation that all access has been removed.
FAQ
Red teaming, answered.
How is this different from a penetration test?
Will you actually break things or steal our data?
Does our blue team or SOC know in advance?
How do you decide the objectives and crown jewels?
How long does a red team engagement take?
Brief us on the adversary.
Tell us what you need to prove. An operator replies within one business day.