Section 01 // Overview
Red Team.
Crown jewels
tested.
Full kill-chain adversary simulation. Distinct from pentest — focused on crown jewel access and detection / IR validation.
Section 02 // Engagement Variants
Three engagement shapes.
Send us the shape of your program (maturity, prior engagements, the question you're trying to answer) and we'll recommend a variant.
Section 03 // Primary Goals
What question are you trying to answer.
Pick one. Every engagement is shaped around a single primary objective so the report has a clear answer.
Section 04 // Crown Jewels
Success is reaching these.
The crown jewels are the success criteria — the assets that, if compromised, materially harm the business. We pick 1–5 per engagement and the engagement scope is built backwards from them.
Impact demonstration ladder.
Per MITRE TA0040. You choose how loud the proof-of-impact is. We stop at the level you authorize — no further.
Section 05 // Starting Positions
Where the engagement begins.
Two families: external (internet only, no inside access) and assumed breach (an attacker already has X — what next). Most Full engagements run both, sequenced.
Section 06 // TTPs in Scope
Tactics, techniques, procedures.
Tap any category to expand. Each module is independently scoped — you can opt categories in or out at the engagement-letter stage.
01
Phishing
Per engagement
02
Vishing & Smishing
Optional module
03
Physical / On-Site
+1 week, +travel
04
External Exploitation
Per scope
05
Post-Compromise Movement
Whole engagement
06
Out of Scope · Always
Non-negotiable
Section 07 // White Cell & Blue Posture
Who knows the engagement is live.
Three blue-team postures. Pick one per engagement; you can switch postures mid-engagement at the readout for the next round.
White cell membership. Typically three people: CISO, IR lead, exec sponsor. Each carries a mobile number for stop-test triggers. Communication runs over an encrypted Signal group, Slack Connect channel, or whatever your IR program already uses.
Section 08 // Pricing & Adjusters
Base price, then adjusters.
Engagement price is the base variant plus any modules you turn on. No retainer fees, no per-finding charges, no SOW surprises.
Fixed overhead included: one week of report writing (the executive briefing is heavy), two days of readout (executive + technical), and a 15% schedule buffer because engagements drift.
Section 09 // What We'd Recommend
Engagement selection, by signal.
Honest, repeatable recommendations. If your situation matches the left column, the right column is where we'd start.
Section 10 // Deliverables
What you receive.
Section 11 // Engagements We Decline
What we won't take.
Stated up front so neither of us wastes time. If your situation matches one of these, we'll tell you and recommend the right path instead.