Full adversarial simulation. With a business goal.
An end-to-end adversarial simulation with a defined objective and no warning to the defence team. The question here is not whether a vulnerability exists: it is whether your organisation notices, contains and responds once someone is already inside.
Red teaming measures detection, not a list of flaws
A pentest answers what is exploitable. A red team exercise answers what happens next — how long before anyone notices, whether the alert reaches a human, whether that human knows what to do, and whether containment holds under pressure. It tests the whole organisation, not just the technology: process, on-call rotation and decision-making are in scope alongside the environment.
- The objective is a concrete business target, defined with you — not a list of technical findings.
- The defence team is not told, because their natural reaction is exactly what is being measured.
- At the end, every action executed is set against what detection actually recorded.
- The result exposes visibility and process gaps that vulnerability fixes alone never close.
What's included
The scope below is the default for a typical engagement. Everything is adjustable during scoping, at no cost.
- Targeted phishing against selected profiles
- OSINT reconnaissance on key people
- Pretexting by phone and messaging channels
- Exposed edge surface
- Leaked credentials and password reuse
- Remote access and third-party portals
- Controlled USB drop and physically delivered media
- Local and domain privilege escalation
- Credential harvesting from memory and disk
- Abuse of trust relationships between systems
- Lateral movement across network segments
- Access to repositories, pipelines and secrets
- Quiet persistence and access recovery
- Reaching a database defined as the target
- Access to a financial or payment system
- Simulated exfiltration of a sensitive set
- Control of an administration console
- Reaching a critical production environment
- Proving impact without causing damage
- Time to first detection
- Quality and destination of the alert raised
- Escalation and on-call activation
- Effectiveness of the containment applied
- Internal communication during the incident
- Records and trail available for investigation
- EDR and antivirus evasion within the agreed rules
- Command and control with controlled persistence
- Active Directory escalation and delegation abuse
- Kerberoasting and credential extraction from memory
- Pivoting between on-premises network and cloud
- Cleanup and restoration of the environment
Modalities
adjustable to scopeFull red team
An unannounced exercise with a defined objective and freedom of route within the rules. It measures the defence operation under realistic conditions, including what happens outside business hours.
Purple team
Attack and defence in the same room, running technique by technique and checking on the spot what shows up in monitoring. Less surprise, more fine-tuning of rules and coverage.
Assumed breach
We start from access already granted, as if an initial compromise had happened. It shortens the entry phase and concentrates effort on lateral movement, detection and containment.
When an adversarial exercise makes sense
Red teaming assumes a foundation already exists. Without monitoring and without a response plan, the exercise measures a void — and a pentest would return more for the same effort.
Tooling bought, rules enabled, dashboards built — and no evidence that a real attack would raise an actionable alert. The exercise turns assumption into measurement.
An approved document, a designed flow, an on-call rota on paper. Only an unannounced exercise shows whether escalation actually happens, and how long it takes.
Several pentest cycles closed, and the next question is different: with the known flaws fixed, can someone still reach the target by a route nobody anticipated?
Certain sectors and contracts ask for evidence of detection and response capability, not just the absence of vulnerabilities. That is what this exercise produces.
How we conduct it
[pipeline]Target definition and rules
With a restricted group we agree the concrete objective, what is forbidden, which systems stay untouched and how the exercise is called off if anything escapes the plan. We record who knows about it — usually very few people — so the rest of the organisation reacts genuinely.
Intelligence on the organisation
We gather what is publicly available: people, roles, suppliers, technologies, addresses, past breaches and digital footprint. It is the same material an adversary would assemble before choosing a way in, and it frequently points at the weakest link on its own.
Gaining initial access
We execute the chosen route — pretext, exposed surface, reused credential or third party. Every attempt is timestamped, so it can later be lined up against what defence saw, including the attempts that failed.
Movement and escalation
From the first foothold we advance towards the objective: elevate privilege, harvest credentials, cross segments and reach systems. We work with an eye on stealth, because being too loud would answer the wrong question.
Reaching the target
On reaching the objective, the demonstration is made without causing harm: evidence of access, no real exfiltration of sensitive data and no destructive change. What matters is proving the route exists and recording how it was walked.
Joint reconstruction
The most valuable deliverable is the final session: the attack timeline placed beside the defence timeline. Where an alert fired and nobody looked, where no record existed at all, where containment worked. It produces a prioritised list of detection fixes.
Public references behind the work
The exercise follows recognised adversarial-simulation frameworks, which makes results comparable over time and legible to regulators and auditors.
- MITRE ATT&CK
- Every technique executed carries its identifier, which lets you build a coverage matrix for your detection and track progress between exercises.
- TIBER-EU
- The European framework for threat-intelligence-led testing defines roles, phases and safeguards for adversarial exercises in live environments, and it is the reference for European financial services.
- CBEST and equivalents
- National intelligence-led testing programmes follow similar logic: a target chosen from real threat intelligence, controlled execution and a joint reconstruction at the end.
- NIST SP 800-53 / CSF
- Detection and response controls provide the vocabulary to describe each gap in terms your governance function already uses.
- Cyber Kill Chain
- The phased model of an attack helps show at which point in the chain the organisation did — or did not — interrupt the advance.
- Rules of engagement
- A document signed before the start, covering scope, prohibitions, windows, emergency contacts and stop criteria. It is what separates an authorised exercise from a real incident.
Deliverables
dual view · NDAAttack narrative
The complete story, in chronological order, from first contact to objective. This is the document a board reads end to end, because it describes decisions and consequences rather than technical identifiers.
Side-by-side timeline
Every action executed, timestamped, alongside what defence recorded, alerted on or ignored. It is the centrepiece of the exercise and usually drives the fastest changes.
Detection coverage matrix
The techniques used, mapped by identifier, showing what was detected, what was logged without alerting and what left no trace at all.
Response assessment
How escalation played out in practice: who was called, how quickly, what decision was taken and what containment actually interrupted.
Detection recommendations
Concrete rule adjustments, missing log sources and coverage to add, prioritised by what would have cut the route short earliest.
Reconstruction session
A working session with the defence team walking the exercise step by step, with room for questions. As knowledge transfer it is worth more than any chapter of the report.
Frequently asked
A pentest goes for breadth: cover the surface and find as many exploitable flaws as possible within scope. A red team goes for depth towards an objective and measures how the organisation reacts. One answers what is vulnerable; the other answers what happens when somebody exploits it.
No, and that is precisely the point. A restricted group — usually the security lead and legal — knows about the exercise and holds the signed authorisation, so everything can be called off if the response escalates externally. The rest of the team reacts without knowing, which is the only way to measure a genuine reaction.
The rules of engagement define forbidden actions, untouchable systems and an immediate stop criterion. Emergency contacts are open on both sides throughout, and the signed authorisation is produced as soon as it is needed to end an escalation.
If there is no monitoring producing actionable alerts and no response plan in use, the exercise will measure an absence you already know about. In that case a pentest plus detection engineering returns more. Red teaming makes sense when there is a defence to test.
When social engineering is in scope, yes, with an explicit safeguard: no result is individualised for disciplinary purposes and nothing is reported in a format that exposes a person. What matters is the effectiveness of the control and the process, not a list of who clicked.
Considerably longer than a pentest, because stealth requires a slow tempo and because the target is reached by a route rather than a scan. Duration is set together with the objective, and the final reconstruction phase often yields as much as the execution itself.
Yes, and that is where the format proves its worth. With techniques recorded by identifier, a later exercise shows what became detectable, what remains invisible and whether reaction time improved — measured progress rather than impression.
Ready to uncover your flaws?
First scoping call is free and covered by NDA. Within 48 hours you receive technical proposal, scope and timeline. No bureaucratic forms.