Basilisk
BASILISK
[services_red_team]RED TEAM ENGAGEMENT

Full adversarial simulation. With a business goal.

An end-to-end adversarial simulation with a defined objective and no warning to the defence team. The question here is not whether a vulnerability exists: it is whether your organisation notices, contains and responds once someone is already inside.

Red teaming measures detection, not a list of flaws

A pentest answers what is exploitable. A red team exercise answers what happens next — how long before anyone notices, whether the alert reaches a human, whether that human knows what to do, and whether containment holds under pressure. It tests the whole organisation, not just the technology: process, on-call rotation and decision-making are in scope alongside the environment.

  • The objective is a concrete business target, defined with you — not a list of technical findings.
  • The defence team is not told, because their natural reaction is exactly what is being measured.
  • At the end, every action executed is set against what detection actually recorded.
  • The result exposes visibility and process gaps that vulnerability fixes alone never close.

What's included

The scope below is the default for a typical engagement. Everything is adjustable during scoping, at no cost.

// initial access
  • Targeted phishing against selected profiles
  • OSINT reconnaissance on key people
  • Pretexting by phone and messaging channels
  • Exposed edge surface
  • Leaked credentials and password reuse
  • Remote access and third-party portals
  • Controlled USB drop and physically delivered media
// movement
  • Local and domain privilege escalation
  • Credential harvesting from memory and disk
  • Abuse of trust relationships between systems
  • Lateral movement across network segments
  • Access to repositories, pipelines and secrets
  • Quiet persistence and access recovery
// objective
  • Reaching a database defined as the target
  • Access to a financial or payment system
  • Simulated exfiltration of a sensitive set
  • Control of an administration console
  • Reaching a critical production environment
  • Proving impact without causing damage
// response
  • Time to first detection
  • Quality and destination of the alert raised
  • Escalation and on-call activation
  • Effectiveness of the containment applied
  • Internal communication during the incident
  • Records and trail available for investigation
// evasion and post-exploitation
  • EDR and antivirus evasion within the agreed rules
  • Command and control with controlled persistence
  • Active Directory escalation and delegation abuse
  • Kerberoasting and credential extraction from memory
  • Pivoting between on-premises network and cloud
  • Cleanup and restoration of the environment

Modalities

adjustable to scope
01 /

Full red team

An unannounced exercise with a defined objective and freedom of route within the rules. It measures the defence operation under realistic conditions, including what happens outside business hours.

02 /

Purple team

Attack and defence in the same room, running technique by technique and checking on the spot what shows up in monitoring. Less surprise, more fine-tuning of rules and coverage.

03 /

Assumed breach

We start from access already granted, as if an initial compromise had happened. It shortens the entry phase and concentrates effort on lateral movement, detection and containment.

When an adversarial exercise makes sense

Red teaming assumes a foundation already exists. Without monitoring and without a response plan, the exercise measures a void — and a pentest would return more for the same effort.

monitoring exists and nobody knows if it works

Tooling bought, rules enabled, dashboards built — and no evidence that a real attack would raise an actionable alert. The exercise turns assumption into measurement.

the response plan has never been used

An approved document, a designed flow, an on-call rota on paper. Only an unannounced exercise shows whether escalation actually happens, and how long it takes.

after a run of remediation

Several pentest cycles closed, and the next question is different: with the known flaws fixed, can someone still reach the target by a route nobody anticipated?

when the requirement is maturity, not a list

Certain sectors and contracts ask for evidence of detection and response capability, not just the absence of vulnerabilities. That is what this exercise produces.

How we conduct it

[pipeline]
01/objective

Target definition and rules

With a restricted group we agree the concrete objective, what is forbidden, which systems stay untouched and how the exercise is called off if anything escapes the plan. We record who knows about it — usually very few people — so the rest of the organisation reacts genuinely.

02/intelligence

Intelligence on the organisation

We gather what is publicly available: people, roles, suppliers, technologies, addresses, past breaches and digital footprint. It is the same material an adversary would assemble before choosing a way in, and it frequently points at the weakest link on its own.

03/entry

Gaining initial access

We execute the chosen route — pretext, exposed surface, reused credential or third party. Every attempt is timestamped, so it can later be lined up against what defence saw, including the attempts that failed.

04/lateral

Movement and escalation

From the first foothold we advance towards the objective: elevate privilege, harvest credentials, cross segments and reach systems. We work with an eye on stealth, because being too loud would answer the wrong question.

05/objective

Reaching the target

On reaching the objective, the demonstration is made without causing harm: evidence of access, no real exfiltration of sensitive data and no destructive change. What matters is proving the route exists and recording how it was walked.

06/debrief

Joint reconstruction

The most valuable deliverable is the final session: the attack timeline placed beside the defence timeline. Where an alert fired and nobody looked, where no record existed at all, where containment worked. It produces a prioritised list of detection fixes.

Public references behind the work

The exercise follows recognised adversarial-simulation frameworks, which makes results comparable over time and legible to regulators and auditors.

MITRE ATT&CK
Every technique executed carries its identifier, which lets you build a coverage matrix for your detection and track progress between exercises.
TIBER-EU
The European framework for threat-intelligence-led testing defines roles, phases and safeguards for adversarial exercises in live environments, and it is the reference for European financial services.
CBEST and equivalents
National intelligence-led testing programmes follow similar logic: a target chosen from real threat intelligence, controlled execution and a joint reconstruction at the end.
NIST SP 800-53 / CSF
Detection and response controls provide the vocabulary to describe each gap in terms your governance function already uses.
Cyber Kill Chain
The phased model of an attack helps show at which point in the chain the organisation did — or did not — interrupt the advance.
Rules of engagement
A document signed before the start, covering scope, prohibitions, windows, emergency contacts and stop criteria. It is what separates an authorised exercise from a real incident.

Deliverables

dual view · NDA
01

Attack narrative

The complete story, in chronological order, from first contact to objective. This is the document a board reads end to end, because it describes decisions and consequences rather than technical identifiers.

02

Side-by-side timeline

Every action executed, timestamped, alongside what defence recorded, alerted on or ignored. It is the centrepiece of the exercise and usually drives the fastest changes.

03

Detection coverage matrix

The techniques used, mapped by identifier, showing what was detected, what was logged without alerting and what left no trace at all.

04

Response assessment

How escalation played out in practice: who was called, how quickly, what decision was taken and what containment actually interrupted.

05

Detection recommendations

Concrete rule adjustments, missing log sources and coverage to add, prioritised by what would have cut the route short earliest.

06

Reconstruction session

A working session with the defence team walking the exercise step by step, with room for questions. As knowledge transfer it is worth more than any chapter of the report.

Frequently asked

01How is red teaming different from a pentest?

A pentest goes for breadth: cover the surface and find as many exploitable flaws as possible within scope. A red team goes for depth towards an objective and measures how the organisation reacts. One answers what is vulnerable; the other answers what happens when somebody exploits it.

02Do we need to warn the security team?

No, and that is precisely the point. A restricted group — usually the security lead and legal — knows about the exercise and holds the signed authorisation, so everything can be called off if the response escalates externally. The rest of the team reacts without knowing, which is the only way to measure a genuine reaction.

03What if the exercise causes a real incident?

The rules of engagement define forbidden actions, untouchable systems and an immediate stop criterion. Emergency contacts are open on both sides throughout, and the signed authorisation is produced as soon as it is needed to end an escalation.

04Is our environment ready for this?

If there is no monitoring producing actionable alerts and no response plan in use, the exercise will measure an absence you already know about. In that case a pentest plus detection engineering returns more. Red teaming makes sense when there is a defence to test.

05Do you phish our staff?

When social engineering is in scope, yes, with an explicit safeguard: no result is individualised for disciplinary purposes and nothing is reported in a format that exposes a person. What matters is the effectiveness of the control and the process, not a list of who clicked.

06How long does it take?

Considerably longer than a pentest, because stealth requires a slow tempo and because the target is reached by a route rather than a scan. Duration is set together with the objective, and the final reconstruction phase often yields as much as the execution itself.

07Can it be repeated and compared?

Yes, and that is where the format proves its worth. With techniques recorded by identifier, a later exercise shows what became detectable, what remains invisible and whether reaction time improved — measured progress rather than impression.

Sectors where this service applies
// related services
// contact

Ready to uncover your flaws?

First scoping call is free and covered by NDA. Within 48 hours you receive technical proposal, scope and timeline. No bureaucratic forms.