Skip to content

Red team operations

Adversary simulation that measures whether you detect and respond — not just whether the perimeter holds on the day of the test.

Deliverable
Attack narrative · detection gaps
Stages
4
Pricing
Fixed, agreed before start

An objective-led operation against your organisation as it actually runs, executed under agreed rules of engagement with a named white-cell contact. The deliverable is not a vulnerability list; it is an attack narrative mapped to MITRE ATT&CK, paired with an honest account of which stages your detection stack caught, which it logged without alerting, and which passed unseen.

How the engagement runs

  1. 01

    Objectives and rules of engagement

    We agree the flags that define success, the systems that are out of bounds, the escalation path, and the white-cell contacts — in writing, before anything runs.

  2. 02

    Threat modelling

    The operation is modelled on adversaries that plausibly target your sector, so the techniques exercised are the ones your detections actually need to cover.

  3. 03

    Execution

    Access, persistence, escalation and movement toward the agreed objectives, with every action logged to the minute for later correlation against your telemetry.

  4. 04

    Replay and remediation

    A joint walkthrough with your defenders, matching our timeline against their alerts, and a concrete list of the detection content worth building next.

Typical scope

  • Objective-based full-scope operations
  • Assumed-breach and insider-threat scenarios
  • Social engineering and phishing (where authorised in writing)
  • Initial access, persistence, privilege escalation, lateral movement
  • Purple team exercises run jointly with your defenders
  • Detection engineering validation against specific ATT&CK techniques

Other engagements