Red team operations
Adversary simulation that measures whether you detect and respond — not just whether the perimeter holds on the day of the test.
- Deliverable
- Attack narrative · detection gaps
- Stages
- 4
- Pricing
- Fixed, agreed before start
An objective-led operation against your organisation as it actually runs, executed under agreed rules of engagement with a named white-cell contact. The deliverable is not a vulnerability list; it is an attack narrative mapped to MITRE ATT&CK, paired with an honest account of which stages your detection stack caught, which it logged without alerting, and which passed unseen.
How the engagement runs
- 01
Objectives and rules of engagement
We agree the flags that define success, the systems that are out of bounds, the escalation path, and the white-cell contacts — in writing, before anything runs.
- 02
Threat modelling
The operation is modelled on adversaries that plausibly target your sector, so the techniques exercised are the ones your detections actually need to cover.
- 03
Execution
Access, persistence, escalation and movement toward the agreed objectives, with every action logged to the minute for later correlation against your telemetry.
- 04
Replay and remediation
A joint walkthrough with your defenders, matching our timeline against their alerts, and a concrete list of the detection content worth building next.
Typical scope
- Objective-based full-scope operations
- Assumed-breach and insider-threat scenarios
- Social engineering and phishing (where authorised in writing)
- Initial access, persistence, privilege escalation, lateral movement
- Purple team exercises run jointly with your defenders
- Detection engineering validation against specific ATT&CK techniques

