Red team & adversary simulation

A penetration test asks whether vulnerabilities exist. A red team asks a harder question: if a competent attacker wanted your customer data, would they get it — and would anyone notice?

This is not a bigger penetration test

A penetration test is breadth-first and openly announced: your team knows it is happening, and the goal is to enumerate as much as possible inside a scope.

A red team is depth-first and quiet. We agree a concrete objective with a small number of people in your organisation — read the production customer database, authorise a payment, obtain domain administrator — and then pursue only what gets us there. Your defenders are not told, because their response is part of what is being measured.

That makes it the right exercise once you already have a security programme worth testing, and the wrong one if you have never had a penetration test. If you are unsure which you need, say so on the scoping call and we will tell you honestly — including when the answer is the cheaper engagement.

Scope

How we get in, and what we do next

Reconnaissance

Open-source intelligence on your estate, staff, technology and suppliers — the same footprinting a real operator performs before touching anything you own.

  • OSINT
  • Footprinting

Initial access

Externally exposed services, exposed credentials, and — only with prior written consent — phishing against an agreed population.

  • Phishing (consented)
  • External foothold

Establish & persist

Command and control over realistic channels, with persistence that mirrors how genuine intrusions survive a reboot and a password change.

  • C2
  • Persistence

Escalate & move

Privilege escalation and lateral movement toward the objective, taking the quietest available path rather than the fastest.

  • Lateral movement

Objective

The agreed goal is reached and evidenced — without exfiltrating real customer data. Proof is a screenshot and a record, never a copy of your production database.

  • Evidence, not exfil

Purple team replay

Optional and strongly recommended: we walk your defenders through the full timeline, replaying each step so they can tune detections against a real attack they just experienced.

  • Detection tuning

Every engagement ships with

  • Executive summary framed around the objective and whether it was met
  • Full attack narrative with a timestamped timeline
  • Every technique mapped to MITRE ATT&CK
  • Detection analysis — what your team saw, what they missed, and why
  • Prioritised remediation and detection-engineering recommendations
  • Live debrief, and an optional purple-team replay session
  • Free retest of remediated findings within 90 days
  • Signed attestation letter for auditors and customers

FAQ

Questions about this service

Do our defenders know it is happening?

No — that is the point. A small group of authorised people (usually the CISO or an equivalent) know, hold the rules of engagement, and can call a halt at any moment. Everyone else responds as they would to a real intrusion.

Is phishing included?

Only with explicit written consent, an agreed target population, and rules about what we will and will not do with anything we obtain. Credentials captured are used strictly inside the agreed scope and destroyed afterwards.

What if you cause an outage?

Rules of engagement define forbidden actions, and there is a named contact plus a kill switch available for the whole exercise. We stop the moment we are asked, and we will not take an action likely to disrupt production without approval.

How long does a red team take?

Typically three to six weeks of elapsed time. Much of that is deliberately slow — moving quietly is most of the exercise, and rushing it would test something other than your real defences.

Next step

Find out what an attacker would find.

Tell us what you have built. You get a reply within one business day, an NDA, and a free 30-minute scoping call with the person who will do the testing.