Red team operations for enterprises
[email protected] @infosecslab Authorized testing only

Tell us your crown jewels.

Describe your environment and your biggest worry. We reply within two business days with a proposed scope, objectives and rules of engagement — before any contract.

Channels

Email — 24/7
[email protected] Best for scoping requests and formal proposals. PGP available on request.
Telegram — fastest
@infosecslab For quick questions and emergency response coordination.
Main resource
infoseclab.ru Our primary site — full service catalog, publications and team background.
Response time
Scoping reply within 2 business days. Emergency incident support — same day.
Include in your request
  • Industry, headcount, primary platform (AD / hybrid / cloud)
  • What you are most worried about — that becomes our objective
  • SOC maturity: in-house, outsourced or none yet
  • Preferred window and any compliance constraints

What happens next

01

Intro call

30 minutes: your context, our approach, questions on both sides.

02

Scope & ROE

We draft objectives, boundaries and rules of engagement for your sign-off.

03

Operation

We execute within ROE, with a live channel and agreed check-ins.

04

Debrief & report

Kill-chain walkthrough with your defenders, then the full report and retest.

Frequently asked

Do you need our permission to attack “everything”?

No. Every asset, person and technique is covered by a signed ROE before we start. Out-of-scope systems are excluded technically where possible, not just on paper.

Will this disrupt production?

Engagements are designed to avoid availability impact. Production-critical systems are on a no-go list, and we use crash-stop signals your team can trigger at any time.

Can our SOC know about the operation?

That is your call. We run both announced and unannounced engagements. Unannounced tests give the truest detection picture; either way, a designated client lead always knows.

What do you deliver at the end?

An executive brief, the full attack narrative with ATT&CK mapping, a detection gap matrix, a prioritized hardening roadmap, an evidence pack with IoCs, and a live debrief — plus a free retest window.

Authorized testing only.

We operate strictly under signed contracts with verified ownership of targets. Requests to test third-party systems without authorization are declined and documented.

Email the team