Intelligence-led. Objective-driven. Fully documented.
A red team engagement is not a longer penetration test. It is a controlled operation with a mission, strict rules and a debrief that makes your defenders better.
Six phases, start to debrief.
Threat intelligence & scoping
We study your industry, attackers that target it, and your stated crown jewels. Together we define objectives, boundaries, timelines and success criteria — the mission brief.
Rules of engagement
A signed ROE document: what is in scope, what is forbidden, emergency contacts, evidence handling and the “go dark” protocol. Nothing happens outside it, ever.
Initial access
OSINT, perimeter exploitation, phishing or approved physical entry — whatever the chosen adversary persona would realistically use. Goal: one quiet foothold.
Foothold & expansion
C2 infrastructure with OPSEC controls, credential harvesting, privilege escalation, lateral movement and persistence — always mapped to ATT&CK technique IDs as we go.
Objective completion
Reach the agreed objectives: domain dominance, crown-jewel access, data staging. Evidence is captured at every step — screenshots, logs and IoCs, without touching production integrity.
Debrief & hardening
The most valuable phase. Red and blue teams walk the kill chain together: what fired, what stayed silent, and the prioritized fixes. Followed by the full report and a retest window.
Rules of engagement, in writing.
- Explicit scope — named assets, networks, tenants and people; everything else is off-limits.
- No-go list — production-critical systems excluded by design, with agreed crash-stop signals.
- Real-time logging — every action timestamped and attributable to an operator.
- Secrets handling — captured credentials stored encrypted, returned and rotated at close-out.
- Single point of contact — a designated client lead with a 24/7 emergency channel.
| Kill chain stage | Example techniques |
|---|---|
| Recon | T1595T1589 |
| Initial access | T1566T1190T1078 |
| Execution | T1059T1204 |
| Persistence | T1136T1547 |
| Privilege escalation | T1558T1068 |
| Lateral movement | T1021T1550 |
| Credential access | T1003T1110 |
| Exfiltration | T1041T1567 |
What we optimize for
OPSEC-first
Infrastructure is per-engagement and disposable. We assume defenders are reading every packet — because the best ones are.
No vanity findings
We do not pad reports with scanner noise. If a finding does not chain toward your objectives, it is not the point.
Blue team uplift
The report is for your defenders. Every missed detection comes with a rule, a log source or a playbook to close the gap.
Want the full ROE template?
We will walk you through scoping and rules of engagement before any contract is signed.