Red team operations for enterprises
[email protected] @infosecslab Authorized testing only

Eight ways we test your defenses the way adversaries do.

Each service can run standalone or chain into a full-scope operation. Every engagement ends with a detection debrief and a prioritized remediation roadmap.

RT-01

Full-scope, objective-driven campaigns

What it is
A multi-week operation modeled on a threat actor relevant to your industry. We pick a persona, adopt its tradecraft, and pursue business-impact objectives — from initial access to your crown jewels — while evading detection.
Typical length
3–6 weeks, black-box start, agreed objectives and rules of engagement
Best for
Organizations with a mature SOC that want to measure real detection and response under pressure

Outcome: an evidence-backed attack narrative, a detection gap matrix per technique, and a debrief that turns findings into a hardening plan.

RT-02

Your perimeter, through an attacker’s eyes

What it is
Focused operations against your internet-facing estate: exposed services, VPN and remote-access stack, forgotten assets, leaked credentials and phishing-resistant entry attempts.
Covers
Asset discovery, CVE weaponization, edge-device abuse, MFA fatigue and AitM phishing simulations
Best for
Validating that the first door really stays closed — before testing what happens after it opens

Outcome: a prioritized external exposure map and proof-of-concept paths into the network, each with the control that should have stopped it.

RT-03

From one workstation to domain dominance

What it is
Starting from an assumed breach — a single compromised endpoint or a plugtest drop — we map and abuse Active Directory: Kerberos attacks, ACL misconfigurations, delegation abuse, NTLM relay and gMSA misuse.
Covers
Kerberoasting, unconstrained/resource-based delegation, ADCS abuse, ACL chains, trust hopping
Best for
Environments where AD is the keys to the kingdom — which is most of them

Outcome: the shortest privilege-escalation paths to Domain Admin, chained and evidenced, with tiering and hardening fixes.

RT-04

AWS, Azure and M365 — attacked, not scanned

What it is
Identity-first operations in your cloud tenants: IAM privilege escalation, role and policy trust abuse, workload federation attacks, and pivot paths between on-prem and cloud.
Covers
IAM escalation chains, Entra ID abuse, app consents, token theft, storage and secrets exposure
Best for
Teams migrating workloads or running hybrid AD + Entra estates

Outcome: a validated cloud attack-path graph and guardrail fixes that survive real administrators.

RT-05

The human layer, tested with care

What it is
Pretext-driven campaigns against your staff: targeted phishing with safe credential capture, vishing to the helpdesk, MFA-push fatigue, and physical pretexting — always with an opt-out and full audit trail.
Covers
AitM phishing infrastructure, helpdesk impersonation, QR-code lures, whitelist-bypass delivery
Best for
Measuring security awareness and process discipline where training slides end

Outcome: campaign metrics by department, the exact lures that worked, and awareness actions that stick.

RT-06

Badges and doors under test

What it is
Authorized on-site operations: tailgating, badge cloning, access-reader weaknesses, unattended-device drops and attempts to reach secure zones — executed discreetly, with escorts and ROE agreed in advance.
Covers
Entry attempts, network drops, rogue-device placement, sensitive-area reach
Best for
Offices, data centers and production sites with badge-based controls

Outcome: a site-by-site access report with camera, guard and process fixes ranked by risk.

RT-07

Purple-team replays of every technique

What it is
A controlled replay of attack techniques against your live SIEM/EDR stack. For each technique we capture whether telemetry was generated, alerted, correlated and responded to.
Covers
ATT&CK-mapped test matrix, log-source coverage, rule tuning, SOC playbook drills
Best for
SOC teams that need to prove coverage, not assume it

Outcome: a detection coverage matrix, tuned rule sets and a backlog of log-source improvements.

RT-08

Quarterly waves on retainer

What it is
A standing red team cadence: quarterly operations with rotating objectives, plus between-wave regression tests to verify that fixes hold and detections stay tuned.
Covers
Objective rotation, retesting, threat-intel-driven scenarios, SOC on-call drills
Best for
Organizations that treat security posture as a metric, not a yearly event

Outcome: a posture trend line your leadership can track quarter over quarter.

Pick the level of pressure.

A

Targeted

One service, 1–2 weeks, white-box start. Ideal for a first engagement or a specific worry.

B

Full operation

Multi-week adversary emulation, black-box start, agreed end objectives. The classic red team.

C

Continuous

Retainer with quarterly waves, regression retests and SOC drills. Posture as a metric.

Not sure which mode fits?

Send us your context — industry, team size, main worry — and we will propose a scope within two business days.

Request assessment