Red Teaming chains individual weaknesses together up to one objective inside your organisation, covertly and against your real blue team. Did the attacker get through, and did anyone notice?
Top: our path to the objective. Bottom: what reached your SOC. Simplified, anonymised example.
Nothing. Expected with passive recon.
One report after 40 minutes, ticket with no follow-up
Nothing. The device ran until the debrief.
SIEM alert, but it was then closed as a false positive
EDR blocked one tool, no further alerts after that
Only in the debrief
Measured in every phase: time to detect, time to respond and the detection rate across all techniques used.
The remediation measures come out of this side-by-side view. Next to the patch, the list then has items like “take alert X seriously” or “adjust the visitor process”.
| Module pentest | Red Teaming | |
|---|---|---|
| Guiding question | Where are the vulnerabilities? | How far does an attacker get? |
| Scope | One system, one vector | Whole organisation, one objective |
| Announcement | Known and scheduled | Covert, small circle informed |
| Detection and response | Not the focus | Central metric |
| Physical access | Only if booked separately | Part of the chain if the scope allows it |
One does not rule out the other. Most Red Teaming clients have carried out module pentests beforehand.
From research on the internet all the way to the objective, with no prior knowledge and no announcement.
For organisations with their own SOC or an MDR provider.
Starts with what an attacker has after a successful phishing attack: a normal account on the network.
For a first test of internal detection.
Attack and defence in the same room: we run technique after technique, and your team sharpens its detection right away.
For teams building a SIEM or closing gaps after a red team.
Red Teaming along the TIBER-EU phases, with threat intelligence up front and a control team. A dry run of the processes before a TLPT under DORA.
For banks, insurers and payment service providers.
Names the client, the scope, the time frame and the operators. On physical assignments our people carry it on them.
One or two people on your side who are in the know, reachable throughout the entire engagement. They can escalate and call a stop.
No deleting, no encrypting, no denial of service. Where ransomware would be rolled out, we place a marker file.
No real customer or personnel data is copied out. We prove access by screenshot, hash value or test record.
Private devices, third-party systems outside the scope and safety-relevant OT controls remain excluded, unless you release them for testing.
If your SOC reports an incident, the white cell checks with us within minutes whether it is ours. If it is not, we pause.
This is a selection. The complete rulebook, which covers abort criteria and a log of every single action among other things, is agreed with you in writing before the start.
The goal is never to show up your team or SOC. The debrief makes weaknesses visible without assigning blame.
In 30 minutes we clarify scope, objective and rules. Free of charge.
Book an initial call