How far does an attacker really get? And when do you notice?

Red Teaming chains individual weaknesses together up to one objective inside your organisation, covertly and against your real blue team. Did the attacker get through, and did anyone notice?

  • CRTO and CRTP certified team
  • Physical access as part of the chain
  • Covert, usually only C-level informed

One attack chain, two perspectives

Top: our path to the objective. Bottom: what reached your SOC. Simplified, anonymised example.

Red Team
Your SOC
1Recon
OSINT, passive recon, external port scan
Neutral

Nothing. Expected with passive recon.

2Initial Access
Phishing sent to six employees, two sets of credentials captured
Detected, no response

One report after 40 minutes, ticket with no follow-up

3Physical Foothold
Tailgating, rogue device in the meeting room
Not detected

Nothing. The device ran until the debrief.

4Internal Access
Network scan, Kerberoasting
Misjudged

SIEM alert, but it was then closed as a false positive

5Privilege Escalation
Lateral movement onto three servers
Partly detected

EDR blocked one tool, no further alerts after that

Objective
Domain Admin, marker file placed
Not detected

Only in the debrief

Measured in every phase: time to detect, time to respond and the detection rate across all techniques used.

Time to Detect Time between our action and the first alert, per phase.
Time to Respond Time from the alert to a countermeasure that actually slowed us down.
Detection rate Which of the techniques we used triggered an alert, and which stayed silent.

The remediation measures come out of this side-by-side view. Next to the patch, the list then has items like “take alert X seriously” or “adjust the visitor process”.

How an engagement runs

  1. Scoping and rules of engagementObjective, boundaries, white cell, letter of authorisation.
  2. ReconnaissanceOSINT and footprinting, passive and without traces.
  3. Initial access and footholdVia phishing, vishing or physical entry.
  4. Objective and proofLateral movement up to the objective, with timestamps.
  5. Report and risk assessmentChain, business impact, timeline, remediation plan.
  6. Debrief and purple team sessionReview session with your blue team.
3 to 8 days Active attack time to the objective. In total with scoping and report: 4 to 8 weeks.

What the final report contains

  • Two-page management summary: objective reached or not, by which route, and what it would have meant in a real incident
  • Attack narrative with times, screenshots and decisions, dead ends included
  • Detection timeline: every phase set against the alerts, tickets and responses of your SOC
  • Findings tied to the chain: would fixing this have broken the chain at this point?
  • MITRE ATT&CK mapping of all techniques and a remediation plan ranked by effort and impact
  • Appendix with indicators of compromise, so you can tell our traces in your logs apart from anyone else's

Module pentest or Red Teaming?

Module pentestRed Teaming
Guiding questionWhere are the vulnerabilities?How far does an attacker get?
ScopeOne system, one vectorWhole organisation, one objective
AnnouncementKnown and scheduledCovert, small circle informed
Detection and responseNot the focusCentral metric
Physical accessOnly if booked separatelyPart of the chain if the scope allows it

One does not rule out the other. Most Red Teaming clients have carried out module pentests beforehand.

Four formats, depending on maturity

The standard

Full-Scope Red Team

From research on the internet all the way to the objective, with no prior knowledge and no announcement.

For organisations with their own SOC or an MDR provider.

The quick start

Assumed Breach

Starts with what an attacker has after a successful phishing attack: a normal account on the network.

For a first test of internal detection.

Together, not covert

Purple Team

Attack and defence in the same room: we run technique after technique, and your team sharpens its detection right away.

For teams building a SIEM or closing gaps after a red team.

Regulatory

TIBER-EU-oriented Red Teaming

Red Teaming along the TIBER-EU phases, with threat intelligence up front and a control team. A dry run of the processes before a TLPT under DORA.

For banks, insurers and payment service providers.

Rules of engagement: the key rules

Letter of authorisation

Names the client, the scope, the time frame and the operators. On physical assignments our people carry it on them.

White cell

One or two people on your side who are in the know, reachable throughout the entire engagement. They can escalate and call a stop.

No destructive actions

No deleting, no encrypting, no denial of service. Where ransomware would be rolled out, we place a marker file.

Handling of data

No real customer or personnel data is copied out. We prove access by screenshot, hash value or test record.

No-go zones

Private devices, third-party systems outside the scope and safety-relevant OT controls remain excluded, unless you release them for testing.

Deconfliction

If your SOC reports an incident, the white cell checks with us within minutes whether it is ours. If it is not, we pause.

This is a selection. The complete rulebook, which covers abort criteria and a log of every single action among other things, is agreed with you in writing before the start.

The goal is never to show up your team or SOC. The debrief makes weaknesses visible without assigning blame.

Ready to be put to a real test?

In 30 minutes we clarify scope, objective and rules. Free of charge.

Book an initial call