Red Teaming

Not 'where are the gaps'. But: how far would a real attacker get?

Module-based pentests find individual weaknesses. Red Teaming chains them together — recon, phishing, physical access, Active Directory — up to one defined objective: domain admin, customer database, production control. Covert, unscheduled, tested against your actual blue team.

Avg. active attack duration to reach objective 3–8 days Full engagement incl. scoping & report: 4–8 weeks
CRTO & CRTP certified team Objective-based, not a checklist scan Covert, usually only C-level is informed
Live simulation

What an engagement looks like in real time

This simulation shows a typical path — from first reconnaissance to reaching the objective. Real engagements usually run over days to weeks, not minutes.

Engagement simulation LIVE
Time to objective 00:00:00
🔎
Recon
✉️
Initial access
🚪
Physical foothold
🖥️
Internal access
🔑
Privilege escalation
🎯
Objective reached

Simplified illustration of a realistic attack path. Actual duration, sequence, and vectors depend on the agreed scope.

Not a marketing chart — a real report sample

Download an anonymized sample report and see for yourself how thoroughly we document an attack chain.

Download sample report
The difference

Why a module-based pentest alone isn't enough

Isolated vs. chained

A single finding looks harmless — a chain doesn't

An exposed account, an unguarded door, one phishing email: each often rated 'medium' on its own. Only the chain — phishing, stolen credentials, physical access, lateral movement — reveals the real business impact, the same path a real attacker would take.

Announced vs. covert

Does your security team even know when you're being tested?

Module-based pentests are usually scheduled and known in advance. Red Teaming additionally tests whether your SOC or blue team notices a real, unannounced attack at all — and how fast they respond.

Breadth vs. depth

Testing everything a little, or pursuing one goal for real?

Modules systematically cover the breadth of your attack surface. Red Teaming pursues one defined objective using every realistically available means — exactly like a real, motivated attacker would.

Positioning

Module-based pentest or red teaming — what fits you?

Aspect Module-based pentest Red teaming
Guiding question Where are the vulnerabilities? How far does an attacker get?
Scope Single system / single vector Entire organization, one defined objective
Awareness Known and scheduled Covert, usually only C-level informed
Tests detection & response Not the focus A core part of the engagement
Best suited for Compliance evidence, annual cadence Security maturity beyond compliance
Physical access Only if booked separately Included in the attack chain by default

The two aren't mutually exclusive: most of our red team clients have already run module-based pentests with us or other providers and now want to know whether their detection actually holds up in a real incident.

Process

A red team engagement — step by step

Access Granted logo
Red Teaming
🖊️

Scoping & rules of engagement

Objective, boundaries, authorized contacts, and escalation paths are defined together — including a letter of authorization.

Reconnaissance

OSINT, footprinting, and planning of realistic attack paths — passive, without leaving traces.

🔍

Initial access & foothold

Through phishing, vishing, or physical access, we establish an initial, persistent foothold.

⚔️
🎯

Lateral movement up to the agreed objective — with complete, logged evidence of every step.

Objective & proof

Report & risk assessment

Full reconstruction of the attack chain, business impact assessment, and prioritized recommendations.

📘

Debrief & purple team session

A joint debrief with your blue team — what was detected, what wasn't, and why.

🤝

Engagement steps

🖊️
Scoping & RoE
Define objective and boundaries.
🔍
Recon
Passive reconnaissance.
⚔️
Initial access
First foothold, covertly.
🎯
Objective & proof
Lateral movement to the objective.
📘
Report
Attack chain & recommendations.
🤝
Debrief
Joint review with your blue team.

The goal isn't simply 'getting in' — it's proving whether your organization detects and stops a real attack.

Why Access Granted

Genuine red team experience, not a bolted-on add-on

Physical-to-cyber from a single provider

Most red team providers stay purely digital — phishing and network access. With over 100 physical pentests delivered, we bring real physical access in as a full part of the attack chain: from tailgating to a rogue device in the server room.

CRTO & CRTP certified

Objective-based red teaming and Active Directory attack chains are their own discipline with their own certifications — not simply 'more pentesting'.

An investigator's perspective

Our founder's background is in cybercrime investigation at the German police — attacker psychology and offender profiling feed directly into how we plan an attack.

Debrief, not exposure

The goal is never to embarrass your team or SOC. The joint debrief makes weaknesses visible without assigning blame.

Discuss your engagement
RED TEAM BLUE TEAM

40

+

red team engagements delivered

3

vectors tested per engagement (human, physical, technical)

78

%

engagements with undetected access to the objective

100

+

physical pentests delivered, the foundation of our attack chains

FAQ

Red teaming — your questions

That's up to you. By default, only a very small circle (usually C-level and one 'white cell' contact) is informed — that's exactly what makes the test meaningful for evaluating your detection and response. Partially announced variants are possible on request.

That's a success, not a reason to stop — detection is a metric, not a failed test. We escalate in a controlled way according to pre-defined rules and report detection as a standalone result.

A pentest systematically covers the breadth of a defined system or vector. Red teaming pursues one concrete objective using every realistically available means — technical, human, and physical access combined — and additionally tests detection and response.

Module-based pentests are the foundation — they surface individual gaps. Red teaming is the logical next step for organizations that have already reached a certain level of security maturity and want to know whether it actually holds in a real incident.

Physical access isn't an add-on for us — it's a core part of the attack chain whenever it fits the scope. With over 100 physical pentests delivered, we bring specialized experience: from tailgating and lockpicking to RFID cloning and rogue devices. Many red team providers stay purely digital; that's exactly the gap we close.

A joint debrief with your internal security team: we walk through the attack chain step by step, show what was detected and what wasn't, and work together on concrete detection and response improvements.

Together, during scoping — usually one concrete 'crown jewel': domain admin, a specific database, access to a production control system. The objective is based on your real threat model, not a generic template.

Before every engagement we issue a letter of authorization with a clearly defined scope, authorized contacts, and emergency contacts. Our operators carry this document with them throughout the engagement.

Once basic security measures — ideally including initial module-based pentests — are already in place. Red teaming tests the effectiveness of your overall system, which only makes sense once there's something to detect and stop in the first place.


© AccessGranted X GmbH