Threat modeling
Before any testing starts, we identify which real-world groups target your sector and align the engagement to their known techniques. A ransomware affiliate behaves differently from a nation-state actor. Your scenario should reflect the actual threat.
External reconnaissance
OSINT against your public footprint — employee profiles, third-party vendors, exposed APIs, leaked credentials. This is the same work a real attacker does before touching your network.
Initial access
Realistic vectors: phishing with modern evasion, valid accounts from breach data, external service exploitation where in scope. We document what worked and, more importantly, what your detection did when it happened.
Privilege escalation & lateral movement
Kerberos abuse, ACL misconfigurations, credential reuse, service account takeover. Every step is logged and mapped to an ATT&CK technique so your blue team can trace what they missed.
Persistence & objectives
We agree on objectives in advance — domain admin, financial system access, sensitive data location. The engagement ends when the objective is met or the time is exhausted, not when a script finishes.
Purple team collaboration
If your team wants it, we work alongside your defenders during and after the engagement. Detection rules get tuned. Telemetry gets reviewed. The gap between what we did and what you saw becomes the report.
Debrief and remediation
A written report with findings ranked by exploitability and business impact. Each finding includes the technique ID, the evidence, and a concrete fix. Then a walkthrough with your security leadership.
We do not guarantee you will not be breached. No engagement can. What we provide is a realistic assessment of how an adversary would move through your environment today, and what to fix first. If that answer is uncomfortable, that is the point.
Week 0 — Scoping call
45 to 90 minutes. Agree on scope, objectives, rules of engagement, points of contact, and emergency stop conditions. We sign your NDA. You sign our RoE.
Week 1 — Threat modeling & recon
OSINT, target profiling, and the emulation plan. You see the plan before any active testing starts.
Weeks 2–5 — Active engagement
Testing runs against agreed scope. We communicate through an encrypted channel. Findings are shared live, not held for the final report.
Week 6 — Report & debrief
Written report, purple team debrief, and a remediation roadmap. Optional retest available within 90 days.
What we do not do. We do not deliver a raw scanner report renamed as red team. We do not run automated tools and call it adversary emulation. We do not touch production data outside agreed scope. Every action is authorized, documented, and reversible.