Overview
Penetration tests find vulnerabilities. Red team engagements answer a different question: if a capable adversary targeted us, would we notice — and how quickly could we respond?
We agree crown-jewel objectives with a small white team, then pursue them using realistic techniques across people, process and technology while avoiding detection. The outcome is a clear narrative of the attack, every point where your defences did or didn't respond, and a prioritised plan to close detection gaps.
For teams building or maturing a SOC, our purple team option runs techniques collaboratively with your defenders so every gap becomes an immediate detection improvement.
What's included
Our approach
- Objectives & rules of engagementCrown jewels, constraints, legal authorisation and white-team escalation.
- Threat modellingAdversary profiles relevant to your sector and geography.
- Campaign executionMulti-week operation with continuous white-team communication.
- Detection analysisCorrelation of our activity with your logs and alerts.
- Debrief & purple workshopJoint replay with defenders and a detection improvement roadmap.
What you receive
- Executive attack narrative
- MITRE ATT&CK technique heat map
- Detection and response timeline
- Prioritised detection engineering backlog
- Optional purple team workshop
Standards & frameworks
- MITRE ATT&CK
- TIBER-EU style methodology
- NIST CSF 2.0
- DORA TLPT (where applicable)
Frequently asked questions
Are we ready for a red team?
You get the most value once you run regular penetration tests, have centralised logging and someone monitoring alerts. If not, we will recommend starting with penetration testing or a purple team.
How long does an engagement take?
Typically four to twelve weeks including planning, execution and reporting.
Will the red team disrupt the business?
No. We operate under strict rules of engagement, avoid destructive actions, and the white team can pause activity at any time.