Red team
Under written rules and in a controlled way, we follow the path a real attacker would take to reach an agreed objective. What we’re really measuring is how quickly you detect and respond.
- Duration
- 3–6 weeks
- Standard
- MITRE ATT&CK · TIBER-EU
- Deliverables
- Timeline, replay session and retest within 60 days
What we test
01
Objective and rules
The target asset and off-limits areas are agreed in writing.
02
Initial access
Approved phishing scenarios and the external surface.
03
Persistence and movement
How long we can keep moving without being noticed.
04
Physical access
Building and device security, if approved.
05
Detection metrics
Which steps were detected, and how quickly.
06
Joint review
A step-by-step replay with your blue team.
Gaps we see often
The ones we’ve run into most in recent engagements. You can’t know whether you have them until you test.
- Initial access after phishing goes unnoticedHigh
- Systems outside endpoint protection coverageHigh
- Multi-factor authentication open to MFA fatigueHigh
- Critical alerts with no ownerMedium
- Incident response plan that fails in practiceMedium
How it works
- 012 weeks
Planning
Objective, rules and the emergency escalation chain.
- 022–4 weeks
Operation
A realistic pace, with daily white team briefings.
- 031 week
Report and replay
Timeline and a joint session with the blue team.
- 04Within 60 days
Remediation retest
Closed gaps are tested again.
Frequently asked questions
Will our employees be told?
How is this different from a penetration test?
When are we ready for a red team?
Often paired with
Let’s take a free look first
Leave us your domain. Within 2 business days, we’ll review your external surface and send the priority risks and a recommended scope on a single page.
- 01Leave your email and domain.
- 02We review your external surface within two business days.
- 03You get a one-page summary and a recommended first step.
- 14
- Subdomains
- 6
- Exposed services
- B
- TLS grade
- 3 / 7
- Security headers
Top three risks
- 1Admin panel exposed to the internetHigh
- 2Outdated TLS version still supportedMedium
- 3Content Security Policy missingLow