Would we notice a determined attacker?
Red team operation
A red team operation is a covert, objective-based simulation of a real adversary against your organization. Instead of listing vulnerabilities, it answers whether an attacker could reach a specific goal without being detected, and how your people and tools responded along the way.
What you get
- Whether the objective was reached, and how
- Where detection and response held and where they failed
- A timeline your blue team can replay and learn from
Overview
Unlike a penetration test, a red team operation does not try to find every flaw. It has an objective, such as reaching a specific database or exfiltrating a defined data set without being caught, and emulates the tactics, techniques, and procedures of a chosen threat actor to get there. It is the truest test of your detection and response.
Scope
What is typically in scope. The final list is agreed with you before testing starts.
- Agreed objectives such as access to specific data, systems, or business processes
- Initial access through phishing, external exploitation, or assumed breach
- Physical intrusion (optional)
- Command and control infrastructure emulating a chosen threat actor
- Detection and response evaluation with a small trusted control group
- Purple team replay sessions after the operation
Methodology
Phases run in this order. Each one produces evidence that feeds the next.
Threat modelling
We agree on objectives, a threat actor profile, and rules of engagement with a small control group who know the test is running.
Initial access
Phishing, perimeter exploitation, or an assumed breach position, chosen to match the threat actor.
Persistence and evasion
We establish covert command and control and operate at the tempo of a real intrusion, avoiding detection where possible.
Objective pursuit
Lateral movement and privilege escalation toward the objective, with every action logged with timestamps for later replay.
Debrief and replay
A joint session with your defenders maps every step to MITRE ATT&CK, showing what was detected, what was missed, and why.
Deliverables
- Executive narrative of the operation and outcome
- Timestamped attack timeline mapped to MITRE ATT&CK
- Detection and response assessment by phase
- Technical findings enabling the path
- Purple team replay session
- Prioritized recommendations across people, process, and technology
Sample report excerpt
One finding, in the structure every finding follows. The content is illustrative.
Objective reached without detection over 11 days of activity
- Severity
- Critical
- Status
- Open, retest pending
- Affected assets
- Listed in appendix A
Impact
The operation obtained the agreed objective, a copy of a defined sensitive data set, with no alert raised or investigation opened during the engagement.
Evidence
Timestamped timeline of 64 actions from initial phishing access to exfiltration, correlated after the operation with security tooling that logged 9 of them and alerted on none.
Remediation
Tune detections for the observed techniques, add alerting on the specific gaps identified in the replay session, and rehearse the response playbook against the timeline.
Verification
Retested after remediation. Result and date are recorded here and reflected in the attestation letter.
Timeline
Typical duration
Typically 4 to 8 weeks including planning and debrief
What affects it
Operations run at a realistic tempo, which takes longer than a penetration test. Planning and infrastructure setup take one to two weeks before any activity begins.
Compliance drivers
Need this for an audit or renewal? This test provides accepted evidence for ISO 27001, Cyber insurance.
See the full requirement mappingFrequently asked questions
How is a red team different from a penetration test?
A penetration test aims to find as many flaws as possible in a defined scope. A red team pursues one objective covertly and tests whether your detection and response notice. It is a test of the whole program, not a list of vulnerabilities.
Who knows the test is running?
A small control group, usually two or three people. Your security operations team should not know, otherwise the detection results are meaningless.
How long does it take?
Typically four to eight weeks including planning, the operation itself, and the debrief.
Is a red team right for us?
It is most valuable once you run regular penetration tests and have detection tooling or a managed provider you want to validate. If not, an internal penetration test is usually the better first step.
What happens if you get caught?
That is a good result. We record the detection, agree with the control group whether to continue from a new position, and the report covers both the detection and what happened after.
Related
Often paired with
Internal penetration test
What damage can an insider do?
Assume the perimeter has failed. Find out what happens next.
Learn moreSocial engineering test
Will someone hand over the keys?
Phishing, vishing, and pretexting campaigns that measure your people.
Learn moreContinuous Threat Exposure Management
What is exposed right now, and does it matter?
A year-round testing program instead of an annual snapshot.
Learn moreReady to scope a red team operation?
Tell us about your environment and timelines. You will talk to the people who run the engagement and hear back within one business day.