Skip to content
AttackVector

Would we notice a determined attacker?

Red team operation

A red team operation is a covert, objective-based simulation of a real adversary against your organization. Instead of listing vulnerabilities, it answers whether an attacker could reach a specific goal without being detected, and how your people and tools responded along the way.

Objective basedTargets: People, process, technologyTypically 4 to 8 weeks including planning and debrief

What you get

  • Whether the objective was reached, and how
  • Where detection and response held and where they failed
  • A timeline your blue team can replay and learn from

Overview

Unlike a penetration test, a red team operation does not try to find every flaw. It has an objective, such as reaching a specific database or exfiltrating a defined data set without being caught, and emulates the tactics, techniques, and procedures of a chosen threat actor to get there. It is the truest test of your detection and response.

Scope

What is typically in scope. The final list is agreed with you before testing starts.

  • Agreed objectives such as access to specific data, systems, or business processes
  • Initial access through phishing, external exploitation, or assumed breach
  • Physical intrusion (optional)
  • Command and control infrastructure emulating a chosen threat actor
  • Detection and response evaluation with a small trusted control group
  • Purple team replay sessions after the operation

Methodology

Phases run in this order. Each one produces evidence that feeds the next.

  1. Threat modelling

    We agree on objectives, a threat actor profile, and rules of engagement with a small control group who know the test is running.

  2. Initial access

    Phishing, perimeter exploitation, or an assumed breach position, chosen to match the threat actor.

  3. Persistence and evasion

    We establish covert command and control and operate at the tempo of a real intrusion, avoiding detection where possible.

  4. Objective pursuit

    Lateral movement and privilege escalation toward the objective, with every action logged with timestamps for later replay.

  5. Debrief and replay

    A joint session with your defenders maps every step to MITRE ATT&CK, showing what was detected, what was missed, and why.

Deliverables

  • Executive narrative of the operation and outcome
  • Timestamped attack timeline mapped to MITRE ATT&CK
  • Detection and response assessment by phase
  • Technical findings enabling the path
  • Purple team replay session
  • Prioritized recommendations across people, process, and technology

Sample report excerpt

One finding, in the structure every finding follows. The content is illustrative.

AttackVector · Red team operation · Technical findingsIllustrative excerpt
CriticalFinding 1 of 19

Objective reached without detection over 11 days of activity

Severity
Critical
Status
Open, retest pending
Affected assets
Listed in appendix A

Impact

The operation obtained the agreed objective, a copy of a defined sensitive data set, with no alert raised or investigation opened during the engagement.

Evidence

Timestamped timeline of 64 actions from initial phishing access to exfiltration, correlated after the operation with security tooling that logged 9 of them and alerted on none.

Screenshot and request/response evidence appear here

Remediation

Tune detections for the observed techniques, add alerting on the specific gaps identified in the replay session, and rehearse the response playbook against the timeline.

Verification

Retested after remediation. Result and date are recorded here and reflected in the attestation letter.

Every finding follows this structure.Download the full sample report

Timeline

Typical duration

Typically 4 to 8 weeks including planning and debrief

What affects it

Operations run at a realistic tempo, which takes longer than a penetration test. Planning and infrastructure setup take one to two weeks before any activity begins.

Compliance drivers

Need this for an audit or renewal? This test provides accepted evidence for ISO 27001, Cyber insurance.

See the full requirement mapping

Frequently asked questions

How is a red team different from a penetration test?

A penetration test aims to find as many flaws as possible in a defined scope. A red team pursues one objective covertly and tests whether your detection and response notice. It is a test of the whole program, not a list of vulnerabilities.

Who knows the test is running?

A small control group, usually two or three people. Your security operations team should not know, otherwise the detection results are meaningless.

How long does it take?

Typically four to eight weeks including planning, the operation itself, and the debrief.

Is a red team right for us?

It is most valuable once you run regular penetration tests and have detection tooling or a managed provider you want to validate. If not, an internal penetration test is usually the better first step.

What happens if you get caught?

That is a good result. We record the detection, agree with the control group whether to continue from a new position, and the report covers both the detection and what happened after.

Ready to scope a red team operation?

Tell us about your environment and timelines. You will talk to the people who run the engagement and hear back within one business day.