Skip to main content

Service

Red Team Operations

A goal-driven, full-scope simulation of a determined adversary against live defences.

A penetration test asks what is vulnerable. A red team engagement asks whether you would notice, and how far somebody would get before you did. It is scoped by objective rather than by asset list: reach the payment system, obtain the customer database, get domain admin. Everything in bounds is available to reach it, and the defenders are usually not told it is happening.

How this works

Objectives agreed with a small group

The engagement is defined by what constitutes success, agreed with a handful of people who know it is running. That group exists for a practical reason: somebody has to be reachable to confirm that an alarming event is the exercise and not a real intrusion, without that call going to the whole security team and ending the test.

Reconnaissance and initial access

Open sources first: what the organisation publishes about its people, technology and processes. Initial access is then whichever route is realistic for the threat being modelled, which is usually credential-based rather than exploit-based. Where phishing is in scope it is used as a real actor would, against a small number of well-chosen recipients rather than everybody.

Operating quietly

The point is to test detection, so the work is done in a way that gives your team a genuine chance to catch it. Tooling and tradecraft are chosen to look like ordinary activity, and each significant step is logged with a timestamp so that afterwards the two timelines, what was done and what was detected, can be laid alongside each other.

The debrief is the deliverable

The report is a narrative of the operation with times, not a findings table. Where detection worked, that is recorded as clearly as where it did not. The most useful hour is usually the joint session afterwards, walking the defenders through what happened against what their tooling showed, because the gap between those two is the actual product.

What we look for

  • Whether initial access is detected at all, and how long it takes
  • Whether lateral movement between systems produces an alert or passes as normal administration
  • Whether privilege escalation and credential access are visible in the telemetry you already collect
  • Whether data staging and exfiltration trigger anything, at what volume and over which channels
  • Whether the response process works under real conditions: who is called, how quickly, and with what authority to act
  • Which controls were bought, deployed and never tuned to the point of firing

What you get

  • An operation narrative with timestamps for every significant action
  • A side-by-side of what was done against what your tooling recorded
  • Specific detection gaps, with the telemetry that would have caught each one
  • Named strengths, because a report that only lists failures gets dismissed
  • A joint debrief with the defending team

What this does not include

  • Anything outside the rules of engagement, which are written down and signed before the work starts
  • Actual destruction, encryption or exfiltration of real data: objectives are proven by access, not by taking anything
  • Testing that continues after a genuine incident is suspected; the exercise pauses so the real thing gets attention
  • Physical intrusion or social engineering of staff unless explicitly scoped in

Questions people ask

Are we ready for a red team engagement?
If you have never had a penetration test, probably not. A red team exercise is a test of detection and response, and if there is little to detect with, the result is a long report saying so at considerable expense. The honest sequence is assessment, then penetration testing, then red teaming once there is a security function whose performance is worth measuring.
Who should know it is happening?
As few people as the situation allows, and always at least one person who can confirm the exercise if something escalates. Typically that is a security leader and an executive sponsor. The defending team not knowing is the point.
What happens if you are caught?
That is a good outcome and it is written up as one. Depending on the objectives the exercise may pause, change approach, or continue from a new position, all of which is agreed in advance rather than improvised.