Think Like the Attacker
Red Team Assessment
We act like a determined attacker with a real objective, then show you exactly how far we get and how you can stop it. This is not a checklist scan. It is a controlled, intelligence-led operation that tests your defences the way a real adversary would.
See the engagement path, 5 phasesSee the full Managed Services service index
Overview
A red team assessment measures how your people, processes and technology hold up against a focused attacker. We agree an objective with you, such as reaching a crown-jewel system or moving funds, then work toward it using the same techniques real threat actors use. Along the way we test detection and response, not just prevention. You finish with a clear picture of what worked, what did not, and where a small change would have stopped us cold.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
5 Phases, 5 Named Handovers
Flow
Flow chart of the Red Team Assessment engagement, 5 phases in order, each one selectable. Phase 1, Objectives and Rules of Engagement. We agree the goals, the systems in scope, the tactics allowed and the safety limits. Everyone signs off before anything starts, so the exercise is realistic and controlled. Activities: Define the crown-jewel objective and success criteria with your leadership; Set the scope, allowed tactics and out-of-bounds systems; Agree emergency stop conditions and named trusted agents; Establish deconfliction and communication channels for live testing; Capture written authorisation and rules of engagement sign-off. Hands over Signed Rules of Engagement and Scope Document. Phase 2, Reconnaissance. We map your public footprint, staff, technology and supply chain to build an attack plan. Most of this looks exactly like what an outside attacker can see. Activities: Enumerate internet-facing hosts, domains and cloud tenants; Harvest employee names, roles and email formats from public sources; Profile suppliers and third parties with access to your estate; Collect leaked credentials from breach data for your domains. Hands over Target Profile and Attack Plan. Phase 3, Initial Access. We gain a foothold through the path a real adversary would choose, including phishing, pretext calls and other social engineering, alongside exposed services and weak credentials. Activities: Design pretexts matched to real lures your staff receive; Run targeted phishing and pretext calls against selected roles; Test exposed services for weak or reused credentials; Establish a resilient command and control channel. Hands over Initial Access Record with Evidence. Phase 4, Lateral Movement and Objectives. From the foothold we escalate, move across your network and work toward the agreed objective, capturing evidence at each step without disrupting your operations. Activities: Map Active Directory attack paths to privileged accounts; Escalate privileges and harvest credentials from compromised hosts; Pivot toward the agreed crown-jewel objective; Capture timestamped proof at every milestone. Hands over Attack Narrative and Evidence Pack. Phase 5, Detection Scorecard and Purple-Team Replay. We score which actions your team detected, missed or blocked. Then we replay the key steps alongside your defenders so they can tune alerts and close the gaps for good. Activities: Score every action as detected, missed or blocked; Map the operation to MITRE ATT&CK coverage; Replay key steps live alongside your defenders; Agree detection rules and response fixes with owners. Hands over Detection Scorecard. Each phase begins from the artefact the phase before it produced.
Phase 01 Objectives and Rules of Engagement
We agree the goals, the systems in scope, the tactics allowed and the safety limits. Everyone signs off before anything starts, so the exercise is realistic and controlled.
What Happens In This Phase
- Define the crown-jewel objective and success criteria with your leadership
- Set the scope, allowed tactics and out-of-bounds systems
- Agree emergency stop conditions and named trusted agents
- Establish deconfliction and communication channels for live testing
- Capture written authorisation and rules of engagement sign-off
The Handover
Signed Rules of Engagement and Scope Document
The next phase starts from this.
Phase 01 Objectives and Rules of Engagement
We agree the goals, the systems in scope, the tactics allowed and the safety limits. Everyone signs off before anything starts, so the exercise is realistic and controlled.
What Happens In This Phase
- Define the crown-jewel objective and success criteria with your leadership
- Set the scope, allowed tactics and out-of-bounds systems
- Agree emergency stop conditions and named trusted agents
- Establish deconfliction and communication channels for live testing
- Capture written authorisation and rules of engagement sign-off
The Handover
Signed Rules of Engagement and Scope Document
The next phase starts from this.
- 01
Objectives and Rules of Engagement
We agree the goals, the systems in scope, the tactics allowed and the safety limits. Everyone signs off before anything starts, so the exercise is realistic and controlled.
OutputSigned Rules of Engagement and Scope DocumentActivities
- Define the crown-jewel objective and success criteria with your leadership
- Set the scope, allowed tactics and out-of-bounds systems
- Agree emergency stop conditions and named trusted agents
- Establish deconfliction and communication channels for live testing
- Capture written authorisation and rules of engagement sign-off
- 02
Reconnaissance
We map your public footprint, staff, technology and supply chain to build an attack plan. Most of this looks exactly like what an outside attacker can see.
OutputTarget Profile and Attack PlanActivities
- Enumerate internet-facing hosts, domains and cloud tenants
- Harvest employee names, roles and email formats from public sources
- Profile suppliers and third parties with access to your estate
- Collect leaked credentials from breach data for your domains
- 03
Initial Access
We gain a foothold through the path a real adversary would choose, including phishing, pretext calls and other social engineering, alongside exposed services and weak credentials.
OutputInitial Access Record with EvidenceActivities
- Design pretexts matched to real lures your staff receive
- Run targeted phishing and pretext calls against selected roles
- Test exposed services for weak or reused credentials
- Establish a resilient command and control channel
- 04
Lateral Movement and Objectives
From the foothold we escalate, move across your network and work toward the agreed objective, capturing evidence at each step without disrupting your operations.
OutputAttack Narrative and Evidence PackActivities
- Map Active Directory attack paths to privileged accounts
- Escalate privileges and harvest credentials from compromised hosts
- Pivot toward the agreed crown-jewel objective
- Capture timestamped proof at every milestone
- 05
Detection Scorecard and Purple-Team Replay
We score which actions your team detected, missed or blocked. Then we replay the key steps alongside your defenders so they can tune alerts and close the gaps for good.
OutputDetection ScorecardActivities
- Score every action as detected, missed or blocked
- Map the operation to MITRE ATT&CK coverage
- Replay key steps live alongside your defenders
- Agree detection rules and response fixes with owners
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Red Team Assessment scope, running left to right in three stages. Stage one, what we run, 9 tools and techniques: Cobalt Strike, Sliver, BloodHound, Nmap, GoPhish, Metasploit, Impacket, Responder, Mimikatz. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: MITRE ATT&CK, TIBER-EU, PTES, CBEST, NIST SP 800-115, OSSTMM.
What We Run
9 tools
- Cobalt Strike
- Sliver
- BloodHound
- Nmap
- GoPhish
- Metasploit
- Impacket
- Responder
- Mimikatz
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
6 standards
- MITRE ATT&CK
- TIBER-EUECB
- PTES
- CBESTBank of England
- NIST SP 800-115
- OSSTMMISECOM
Deliverables
What You Receive
- Attack narrative with a step-by-step timeline of the operation
- Detection and response scorecard against MITRE ATT&CK
- Prioritised findings with practical fixes
- Purple-team replay session with your defenders
- Executive briefing for leadership and the board
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
How is a red team different from a penetration test, and which should we run first?
A penetration test enumerates weaknesses across a defined scope; a red team tests whether your defence stops a focused attacker reaching one agreed objective. The practical difference is what gets measured. A test is judged on coverage: how much of the application or network segment was examined and how many issues were found. A red team is judged on the path taken and on what your defenders saw while we took it, so people, process and detection are all in the measurement. That means a red team deliberately leaves findings on the table. If one route reaches the crown-jewel objective, we do not enumerate the other four. Most organisations need both, and in that order, because an unfixed obvious flaw turns the exercise into a short and uninformative story. Our guide comparing red teaming with penetration testing sets the two side by side if you are deciding between them.
What is in scope, what is out of scope, and what do we have to supply?
Scope is written down and signed before anything starts, and it names both what we may reach for and what we must leave alone. Usually in scope: your internet-facing estate, staff who can be reached by phishing or pretext calls, the identity and Active Directory paths between a foothold and the objective, cloud tenants you control, and suppliers you have the authority to include. Usually out of scope: systems you do not own or cannot authorise, anything a supplier contract forbids, denial-of-service and destructive actions, data exfiltration beyond the proof needed, and any host your team marks out of bounds. Physical intrusion and on-site entry are out of scope and are not part of this engagement unless separately agreed in writing. From you we need the asset list, the named trusted agents, and written authorisation from someone empowered to give it. Where an asset sits with a provider, we need their permission in writing too.
What do the rules of engagement actually control, and how do you keep this safe?
The rules of engagement fix the objective, the tactics allowed, the safety limits and the stop conditions, and both sides sign before any testing begins. Four controls do most of the work. A small group of named trusted agents knows the exercise is running, so your team can confirm that an alert is us and not a genuine intruder. A deconfliction channel stays open throughout for exactly that question. Emergency stop conditions are agreed in advance and either side can invoke them without argument. If an action risks affecting a live system, we pause and check with your named contact rather than proceeding and apologising afterwards. Each action we take is logged with timestamps so it can be attributed later. You also decide how covert the exercise is, and that decision is written into the rules of engagement before testing starts rather than revisited halfway through.
What evidence does the report carry, and what does it not claim?
The report is built so each claim can be checked against your own logs. The attack narrative is a step-by-step timeline with timestamped proof captured at each milestone, so you can line up what we did against what your telemetry recorded. Beside it sits a detection scorecard grading each action we take as detected, missed or blocked and mapped to MITRE ATT&CK, which is the section your defenders should argue with. Findings are prioritised with practical fixes rather than generic advice, and a separate executive briefing is written for leadership and the board. The purple-team replay runs the key steps again in front of your team so they can watch the alerts arrive and tune rules while we are still there. What the report does not claim is completeness: it documents the paths we took, not every path that exists.
When is a red team premature for an organisation like ours?
A red team is premature when you already know the answer will be yes. If there is no central logging, nobody watching alerts outside office hours, unpatched internet-facing services or no asset inventory, we will reach the objective and the report will tell you things you could have written yourself. The exercise earns its place when you have controls you believe in and want tested, and defenders who will act on a scorecard. Signs you are ready: testing has been running long enough that findings close rather than accumulate, someone owns detection, and leadership will fund what the replay surfaces. Signs you are not: this is your first security engagement, or an auditor asked for evidence and a red team looked like the strongest answer. In that case a penetration test and a configuration review give you more, and we will say so on the scoping call.
Related Reading
Articles on Red Team Assessment
Keep Moving Through Managed Services
Service 1 of 9 in this practice area
Practice Area
More in Managed Services
- SOC as a ServiceA 24/7 security operations centre run by our analysts
- Attack Surface ManagementRecurring discovery of what you expose to the internet, and what is wrong with it
- Dark Web MonitoringAnalyst-validated monitoring for leaked credentials, documents and brand abuse
- vCISOSenior security leadership on demand, without a full-time hire
- vDPOA data protection officer as a service for the DPDP Act and beyond
- Phishing SimulationsSafe, realistic phishing tests that build lasting instincts
- Awareness TrainingsSecurity training your people actually remember and use
- Digital and Cyber ForensicsSound investigation and evidence when something has gone wrong