Think Like the Attacker
Red Team Assessment
We act like a determined attacker with a real objective, then show you exactly how far we get and how you can stop it. This is not a checklist scan. It is a controlled, intelligence-led operation that tests your defences the way a real adversary would.
See the engagement path, 5 phasesSee the full Managed Services service index
Overview
A red team assessment measures how your people, processes and technology hold up against a focused attacker. We agree an objective with you, such as reaching a crown-jewel system or moving funds, then work toward it using the same techniques real threat actors use. Along the way we test detection and response, not just prevention. You finish with a clear picture of what worked, what did not, and where a small change would have stopped us cold.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
5 Phases, 5 Named Handovers
Flow
Flow chart of the Red Team Assessment engagement, 5 phases in order, each one selectable. Phase 1, Objectives and Rules of Engagement. We agree the goals, the systems in scope, the tactics allowed and the safety limits. Everyone signs off before anything starts, so the exercise is realistic and controlled. Activities: Define the crown-jewel objective and success criteria with your leadership; Set the scope, allowed tactics and out-of-bounds systems; Agree emergency stop conditions and named trusted agents; Establish deconfliction and communication channels for live testing; Capture written authorisation and rules of engagement sign-off. Hands over Signed Rules of Engagement and Scope Document. Phase 2, Reconnaissance. We map your public footprint, staff, technology and supply chain to build an attack plan. Most of this looks exactly like what an outside attacker can see. Activities: Enumerate internet-facing hosts, domains and cloud tenants; Harvest employee names, roles and email formats from public sources; Profile suppliers and third parties with access to your estate; Collect leaked credentials from breach data for your domains. Hands over Target Profile and Attack Plan. Phase 3, Initial Access. We gain a foothold through the path a real adversary would choose, including phishing, pretext calls and other social engineering, alongside exposed services and weak credentials. Activities: Design pretexts matched to real lures your staff receive; Run targeted phishing and pretext calls against selected roles; Test exposed services for weak or reused credentials; Establish a resilient command and control channel. Hands over Initial Access Record with Evidence. Phase 4, Lateral Movement and Objectives. From the foothold we escalate, move across your network and work toward the agreed objective, capturing evidence at each step without disrupting your operations. Activities: Map Active Directory attack paths to privileged accounts; Escalate privileges and harvest credentials from compromised hosts; Pivot toward the agreed crown-jewel objective; Capture timestamped proof at every milestone. Hands over Attack Narrative and Evidence Pack. Phase 5, Detection Scorecard and Purple-Team Replay. We score which actions your team detected, missed or blocked. Then we replay the key steps alongside your defenders so they can tune alerts and close the gaps for good. Activities: Score every action as detected, missed or blocked; Map the operation to MITRE ATT&CK coverage; Replay key steps live alongside your defenders; Agree detection rules and response fixes with owners. Hands over Detection Scorecard. Each phase begins from the artefact the phase before it produced.
Phase 01 Objectives and Rules of Engagement
We agree the goals, the systems in scope, the tactics allowed and the safety limits. Everyone signs off before anything starts, so the exercise is realistic and controlled.
What Happens In This Phase
- Define the crown-jewel objective and success criteria with your leadership
- Set the scope, allowed tactics and out-of-bounds systems
- Agree emergency stop conditions and named trusted agents
- Establish deconfliction and communication channels for live testing
- Capture written authorisation and rules of engagement sign-off
The Handover
Signed Rules of Engagement and Scope Document
The next phase starts from this.
Phase 01 Objectives and Rules of Engagement
We agree the goals, the systems in scope, the tactics allowed and the safety limits. Everyone signs off before anything starts, so the exercise is realistic and controlled.
What Happens In This Phase
- Define the crown-jewel objective and success criteria with your leadership
- Set the scope, allowed tactics and out-of-bounds systems
- Agree emergency stop conditions and named trusted agents
- Establish deconfliction and communication channels for live testing
- Capture written authorisation and rules of engagement sign-off
The Handover
Signed Rules of Engagement and Scope Document
The next phase starts from this.
- 01
Objectives and Rules of Engagement
We agree the goals, the systems in scope, the tactics allowed and the safety limits. Everyone signs off before anything starts, so the exercise is realistic and controlled.
OutputSigned Rules of Engagement and Scope DocumentActivities
- Define the crown-jewel objective and success criteria with your leadership
- Set the scope, allowed tactics and out-of-bounds systems
- Agree emergency stop conditions and named trusted agents
- Establish deconfliction and communication channels for live testing
- Capture written authorisation and rules of engagement sign-off
- 02
Reconnaissance
We map your public footprint, staff, technology and supply chain to build an attack plan. Most of this looks exactly like what an outside attacker can see.
OutputTarget Profile and Attack PlanActivities
- Enumerate internet-facing hosts, domains and cloud tenants
- Harvest employee names, roles and email formats from public sources
- Profile suppliers and third parties with access to your estate
- Collect leaked credentials from breach data for your domains
- 03
Initial Access
We gain a foothold through the path a real adversary would choose, including phishing, pretext calls and other social engineering, alongside exposed services and weak credentials.
OutputInitial Access Record with EvidenceActivities
- Design pretexts matched to real lures your staff receive
- Run targeted phishing and pretext calls against selected roles
- Test exposed services for weak or reused credentials
- Establish a resilient command and control channel
- 04
Lateral Movement and Objectives
From the foothold we escalate, move across your network and work toward the agreed objective, capturing evidence at each step without disrupting your operations.
OutputAttack Narrative and Evidence PackActivities
- Map Active Directory attack paths to privileged accounts
- Escalate privileges and harvest credentials from compromised hosts
- Pivot toward the agreed crown-jewel objective
- Capture timestamped proof at every milestone
- 05
Detection Scorecard and Purple-Team Replay
We score which actions your team detected, missed or blocked. Then we replay the key steps alongside your defenders so they can tune alerts and close the gaps for good.
OutputDetection ScorecardActivities
- Score every action as detected, missed or blocked
- Map the operation to MITRE ATT&CK coverage
- Replay key steps live alongside your defenders
- Agree detection rules and response fixes with owners
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Red Team Assessment scope, running left to right in three stages. Stage one, what we run, 9 tools and techniques: Cobalt Strike, Sliver, BloodHound, Nmap, GoPhish, Metasploit, Impacket, Responder, Mimikatz. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: MITRE ATT&CK, TIBER-EU, PTES, CBEST, NIST SP 800-115, OSSTMM.
What We Run
9 tools
- Cobalt Strike
- Sliver
- Impacket
- Responder
- Mimikatz
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
6 standards
- TIBER-EUECB
- PTES
- CBESTBank of England
- OSSTMMISECOM
Deliverables
What You Receive
- Attack narrative with a step-by-step timeline of the operation
- Detection and response scorecard against MITRE ATT&CK
- Prioritised findings with practical fixes
- Purple-team replay session with your defenders
- Executive briefing for leadership and the board
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
How is a red team different from a penetration test?
A penetration test finds as many vulnerabilities as it can in a defined scope. A red team picks one realistic objective and tests whether your whole defence, including detection and response, can stop a focused attacker from reaching it.
Will this disrupt our business?
No. We agree safety limits up front and work carefully to avoid downtime. If we ever risk affecting a live system, we pause and check with your named contact first.
Do our defenders know it is happening?
Usually only a small trusted group knows, so the response is genuine. You choose how many people are aware, and we can run it fully covert or as a known exercise.
Keep Moving Through Managed Services
Service 1 of 7 in this practice area
Practice Area
More in Managed Services
- SOC as a ServiceA 24/7 security operations centre run by our analysts
- vCISOSenior security leadership on demand, without a full-time hire
- vDPOA data protection officer as a service for the DPDP Act and beyond
- Phishing SimulationsSafe, realistic phishing tests that build lasting instincts
- Awareness TrainingsSecurity training your people actually remember and use
- Digital and Cyber ForensicsSound investigation and evidence when something has gone wrong