Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Managed Services7 services in this practice area

Think Like the Attacker

Red Team Assessment

We act like a determined attacker with a real objective, then show you exactly how far we get and how you can stop it. This is not a checklist scan. It is a controlled, intelligence-led operation that tests your defences the way a real adversary would.

See the engagement path, 5 phasesSee the full Managed Services service index

Overview

A red team assessment measures how your people, processes and technology hold up against a focused attacker. We agree an objective with you, such as reaching a crown-jewel system or moving funds, then work toward it using the same techniques real threat actors use. Along the way we test detection and response, not just prevention. You finish with a clear picture of what worked, what did not, and where a small change would have stopped us cold.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

5 Phases, 5 Named Handovers

Flow

Flow chart of the Red Team Assessment engagement, 5 phases in order, each one selectable. Phase 1, Objectives and Rules of Engagement. We agree the goals, the systems in scope, the tactics allowed and the safety limits. Everyone signs off before anything starts, so the exercise is realistic and controlled. Activities: Define the crown-jewel objective and success criteria with your leadership; Set the scope, allowed tactics and out-of-bounds systems; Agree emergency stop conditions and named trusted agents; Establish deconfliction and communication channels for live testing; Capture written authorisation and rules of engagement sign-off. Hands over Signed Rules of Engagement and Scope Document. Phase 2, Reconnaissance. We map your public footprint, staff, technology and supply chain to build an attack plan. Most of this looks exactly like what an outside attacker can see. Activities: Enumerate internet-facing hosts, domains and cloud tenants; Harvest employee names, roles and email formats from public sources; Profile suppliers and third parties with access to your estate; Collect leaked credentials from breach data for your domains. Hands over Target Profile and Attack Plan. Phase 3, Initial Access. We gain a foothold through the path a real adversary would choose, including phishing, pretext calls and other social engineering, alongside exposed services and weak credentials. Activities: Design pretexts matched to real lures your staff receive; Run targeted phishing and pretext calls against selected roles; Test exposed services for weak or reused credentials; Establish a resilient command and control channel. Hands over Initial Access Record with Evidence. Phase 4, Lateral Movement and Objectives. From the foothold we escalate, move across your network and work toward the agreed objective, capturing evidence at each step without disrupting your operations. Activities: Map Active Directory attack paths to privileged accounts; Escalate privileges and harvest credentials from compromised hosts; Pivot toward the agreed crown-jewel objective; Capture timestamped proof at every milestone. Hands over Attack Narrative and Evidence Pack. Phase 5, Detection Scorecard and Purple-Team Replay. We score which actions your team detected, missed or blocked. Then we replay the key steps alongside your defenders so they can tune alerts and close the gaps for good. Activities: Score every action as detected, missed or blocked; Map the operation to MITRE ATT&CK coverage; Replay key steps live alongside your defenders; Agree detection rules and response fixes with owners. Hands over Detection Scorecard. Each phase begins from the artefact the phase before it produced.

Phase 01 Objectives and Rules of Engagement

We agree the goals, the systems in scope, the tactics allowed and the safety limits. Everyone signs off before anything starts, so the exercise is realistic and controlled.

What Happens In This Phase

  • Define the crown-jewel objective and success criteria with your leadership
  • Set the scope, allowed tactics and out-of-bounds systems
  • Agree emergency stop conditions and named trusted agents
  • Establish deconfliction and communication channels for live testing
  • Capture written authorisation and rules of engagement sign-off

The Handover

Signed Rules of Engagement and Scope Document

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Objectives and Rules of Engagement

    We agree the goals, the systems in scope, the tactics allowed and the safety limits. Everyone signs off before anything starts, so the exercise is realistic and controlled.

    OutputSigned Rules of Engagement and Scope Document

    Activities

    • Define the crown-jewel objective and success criteria with your leadership
    • Set the scope, allowed tactics and out-of-bounds systems
    • Agree emergency stop conditions and named trusted agents
    • Establish deconfliction and communication channels for live testing
    • Capture written authorisation and rules of engagement sign-off
  2. 02

    Reconnaissance

    We map your public footprint, staff, technology and supply chain to build an attack plan. Most of this looks exactly like what an outside attacker can see.

    OutputTarget Profile and Attack Plan

    Activities

    • Enumerate internet-facing hosts, domains and cloud tenants
    • Harvest employee names, roles and email formats from public sources
    • Profile suppliers and third parties with access to your estate
    • Collect leaked credentials from breach data for your domains
  3. 03

    Initial Access

    We gain a foothold through the path a real adversary would choose, including phishing, pretext calls and other social engineering, alongside exposed services and weak credentials.

    OutputInitial Access Record with Evidence

    Activities

    • Design pretexts matched to real lures your staff receive
    • Run targeted phishing and pretext calls against selected roles
    • Test exposed services for weak or reused credentials
    • Establish a resilient command and control channel
  4. 04

    Lateral Movement and Objectives

    From the foothold we escalate, move across your network and work toward the agreed objective, capturing evidence at each step without disrupting your operations.

    OutputAttack Narrative and Evidence Pack

    Activities

    • Map Active Directory attack paths to privileged accounts
    • Escalate privileges and harvest credentials from compromised hosts
    • Pivot toward the agreed crown-jewel objective
    • Capture timestamped proof at every milestone
  5. 05

    Detection Scorecard and Purple-Team Replay

    We score which actions your team detected, missed or blocked. Then we replay the key steps alongside your defenders so they can tune alerts and close the gaps for good.

    OutputDetection Scorecard

    Activities

    • Score every action as detected, missed or blocked
    • Map the operation to MITRE ATT&CK coverage
    • Replay key steps live alongside your defenders
    • Agree detection rules and response fixes with owners

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Red Team Assessment scope, running left to right in three stages. Stage one, what we run, 9 tools and techniques: Cobalt Strike, Sliver, BloodHound, Nmap, GoPhish, Metasploit, Impacket, Responder, Mimikatz. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: MITRE ATT&CK, TIBER-EU, PTES, CBEST, NIST SP 800-115, OSSTMM.

What We Run

9 tools

  • Cobalt Strike
  • Sliver
  • BloodHound
  • Nmap
  • GoPhish
  • Metasploit
  • Impacket
  • Responder
  • Mimikatz

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

6 standards

  • MITRE ATT&CK
  • TIBER-EUECB
  • PTES
  • CBESTBank of England
  • NIST SP 800-115
  • OSSTMMISECOM
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Attack narrative with a step-by-step timeline of the operation
  • Detection and response scorecard against MITRE ATT&CK
  • Prioritised findings with practical fixes
  • Purple-team replay session with your defenders
  • Executive briefing for leadership and the board

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

How is a red team different from a penetration test?

A penetration test finds as many vulnerabilities as it can in a defined scope. A red team picks one realistic objective and tests whether your whole defence, including detection and response, can stop a focused attacker from reaching it.

Will this disrupt our business?

No. We agree safety limits up front and work carefully to avoid downtime. If we ever risk affecting a live system, we pause and check with your named contact first.

Do our defenders know it is happening?

Usually only a small trusted group knows, so the response is genuine. You choose how many people are aware, and we can run it fully covert or as a known exercise.

Keep Moving Through Managed Services

Service 1 of 7 in this practice area