Putting your defence to the test with a Red Team
A Red Team does not try to find as many vulnerabilities as possible: it finds just enough to reach an agreed objective, by the quietest path. What it measures is not your attack surface, it is your ability to see that surface being used.
An exercise that presupposes a defence to test
Let us say it plainly: a Red Team is only worth running if a detection capability already exists. With no SOC, no rules written for your environment, no escalation procedure, the exercise ends the same way every time — the attack succeeds, nothing was seen — and you will have paid a great deal for a finding an hour's conversation would have established. The right order is to build detection, then test it.
Once that capability is in place, the question changes in nature. It is no longer "are we vulnerable?" but "at which step would we have seen the attacker, and what would we have done?". No scan and no conventional penetration test answers that, because both announce themselves.
The exercise naturally extends into a Purple Team: undetected scenarios are replayed with your teams, this time in the open, to write the rules that were missing. That is where the value materialises — not in the intrusion report, but in the detections that did not exist the day before.
- An attack run end to end without a single alert being raised
- An alert raised, but drowned in noise and never qualified
- Detection correct, reaction too slow to change the outcome
- An escalation procedure never tested under real conditions
- Blind spots concentrated exactly where nobody is looking
The result is not the breach, it is the gap
How we proceed
The exercise is authorised in writing, bounded by rules of engagement, and known to a deliberately small circle so that the measurement means something.
Objective and rules of engagement
Defining what counts as success with management — reaching this data, this system. Excluded actions, perimeter, window, and a reachable contact on each side able to stop the exercise at any moment.
Reconnaissance
Gathering what a real attacker would obtain without ever approaching you: exposed surface, people, technologies, public leaks. This step involves no interaction and remains, by nature, undetectable.
Initial access and progression
Obtaining a first foothold, then progressing quietly towards the objective: privilege escalation, lateral movement, persistence. Every action is timestamped, to be set later against what the defence recorded.
Confronting the defence
Matching our timeline against yours: which steps produced a trace, which raised an alert, which was qualified, and how long it took. That confrontation is what produces the measurement.
Purple Team and remediation
Replaying the undetected scenarios in the open, with your teams, to write and validate the missing rules. We check they fire, and that they do not drown everything else in false positives.
Several disciplines, a single point of contact
The offensive side tests, monitoring detects, incident response draws the conclusions.
- Timestamped chronology of every action taken
- Measured gap between actions run and alerts qualified
- Detection blind spots, step by step
- Detection rules written and validated in Purple Team
- Technical debrief and presentation to management
Frequently asked questions
At which step would you see an attacker go past?
If your detection is in place, that is the next question. If not, let us start with that.