Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Red Team

Putting your defence to the test with a Red Team

A Red Team does not try to find as many vulnerabilities as possible: it finds just enough to reach an agreed objective, by the quietest path. What it measures is not your attack surface, it is your ability to see that surface being used.

The challenge

An exercise that presupposes a defence to test

Let us say it plainly: a Red Team is only worth running if a detection capability already exists. With no SOC, no rules written for your environment, no escalation procedure, the exercise ends the same way every time — the attack succeeds, nothing was seen — and you will have paid a great deal for a finding an hour's conversation would have established. The right order is to build detection, then test it.

Once that capability is in place, the question changes in nature. It is no longer "are we vulnerable?" but "at which step would we have seen the attacker, and what would we have done?". No scan and no conventional penetration test answers that, because both announce themselves.

The exercise naturally extends into a Purple Team: undetected scenarios are replayed with your teams, this time in the open, to write the rules that were missing. That is where the value materialises — not in the intrusion report, but in the detections that did not exist the day before.

What is at stake
  • An attack run end to end without a single alert being raised
  • An alert raised, but drowned in noise and never qualified
  • Detection correct, reaction too slow to change the outcome
  • An escalation procedure never tested under real conditions
  • Blind spots concentrated exactly where nobody is looking
Diagram

The result is not the breach, it is the gap

The attacker's path and what the defence sees of it Path taken objective-driven, unannounced What the defence sees alerts actually qualified Red TeamRed Team Initial accessLateral movementObjective metInitial accessLateral movementObjective met every step leaves a trace, usable or notthe unseen steps become the rules to write
What counts is not that the objective was reached — it almost always is — but at which step the trace stopped being seen.
Our approach

How we proceed

The exercise is authorised in writing, bounded by rules of engagement, and known to a deliberately small circle so that the measurement means something.

01

Objective and rules of engagement

Defining what counts as success with management — reaching this data, this system. Excluded actions, perimeter, window, and a reachable contact on each side able to stop the exercise at any moment.

02

Reconnaissance

Gathering what a real attacker would obtain without ever approaching you: exposed surface, people, technologies, public leaks. This step involves no interaction and remains, by nature, undetectable.

03

Initial access and progression

Obtaining a first foothold, then progressing quietly towards the objective: privilege escalation, lateral movement, persistence. Every action is timestamped, to be set later against what the defence recorded.

04

Confronting the defence

Matching our timeline against yours: which steps produced a trace, which raised an alert, which was qualified, and how long it took. That confrontation is what produces the measurement.

05

Purple Team and remediation

Replaying the undetected scenarios in the open, with your teams, to write and validate the missing rules. We check they fire, and that they do not drown everything else in false positives.

Services involved

Several disciplines, a single point of contact

The offensive side tests, monitoring detects, incident response draws the conclusions.

Deliverables
  • Timestamped chronology of every action taken
  • Measured gap between actions run and alerts qualified
  • Detection blind spots, step by step
  • Detection rules written and validated in Purple Team
  • Technical debrief and presentation to management
Frequently asked questions

Frequently asked questions

A penetration test seeks coverage: within a given scope, find as many exploitable vulnerabilities as possible, and the defence knows it is happening. A Red Team seeks an objective by the quietest path, unannounced. The first measures your exposure, the second your ability to detect and react.

Yes, and we say so even though it costs us the engagement. With no detection capability to test, the outcome is known in advance: the attack lands, nothing was seen. Build detection first; the Red Team will then measure what it is really worth, which no dashboard does.

A small circle, agreed with you: the management who authorise it, and one or two contacts able to stop the exercise. The detection teams are not told — their reaction is precisely what is being measured. The Purple Team phase, by contrast, is run entirely in the open.

That is an excellent result, and it happens. The exercise does not stop there: we then agree to resume from an assumed foothold, to test the later steps. A defence that stops initial access does not necessarily have visibility on lateral movement.

At which step would you see an attacker go past?

If your detection is in place, that is the next question. If not, let us start with that.