Red teaming: one objective over weeks
An agreed objective, every route allowed, every step logged. What gets measured is how much of it your detection noticed.
One objective, several weeks, no warning
A red team pursues an agreed objective: reach a particular database, reach a particular controller, become domain administrator. The route there is open, through technology, through people and through the door.
That tests something other than a penetration test. A test looks for as many weaknesses as possible in a defined area and reports them. A red team takes one route and leaves much untested, but the defence runs under real conditions alongside.
It starts with open research, OSINT: who works where, what technology is in use, which service providers have access, and when which processes are vulnerable. The plan comes out of that, not out of a tool.
The question is the detection
We log every step with a timestamp and a technique identifier from MITRE ATT&CK. Your defence logs independently what arrived in its tools. Comparing the two at the end shows at which steps something was noticed and at which it was not.
Two noticed out of six steps is a start. More important than the number is the question behind it: was there no log, was there a log but no rule, was the rule too narrow, or was there an alert nobody worked on. Those are four problems with four different solutions.
When a red team is worth it
A red team assumes the basics are in place. Otherwise it only confirms what a simpler test would have shown faster.
Detection exists
There is a SOC, or at least someone who works on alerts. Without an opposing side the exercise measures nothing.
The reachable services are tested
Where an external test still finds open services, the route is too short for an exercise that says anything.
An objective is named
What exactly is meant to be protected. Without that, the exercise becomes an unbounded search.
How a red team engagement runs
Four to eight weeks, with breaks. Anyone finished in three days has done a penetration test and called it something else.
Objective and rules
An agreed objective, a small circle of people in the know, abort criteria, and the question of how we identify ourselves if something goes wrong. All of it in writing before anything starts.
Reconnaissance
Open research: who works where, what technology is in use, which service providers have access, and when which processes are vulnerable. The plan comes out of that, not out of a tool.
The engagement
The route to the objective, through technology, through people and through the door. Every step with a timestamp and a technique identifier from MITRE ATT&CK, so that it can be found again later.
Comparison and review
Your defence logs independently what arrived in its tools. The comparison shows at which steps something was noticed and at which it was not, and why.
Common questions about red teaming
A small circle, so that the response is real. We agree in writing beforehand who is in the know, how we identify ourselves if something goes wrong, and how the exercise gets called off.
Four to eight weeks, with breaks. Anyone finished in three days has done a penetration test and called it something else.
We work with abort criteria and report everything that could have gone wrong. Interventions in production are agreed, and in OT environments they run on a spare rig as a matter of course.
Certifications and memberships.
Talk to us.
A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.