Red Team Operations / FOCUSED SERVICE

Assumed Breach Exercise

A red team exercise that starts from a foothold you grant, measuring how far an intruder gets, how fast, and what stops them.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

An assumed breach exercise skips the unpredictable initial-access stage and focuses on what an attacker does once inside. You provision a starting position agreed in writing. It is usually a managed endpoint with an ordinary user account, remote-access credentials on a standard build, or a low-privilege identity in a cloud or SaaS tenant. From there we work toward agreed objectives while your defenders monitor as usual. We record how far the position extends, how quickly the SOC notices, and which controls stop progress. Every technique is executed by hand and mapped to the attacker behavior it represents. You receive a timeline from the granted foothold to each objective, the paths that worked and were blocked, findings with fixes, and retest evidence. All activity runs under written authorization and exfiltrates seeded data only.

WHEN THIS IS THE RIGHT FIT

For mid-market organizations planning a first red-team engagement, or teams with a hardened perimeter who want to know what happens when one endpoint or account is compromised. Common triggers: a phishing near miss, a new EDR rollout, or a cyber-insurance question about lateral movement.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Provision the starting foothold

Before the window we agree the granted position: a test account that mirrors a real user, a foothold host, or a low-privilege cloud identity. We confirm the objectives, the systems that are off limits, and the control team contacts, then provision the access so no time is lost on entry.

Extend access toward objectives

From the foothold we enumerate the estate and move toward each objective while your defenders monitor as usual. We record every technique attempted with its detection outcome, measuring how far the position extends, how quickly the SOC reacts, and which controls halt progress.

Measure containment and prove fixes

You receive the elapsed time from foothold to each objective, the first alert your SOC raised and when, and the control that finally contained the intruder. If nothing did, the report says so. We debrief your defenders on the gap between those two moments, then retest the fixes that close it.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • Mid-market organizations planning their first red-team engagement without full-scope budget or time
  • Teams with a hardened perimeter wanting to know what one compromised endpoint or account allows
  • Security groups focused on lateral movement, privilege escalation, and containment rather than initial access
  • Organizations whose insurers or customers scrutinize post-compromise blast radius
WHEN IT’S TIME TO ENGAGE
  • A phishing near miss or credential leak raises questions about post-compromise exposure
  • A new endpoint detection or monitoring rollout needs validation against realistic activity
  • You want red-team value but are not yet ready for a full stealth operation
  • An insurer or customer questionnaire asks how far an intruder could move internally
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • Granted starting position provisioned and agreed before the test window

  • Objectives, off-limits systems, and control team contacts confirmed in writing

  • Post-access enumeration of the estate, identities, and cloud tenants

  • Lateral movement and privilege escalation toward each agreed objective

  • Detection timing and control effectiveness recorded for every technique attempted

  • Defender debrief, timeline replay, and retest of remediated findings

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and reporting, plus a retest of your fixes, included. Find the size closest to yours.

Small
$7,200–$11,000

One starting account or laptop, one or two goals, one office network

About 48–72 hours
Mid-size
$12,000–$18,000

Two or three goals across office and cloud sign-in, with your security team watching

About 80–120 hours
Large
$21,000–$30,000

Several starting points such as laptop and cloud account, multiple sites, up to five goals

About 140–200 hours
WHAT MOVES THE PRICE
  • Number of starting points provided
  • Number of goals
  • Size of the network and cloud estate in reach
  • Depth of detection timing and debrief
TYPICAL TIMELINE

2–4 weeks

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • Timeline from the granted foothold to each objective reached or blocked
  • Detection record: the first alert raised, when it fired, and what finally contained the intruder
  • Findings with root cause, business impact, and fixes written for the owner
  • Cleanup steps for the foothold and residual access, plus retest evidence

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

What foothold do you start from, and how do we set it up safely?

You choose a starting position that mirrors a realistic compromise. Most often that is a managed endpoint with an ordinary user account, remote-access credentials on a standard build, or a low-privilege identity in a cloud or SaaS tenant. We agree it in writing and you provision it before the window opens, so the exercise begins cleanly at the post-access stage. We exfiltrate seeded data only, never real user records.

Is this cheaper or faster than a full red team operation?

Usually, because the slowest and least predictable stage, gaining initial access, is removed. That lets the budget go to lateral movement, privilege escalation, and testing what your defenders detect once someone is inside. It is a common first red-team engagement. Many organizations run an assumed breach exercise first, then move to a full-scope operation once they have tuned detection and response.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security