The challenge behind the engagement.
Detection and response validation is a collaborative, open exercise. We run known attacker techniques while your defenders watch their tools, then tune and re-run. We work from a recognized library of attacker behavior chosen for your threat model and execute techniques one at a time. For each one we record whether it was logged, whether an alert fired, whether it was blocked, and how your team reacted. Repeatable test scripts and portable, vendor-neutral detection rules support the work and let your team run the same tests again later. When it follows a red team or assumed breach engagement, we replay that operation's timeline so defenders can map each action to what their tools showed. You receive a technique-by-technique detection-gap map, tuned rules, time-to-detect and time-to-respond baselines, and a repeatable playbook.
For SOC, detection engineering, and incident response teams that want to measure and improve what their tooling actually catches. Often run after a red team or assumed breach engagement, after a SIEM or EDR migration, or before an audit of detection capability.
What we do.
What you can use.
Select techniques and environment
With your team we choose the attacker techniques and emulation plans that fit your threat model. We confirm access to the SIEM, EDR, and logging consoles, and agree a test environment or a bounded production window. Defenders join the sessions rather than being kept in the dark.
Run, observe, and tune
We execute each technique in the open while defenders watch their tools, recording whether it was logged, alerted, or blocked and how fast your team reacted. We tune the detection or control in the room, then re-run the technique to confirm the change using portable detection rules and repeatable test scripts.
Hand over matrix and playbook
You receive a technique-by-technique detection-gap map with before-and-after time-to-detect and time-to-respond metrics, and a clear picture of where coverage is thin. New or tuned detection rules ship with the log sources they need. A short playbook lets your team repeat the exercises without us.
Who it’s for.
When you need it.
- SOC, detection engineering, and incident response teams measuring what their tooling actually catches
- Security teams with detection content but no evidence it fires on real attacker techniques
- Organizations wanting a repeatable, measurable detection-improvement loop they can run in house
- Defenders coming off an adversary-simulation engagement who must remediate the coverage gaps it surfaced
- A SIEM or endpoint detection migration needs its coverage revalidated
- A red team or assumed breach exposed detection gaps you now want to tune
- An audit or customer question asks you to evidence detection capability
- New detection engineers or content need a structured baseline of time to detect and respond
What the scope can include.
- 01
Technique and emulation-plan selection mapped to your threat model
- 02
Review of current SIEM and EDR detection content against the selected techniques
- 03
Live execution of each technique with defenders observing their tools
- 04
Recording of logged, alerted, blocked, or missed for every technique
- 05
Detection tuning and re-run to confirm the change in the room
- 06
Optional replay of a prior red team or assumed breach timeline
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and reporting, plus a retest of your fixes, included. Find the size closest to yours.
About 20 to 30 attacker techniques, one security tool set, two working sessions
About 32–48 hoursAbout 50 to 75 techniques across laptops, sign-in, and cloud monitoring
About 64–96 hours100 or more techniques across several tools or sites, or a full replay of a prior red team
About 120–180 hours- Number of attacker techniques to run
- Number of monitoring tools and data sources
- Rounds of tuning and re-testing
- Whether a prior red team timeline is replayed
Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Technique-by-technique detection-gap map showing logged, alerted, blocked, or missed for each
- Before-and-after time-to-detect and time-to-respond baselines
- New or tuned detection rules with the log sources each one needs
- A repeatable exercise playbook your team can run without us
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Is this the same as a red team operation?
No. A red team operation is adversarial and stealthy: your defenders are not told, and the point is to see whether a hidden operator gets caught. Detection and response validation is collaborative and open. We run techniques while your defenders watch, tune detections in the room, and re-run to confirm the fix. The goal is a measured change in what your tooling catches, not a win or a loss.
Do we need to have run a red team first, and will this touch production?
A prior engagement helps because we can replay its timeline, but it is not required; we can start fresh from attacker techniques chosen for your threat model. The work can run in a test environment or a clearly bounded production window agreed with your team, using seeded artifacts and techniques sequenced to stay safe. Detection content is environment-specific and needs ongoing maintenance after we hand it over.
- NIST SP 800-115: Technical Guide to Information Security Testing and Assessment
- NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations
- MITRE ATT&CK
- Adversary Emulation Library | Center for Threat-Informed Defense
- A Tale of Two SOCs: Insights From Two Red Team Assessments | CISA
