The challenge behind the engagement.
A full-scope red team operation tests what a determined attacker would achieve, not whether vulnerabilities exist. We agree two to five objectives tied to critical functions, such as a high-value administrative account, a payments approval system, or a seeded data set. After reconnaissance, we attempt initial access by hand, using paths such as phishing, external exploitation, or credential spraying against your identity providers. We then chain persistence, privilege escalation, and lateral movement, abusing misconfigured authentication, directory, and cloud services, with techniques chosen to fit your environment. A control team holds a deconfliction channel while the SOC stays blind. You receive a scenario-by-scenario timeline, a per-technique detection outcome for every action, and fixes. All work runs under written authorization, exfiltrates seeded data only, and can be paused or stopped at any time.
For organizations that have completed penetration testing and basic vulnerability management and now want to know whether prevention and detection would stop an objective-driven campaign. Often triggered before a board review or a major customer security due-diligence questionnaire.
What we do.
What you can use.
Agree objectives and threat model
In a scoping workshop we pick two or three adversary profiles and the techniques they use, then define the flags that matter to your business. We capture written executive authorization, allowed and prohibited actions, social engineering and physical boundaries, and halt criteria.
Chain techniques toward objectives
We set up domains, redirectors, and command and control, then gain a foothold. From there we move through the estate toward each flag, abusing the misconfigurations and trust relationships in play, with techniques such as credential theft, token abuse, and privilege or role chaining. If a stage stalls, the control team grants a documented leg-up so later stages still get tested.
Deliver narrative and retest
You get an executive summary and a storyline with an in, through, and out timeline. Findings are grouped by security function with root cause and fixes, and every leg-up is recorded. We replay the timeline with your defenders and retest closed findings with evidence.
Who it’s for.
When you need it.
- Organizations that have completed penetration testing and now want their detection and response tested
- Security leaders answering board or regulator questions about how defenses perform under a real campaign
- Firms with a staffed SOC and endpoint detection wanting an honest measure of coverage
- Mature security programs ready for objective-driven, stealthy testing rather than broad vulnerability coverage
- A major customer or insurer asks how your defenses hold against a targeted attacker
- You have stood up a SOC or EDR and want to prove it detects intrusions
- A board review or annual security program milestone calls for adversary-simulation evidence
- A regulator-style threat-led testing expectation is approaching and you want a dry run
What the scope can include.
- 01
Objective and threat-model workshop selecting adversary profiles and flags
- 02
Rules of engagement, executive authorization, and deconfliction code word
- 03
Reconnaissance, phishing pretext design, and command-and-control setup
- 04
Initial access, persistence, privilege escalation, and lateral movement
- 05
Controlled exfiltration of seeded data toward each agreed objective
- 06
Closure replay, purple-team review of missed detections, and retest
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and reporting, plus a retest of your fixes, included. Find the size closest to yours.
Two goals, one main site, about three weeks of covert activity
About 100–140 hoursThree or four goals across offices and cloud, with a phishing campaign
About 160–220 hoursUp to five goals, several sites and clouds, a long-running campaign that mimics a known attacker
About 240+ hours- Number of goals and attacker profiles
- Length of the covert operating window
- Entry routes allowed, such as phishing or outside exploitation
- Number of sites, clouds, and sign-in systems
Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Executive narrative plus a scenario storyline with an in, through, and out timeline
- Objectives reached and not reached, with the attack paths that worked and failed
- Every technique attempted with its detection outcome, findings, and owner-ready fixes
- Artifact cleanup list, defender IOC set, and retest evidence for closed findings
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
How is this different from the internal penetration test we already buy?
A penetration test maximizes coverage and is coordinated with your IT team to find as many vulnerabilities as possible. A full-scope red team operation is objective-driven and stealthy. Your SOC is not told, and we chain techniques toward specific flags. The report shows what an attacker achieved and what your defenders detected, not a ranked vulnerability list. Most buyers run penetration testing and fix the basics first, then use a red team to test detection and response.
What happens if you break something or find a real attacker?
We work by hand with non-destructive methods and exfiltrate seeded data rather than real records. Your control team can pause or stop the operation at any time. A deconfliction channel with a code word lets us confirm whether suspicious activity is ours or a genuine intrusion. If we discover signs of a real attacker, we escalate to your control team immediately rather than continuing.
- NIST SP 800-115: Technical Guide to Information Security Testing and Assessment
- NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations
- MITRE ATT&CK
- Adversary Emulation Library | Center for Threat-Informed Defense
- A Tale of Two SOCs: Insights From Two Red Team Assessments | CISA
