Adversary Simulation
Red & purple team — Objective-driven simulation of a real adversary against your whole organization — people, process and technology at once — measured against your detection and response rather than against a vulnerability list. This is what you buy after penetration testing has stopped surprising you.
Is this the right engagement?
- You have a security team and tooling, and want to know whether they work under pressure
- Penetration tests have stopped producing findings that change anything
- You need to validate detection and response against a defined objective, not a checklist
- You want your defenders to train against a live adversary rather than a tabletop
Deliverables
- Objective narrative: what we achieved, how, and how long each stage took
- Full attack timeline mapped to MITRE ATT&CK, aligned to your detection telemetry
- Detection and response assessment — what alerted, what did not, and how long response took
- Technical findings for every control gap exploited along the way
- Executive briefing framed around business impact and response capability
- Joint replay session with your defenders, so the exercise produces detection improvements
Engagements in this solution
Each engagement is scoped around what you are actually running. Where pricing is standardized you can estimate it online in a couple of minutes.
Red Team Engagement
CUSTOM SCOPEObjective-driven, multi-vector simulation against a defined goal — data access, domain control, or a business-impacting action — with detection evasion in scope.
Purple Team Exercise
CUSTOM SCOPECollaborative execution of attacker techniques alongside your defenders, tuning detection in real time and measuring coverage against the techniques that matter to you.
Assumed Breach Exercise
CUSTOM SCOPESimulation starting from an established foothold, focused on what an adversary achieves post-compromise and how quickly you detect it.
Ransomware Readiness Simulation
CUSTOM SCOPENon-destructive simulation of ransomware operator tradecraft — access, escalation, staging and exfiltration precursors — stopping short of encryption.
How the work is run
The same sequence runs underneath every engagement in this solution — specialised here for adversary simulation.
Scope & authorize
Objectives, in-bounds vectors, prohibited techniques and escalation contacts agreed in writing, with a named control group inside your organization.
Reconnaissance
Open-source intelligence and infrastructure preparation, building the picture a real adversary would build.
Gain access
Initial access through the authorized vectors — phishing, exposed services, physical entry, or an assumed-breach starting point.
Operate
Persistence, escalation and lateral movement toward the objective, with detection evasion where in scope and full logging of every action.
Report & replay
Objective narrative and ATT&CK-mapped timeline, then a joint replay session where your defenders see every action against their telemetry.
Improve
Detection gaps turned into concrete tuning recommendations, with a follow-up exercise to validate them where scoped.
What to expect, and when
Indicative for a standard scope. Your dates are confirmed in writing before any testing begins.
| Stage | Duration | What happens |
|---|---|---|
| Scope & authorize | 2–3 weeks | Objectives, vectors, prohibited techniques and control group agreed in writing. |
| Reconnaissance & preparation | 1–2 weeks | Intelligence gathering and infrastructure preparation. |
| Operate | 2–6 weeks | Access, escalation and movement toward the agreed objective. |
| Report & replay | 1–2 weeks | Objective narrative, ATT&CK-mapped timeline and joint replay with your defenders. |
| Total | 6–12 weeks | From signed authorization to replay session, depending on objective and scope. |
What you can hold us to
Commitments that are checkable, not adjectives.
The deliverable is a response assessment. A finding list is a by-product.
The full operator log is handed over, so your team can replay the engagement against their own telemetry.
A small group inside your organization always knows the engagement is live and can stop it instantly.
Ransomware simulation stops short of encryption. Destructive actions are never in scope.
Objective-driven work is scoped to your objective. We do not publish a rate card for it.
Before you ask us
Should we do this or a penetration test?
If a penetration test would still surprise you, do that first. A red team is for organizations whose known issues are already handled.
Will our SOC know?
No — only a named control group does. That is what makes the response measurement meaningful.
What if you get caught?
That is a good outcome and it is recorded as one. Depending on the objective we may pause, change vector, or continue — all agreed in advance.