Englishالعربية Soon
Under attack?
Red teaming · APT emulation

A covert, black box emulation of an APT group, run against you around the clock.

You set the objectives. We work from the internet with no privileges and no prior knowledge, using the tools, tactics and procedures of more than 35 tracked APT groups, and we do it quietly enough that your blue team has to earn the detection.

How it differs from a pen test
Objectives you name, not a checklist
Covert throughout, to test detection
24/7, including outside business hours
Social engineering in scope by default
Blue team response measured and scored

Attacks proceed without prior notice. The single exception is exploitation that carries a genuine denial of service risk, which is agreed with your named contact before it runs.

Scope of services

Five stages, run as one continuous operation

This is not a longer penetration test. It is a kill chain assembled the way a real group assembles one, which is what makes the probability of a successful targeted attack against you measurable.

Stage 01

Collecting initial data

Reconnaissance and perimeter discovery

We assess the feasibility of an attack the way an external group would: open sources, media and conference material, and private darknet resources for data about you that has already been compromised. The perimeter is scanned for exploitable vulnerabilities and configuration flaws in network devices, internet-facing services and applications.

Open source and darknet research
Perimeter scanning and vulnerability discovery
Zero-day candidate list where software versions are known
Employee list built for phishing
Stage 02

Infrastructure penetration

Getting inside, by whichever route is weakest

The goal is to reach as many internal segments as possible, including those of subsidiaries. Once inside a segment we study what is reachable and escalate. Your named contact is told which resources were reached, so you can suspend work on a host or segment if our actions risk operational consequences.

Exploitation of perimeter vulnerabilities, including zero-days
Phishing against named employees
Attacks on corporate wireless from outside the controlled perimeter
Rogue access point staged near the office entrance
Stage 03

Lateral movement

Expanding control quietly

Control is extended across the infrastructure towards the agreed objectives, escalating privileges on critical systems or taking the domain outright, while keeping our presence as hard to spot as possible.

Traces of presence minimised throughout
Prepared tooling distributed to hold a foothold
Access obtained to workstations and servers
Highest privileges pursued on the domain
Infrastructure searched for routes to the objective
Stage 04

Attainment of objectives

Reaching what you told us would hurt

Objectives are yours to define during approval. They are stated in business terms, and the route to them is our problem to solve.

Highest privileges in Active Directory
Access to business-critical services and systems
Access to a defined segment, such as the ATM or industrial network
Access to the workstations of named executives
Stage 05

Blue team response analysis

Measuring what your defence actually did

Logs from your security tooling and surrounding infrastructure are analysed against everything we did, and your response is assessed against your own internal standards and international practice. This is the part that changes how you operate.

Security tool logs analysed against our timeline
Response times compared with internal standards and best practice
Sufficiency of blue team actions assessed
Recommendations for tuning and upgrading existing tooling
Methodology

Black box. No briefing, no credentials, no map.

The team begins with no preliminary data about your systems or infrastructure, under the same conditions a real external attacker faces: a highly skilled operator on the internet with no privileges, working to reach one host and then the privileges needed to attack everything behind it.

Automated tooling is combined with manual analysis. Defects are found with methods and tools that are commercially available, open source, or obtainable from restricted sources, because that is what the adversary has too.

01
Reconnaissance
Networks and domains attributed to you from publicly available sources. You add to or remove from that list before testing begins.
02
Scanning and enumeration
Devices, operating systems and applications enumerated across scope. Full scan output is available on request.
03
Service vulnerability analysis
Perimeter services assessed for what an external intruder could compromise, intercept or take down.
04
External web application testing
Public applications assessed with no data and no logical access, to find at least one vector to business-critical resources.
05
Perimeter breach
If access to the internal network is obtained, the attack is deemed successful and the operation continues inside.
06
Debrief
Detected incidents, IDS and IPS reactions and every countermeasure your staff took are summarised back to you.
Coverage

Vulnerability classes assessed on the perimeter

The operation is objective-led, but the perimeter work underneath it is systematic. These are the classes we test for on the way in.

Misconfiguration of perimeter telecommunication equipment
Firewall rule errors
Remote access misconfiguration
Vulnerabilities in externally reachable network services and applications
Errors in web application authentication mechanisms
Errors in authorisation and access control
Missing or deficient protection against XSS and CSRF
Injection flaws such as SQL injection and OS command execution
Disclosure of implementation detail and components in use
Errors in user-accessible application functions
Misconfiguration of operating system, web server or CMS components
Engagement

Rules of engagement

Primary targets are listed by you before work begins. Anything that could cause a malfunction or other negative consequence is agreed with your representative first. You designate a point of contact and we recommend you hold a current backup of the systems in scope.

Talk to us →

Engagement

What you receive

Complete information about every action taken, the attack methods used, the defects found, the results of exploiting the most critical of them, and objective evidence demonstrating each one. Zero-day findings are given to you and, with your agreement, to the vendor.

Incident response →

Related

Work that sits either side of it

Penetration testing

Do this first. There is no point being covert against a perimeter with unpatched public services.

Phishing simulation

Initial access usually starts with people. Measure that continuously and separately.

Managed SOC

A red team measures detection once. A SOC is what turns the findings into standing capability.

Name the target. We will try to reach it.

A scoping call defines the objectives, the exclusions and the point of contact. Nothing starts until the rules of engagement are signed.