[ Adversarial ]
Red Team Assessment
- Typical duration
- 3-6 weeks
- Starting price
- Scoped
- You provide
- Objective only, agreed with a small internal group
[ 01 / The engagement ]
A red team engagement measures your response, not your patch level. You give us an objective, the payroll database, the build pipeline, a signed release, and we take whatever path reaches it, over weeks rather than days, staying quiet. The deliverable is not just how we got in. It is which of your controls fired, which stayed silent, and how long it took anyone to notice.
[ 02 / Coverage ]
What we test, in practice.
This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.
Methodology
- 01Objective-based full-chain attack simulation
- 02Initial access through phishing and social engineering, on approval
- 03Custom tooling and payload development to avoid signature matching
- 04Command and control over resilient, low-profile channels
- 05Persistence, privilege escalation and long-horizon lateral movement
- 06Detection timeline reconstructed against your SOC's own logs
- 07Purple team replay session with your defenders afterwards
[ 03 / What you get ]
Four things land at the end of every engagement.
Technical report
Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.
Executive summary
Two pages your board can read. Risk in business terms, with the three things that matter most called out.
Letter of attestation
A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.
Free retest
Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.
[ 04 / Questions ]
Before you commit.
A control group of two or three people, usually the CISO and one operations lead. Everyone else stays unaware. That is what makes the detection timeline meaningful. We hold signed authorisation throughout.
That is a good outcome and we record it precisely. Depending on the rules of engagement we either go quiet and re-approach, or declare and continue from the point of detection so the rest of the objective still gets tested.
Often scoped together
All services →AI & LLM Penetration Testing
Prompt injection, tool abuse and data leakage in systems that act on their own output.
Black Box Penetration Testing
We start with your domain name and nothing else, exactly like a real attacker.
Grey Box Penetration Testing
Standard user credentials, no source code. The best coverage per pound spent.
Scope a red team assessment.
Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.