Purple team exercises
A joint exercise: our operators execute attack techniques one by one while your defenders tune detection and response.
Adversary simulation
A goal-driven simulation of a real adversary against people, process and technology, to test whether an attack would be detected and stopped.
Adversary simulation
A penetration test asks which vulnerabilities exist. A red team operation asks a different question: if a capable adversary decided to reach a specific objective in your organisation, would anyone notice, and how fast would they be stopped?
The operation is planned around objectives you define, such as access to the payment system or to the source code, and around the adversaries who would realistically pursue them. Only a small control group in your organisation knows. The defenders face the operation as they would face a real attack.
01Scope
02Approach
Together with the control group we define the objectives and choose the adversaries to emulate, with their known techniques.
Infrastructure, pretexts and tooling are prepared for this operation. Risk controls, escalation contacts and stop conditions are agreed in writing.
The operation runs over weeks, not days, at the pace of a real adversary. The control group is informed at every significant step.
After the operation the attack is replayed with the defenders step by step. Each technique is checked against the logs: seen, alerted, acted on.
03
04
05Standards
Catalogue of adversary techniques used to plan operations and to report detection coverage.
The MITRE Corporation
Structure of threat-led red team tests: threat intelligence, red team phase, closure.
European Central Bank
Planning, rules of engagement and conduct of technical testing.
NIST
06Questions
The method follows the TIBER-EU framework that the DORA testing standards build on: threat intelligence, a red team phase and a closure phase with replay. A formal test under DORA is supervised by your authority and sets requirements for the providers, including references and insurance. Whether we qualify for your test is established against those requirements during scoping, before any commitment.
No. A red team operation tests detection and response. If basic vulnerabilities have not been found and fixed, a penetration test gives far more for the same effort.
They are set in writing before the operation. No pretext uses threats, personal hardship or health, no private accounts or devices of employees are targeted, and no employee is named in the report as having failed.
The operation stops and the control group is informed immediately. Everything we observed is handed over to support your incident response.
08Request
Reference
Keep the reference: we name it in all further communication with you.
We never ask for payment, passwords or remote access in the first reply.