Testing · Full scope
Red Team & Adversary Simulation.
Objective-driven campaigns run against your live defences, across people, process and technology — measured by what your team detected, not only by what we found.
At a glance
- Surface
- Full scope
- Execution
- Manual, senior-led
- Retest
- Included, no charge
- Proposal
- Within one business day
Scope
Test the defenders, not just the defences.
Emulation is built from threat intelligence on the actors who actually target your sector, then executed under strict rules of engagement.
Full-scope red team
Multi-vector campaign toward agreed objectives — payment fraud, data exfiltration or domain control.
4–8 weeks
Purple team exercise
Techniques executed side by side with your SOC to tune detections in real time.
1–2 weeks
Assumed-breach simulation
Start from compromise and measure how quickly the blast radius is contained.
2–3 weeks
Threat-actor emulation
Named adversary TTPs replayed against your estate using current intelligence.
3–5 weeks
Detection engineering support
Detections written, tested and handed over for every technique that went unseen.
1–2 weeks
Tabletop & crisis simulation
Executive and technical response rehearsed against the scenario we just ran.
1–2 days
Method
Intelligence-led, objective-based.
Nothing starts before the authorisation letter is signed and the blast radius is agreed.
- 01
Objectives
Crown jewels, success criteria, rules of engagement and white-cell contacts.
- 02
Intelligence
Threat profiling, OSINT and infrastructure preparation.
- 03
Initial access
Phishing, exposed services or physical entry — whichever the actor would use.
- 04
Actions on objective
Persistence, escalation, lateral movement and evidenced objective capture.
- 05
Debrief
Joint replay with your blue team, ATT&CK heatmap and detection uplift plan.
Deliverables
What lands on your desk.
- Full campaign narrative with timeline and evidence
- MITRE ATT&CK heatmap of techniques executed versus detected
- Detection and response gap analysis with mean-time metrics
- Detection rules and hunting queries for missed techniques
- Executive readout on business risk and preparedness
- Prioritised remediation and detection roadmap
- Joint blue-team replay workshop
Indicative timeline
Kickoff to closure.
- Weeks 0–1
- Objectives, rules of engagement and white-cell setup
- Weeks 1–2
- Threat intelligence and infrastructure preparation
- Weeks 2–6
- Campaign execution toward agreed objectives
- Week 7
- Reporting, ATT&CK heatmap and executive readout
- Week 8
- Purple-team replay and detection handover
Enquire
Start a Red Team & Adversary Simulation conversation.
Tell us what you need tested. A senior consultant replies within one business day with scoping questions and indicative timelines — no sales funnel.
PRACTICE 05 OF 07
Start here
Find out what your SOC would actually catch.
Tell us the objective worth defending. We'll design the campaign and come back within one business day.
