Skip to content

Testing · Full scope

Red Team & Adversary Simulation.

Objective-driven campaigns run against your live defences, across people, process and technology — measured by what your team detected, not only by what we found.

At a glance

Surface
Full scope
Execution
Manual, senior-led
Retest
Included, no charge
Proposal
Within one business day

Scope

Test the defenders, not just the defences.

Emulation is built from threat intelligence on the actors who actually target your sector, then executed under strict rules of engagement.

Full-scope red team

Multi-vector campaign toward agreed objectives — payment fraud, data exfiltration or domain control.

4–8 weeks

Purple team exercise

Techniques executed side by side with your SOC to tune detections in real time.

1–2 weeks

Assumed-breach simulation

Start from compromise and measure how quickly the blast radius is contained.

2–3 weeks

Threat-actor emulation

Named adversary TTPs replayed against your estate using current intelligence.

3–5 weeks

Detection engineering support

Detections written, tested and handed over for every technique that went unseen.

1–2 weeks

Tabletop & crisis simulation

Executive and technical response rehearsed against the scenario we just ran.

1–2 days

Method

Intelligence-led, objective-based.

Nothing starts before the authorisation letter is signed and the blast radius is agreed.

  1. 01

    Objectives

    Crown jewels, success criteria, rules of engagement and white-cell contacts.

  2. 02

    Intelligence

    Threat profiling, OSINT and infrastructure preparation.

  3. 03

    Initial access

    Phishing, exposed services or physical entry — whichever the actor would use.

  4. 04

    Actions on objective

    Persistence, escalation, lateral movement and evidenced objective capture.

  5. 05

    Debrief

    Joint replay with your blue team, ATT&CK heatmap and detection uplift plan.

Deliverables

What lands on your desk.

  • Full campaign narrative with timeline and evidence
  • MITRE ATT&CK heatmap of techniques executed versus detected
  • Detection and response gap analysis with mean-time metrics
  • Detection rules and hunting queries for missed techniques
  • Executive readout on business risk and preparedness
  • Prioritised remediation and detection roadmap
  • Joint blue-team replay workshop

Indicative timeline

Kickoff to closure.

Weeks 0–1
Objectives, rules of engagement and white-cell setup
Weeks 1–2
Threat intelligence and infrastructure preparation
Weeks 2–6
Campaign execution toward agreed objectives
Week 7
Reporting, ATT&CK heatmap and executive readout
Week 8
Purple-team replay and detection handover

Enquire

Start a Red Team & Adversary Simulation conversation.

Tell us what you need tested. A senior consultant replies within one business day with scoping questions and indicative timelines — no sales funnel.

PRACTICE 05 OF 07

0/2000

Start here

Find out what your SOC would actually catch.

Tell us the objective worth defending. We'll design the campaign and come back within one business day.