EspañolEnglish
Red team
Find out what your defenders actually catch.
A red team operation goes past an audit. It emulates a real attacker with a real objective, against a blue team that has not been told, to measure whether your organization would detect it, contain it, and recover.
Objective-based, typically two to four weeks. Scoped on the call. OSEP certified, ten published CVEs.
A pentest finds vulnerabilities. A red team finds out if anyone is watching.
Detection and response, under real conditions
A red team tells you what your SOC actually catches, how fast it reacts, and where an attacker moves unseen. A pentest tells you which vulnerabilities exist. Different questions.
Cross-cutting weaknesses
Real intrusions rarely turn on one vulnerability. The value is in the chain: a phish, a misconfigured service, an over-privileged account, and Tier-0 in three hops.
Monitoring gaps you can name
Every action is logged on our side. The debrief shows exactly which steps your tooling saw, which it missed, and the log source that would have caught the rest.
A blue team that has seen this before
The engagement ends with a joint session. Your defenders replay the operation with the operator who ran it, so the next real one is not their first.
How the operation runs.
One senior operator, the same one from planning to debrief. Every action logged, critical findings escalated the day they happen.
- 01
Threat intel and planning
We agree on the adversary to emulate and the objective that defines success. Recon builds the picture: exposed infrastructure, people, technology, leaked credentials. The blue team is not told.
- 02
Initial access
Phishing, external exploitation, or an agreed assumed-breach starting point. Whatever a real operator with that objective would use, inside the rules of engagement.
- 03
Evasion and foothold
Custom loaders and C2 tuned to get past the EDR in place, Sophos, CrowdStrike, SentinelOne. Persistence that survives a reboot and a credential reset.
- 04
Lateral movement and escalation
From the first host toward the objective. Kerberos abuse, credential theft, ACL and delegation chains, pivoting between segments.
- 05
Objective and exfiltration
Reaching the agreed target: Domain Admin, a specific system, staged data, or a controlled ransomware simulation. Proven, not asserted, and always reversible.
- 06
Debrief
The full narrative, the detection timeline, and a working session with your defenders. Free follow-up on Critical findings within 30 days.
Red team scenarios.
A scenario is one adversary, one way in, one objective, agreed before anything starts. It defines who we emulate and what success means.
Adversary
- External attacker, no prior access
- Compromised supplier or third party
- Malicious or compromised insider
- Competitor after specific data
Way in
- Phishing and social engineering
- External vulnerability exploitation
- Leaked or guessed credentials
- Assumed breach, a planted foothold
- Physical or wireless access, where scoped
Objective
- Domain Admin and Tier-0 control
- A named business system (ERP, payments, source)
- Sensitive data staged for exfiltration
- Controlled ransomware simulation
- A client-defined objective
What a scenario looks like.
- A phishing email lands a foothold. Two weeks later the objective is Domain Admin and a copy of the HR database staged for exfiltration.
- An assumed-breach laptop on the corporate VLAN, tasked with reaching the payment system without tripping the SOC.
- A developer credential leaked in a public breach, used to reach source code and CI/CD secrets.
- A controlled ransomware simulation across a segmented file server estate, to measure detection, containment, and recovery.
Ransomware
The one scenario worth running before it runs itself.
Ransomware is the attack most likely to hit and the one most organizations have never rehearsed. We run it end to end, safely, and then measure how far it got.
Run the scenario
A ransomware operation executed end to end against an agreed scope, with a reversible payload and hard safety limits. Nothing is encrypted for real.
Gap analysis
A review of how each defensive layer responded: detection, containment, recovery. Where the operation would have been stopped, and where it would not.
Three questions it answers
- Would your defenses catch it before encryption starts?
- Can you contain it to the first host, or does it spread?
- Could you recover operations, and how fast?
Why this red team is different.
Senior only
A small team of senior operators. The person who plans the operation runs it and writes it up. No juniors on your network, no handoffs.
Custom tooling
Loaders and C2 built for the engagement, not off-the-shelf frameworks every EDR already fingerprints. Loader research is public on the blog.
Real evasion
EDR evasion developed and tested against Sophos, CrowdStrike, and SentinelOne, not assumed from a course.
Research to back it
Ten published CVEs with MITRE and INCIBE identifiers, and OSEP certification. Verifiable before you sign anything.
Red team, or penetration test?
Both are manual, both are senior-led. They answer different questions. If you are unsure which you need, that is what the call is for.
| Penetration test | Red team | |
|---|---|---|
| The question | Which vulnerabilities exist in this scope? | Would we detect and stop a real attacker with an objective? |
| Scope | Defined and broad: test everything in the target | Narrow and deep: reach the objective by any agreed path |
| The blue team | Usually informed; it is a known exercise | Not informed; detection and response are part of the test |
| Output | A prioritized list of findings to fix | A narrative of the intrusion, and where defense held or broke |
| When to run it | A new app, an annual requirement, before a launch | A mature team that wants to test itself, not its scanners |
What you get.
- Full operation narrative mapped to MITRE ATT&CK
- Detection timeline: what your tooling saw, and when
- IOCs and a detection gap analysis for your SOC
- Executive briefing and a technical debrief with your team
- Free retest of Critical findings within 30 days
Red team operations are objective-based and scoped on the call. See services and pricing.
Questions.
What is a red team exercise?
A planned offensive operation that emulates a specific attacker with a specific objective, run to test detection and response, not just to enumerate vulnerabilities. It measures what your people, process, and tooling actually do during a real intrusion.
How is it different from a penetration test?
A pentest maps the vulnerabilities in a defined scope, with the defenders usually aware. A red team picks an objective and reaches it by any agreed route, without warning the blue team, so you learn whether you would catch a real one.
How long does it take?
Objective-based, typically two to four weeks of active operation, longer when it starts cold from the internet with no prior knowledge. Mature teams often run several shorter operations across a year rather than one.
Can it break something?
Any real-world operation carries risk, so it is managed: written rules of engagement, agreed no-go systems, reversible payloads, and same-day escalation of anything critical. Ransomware simulation never encrypts real data.
Do we need a mature security team first?
For a full red team, ideally yes. With no monitoring to test, a penetration test or the Active Directory assessment gives more for the money. The scoping call is where we decide honestly which one fits.
Not sure a full red team is the right test?
Thirty minutes is enough to scope it.
NDA first, so we can talk about your actual environment. You talk to the operator who would run the operation, not a salesperson.
Book a free scoping callPrefer email? engagements@redghostops.com