Red team assessment: we show whether a real attack would be noticed at your company.
Goal-oriented, covert attack simulation against people, technology and process. We emulate real threat groups per MITRE ATT&CK and measure what your SOC sees, when it responds — and where an attacker still reaches the objective.
Which red team format fits your question?
Goal-oriented red team
A single attacker objective (e.g. Domain Admin, payment authorisation, crown-jewel data access). Techniques at operator discretion, stealth constraints, 8–14 weeks. The classic format.
Adversary simulation
Emulation of a specific threat group (APT29, FIN7, ransomware affiliate) via their TTPs in MITRE ATT&CK. Answers: "Are we prepared against this specific modus operandi?"
Red team as a service
Continuous annual mandate: multiple smaller goal scenarios plus detection-engineering cycles between waves. Useful past medium SOC maturity.
How a red team assessment runs with us.
1. Scoping & threat model
Crown jewels, white-team setup, relevant threat groups, rules of engagement, legal framing.
2. OSINT & recon
External perimeter, employee exposure, supply chain, cloud footprint — the basis for initial-access scenarios.
3. Active operation
Initial access → persistence → lateral movement → objective. Covert, at realistic pace, with continuous white-team coordination.
4. Report & purple replay
Executive summary, technical kill-chain report, joint replay with your blue team, and a prioritised remediation plan.
One fixed team. No subcontracting.
TIBER-EU compliant delivery
We deliver red team operations under TIBER-EU and DORA TLPT — in 2024 we completed a full TLPT for a regulated entity.
MITRE ATT&CK as the shared language
Every TTP is mapped to ATT&CK so your blue team, SIEM content team and auditors read the same map.
The same operators from start to finish
No handover between sales, junior and senior roles. Whoever scopes it, executes it. Whoever executes it, is in the debrief.
Frequently asked questions about red team assessments
What is a red team assessment?→
A red team assessment is a goal-oriented, covert attack simulation against a company. Unlike a pentest, the focus is not breadth of findings but a concrete objective — for example access to a crown-jewel application, Domain Admin, or payment authorisation. The scope covers technology, people, processes, and detection & response.
Red team assessment vs. penetration test — what's the difference?→
A pentest looks for as many vulnerabilities as possible within a defined scope over a few weeks. A red team assessment pursues a realistic attacker objective under stealth conditions over 6–14 weeks and explicitly measures the blue team's response. Neither replaces the other — they answer different questions.
How long does a red team assessment take?→
Realistically 8–16 weeks from kick-off to final report: 1–2 weeks of threat modelling and OSINT, 6–12 weeks of active operation, then reporting and a purple-team replay. Under six weeks is rarely useful because detection engineering and persistence need time to play out.
What is adversary simulation?→
Adversary simulation (also: adversary emulation) means replaying the TTPs of a specific threat group — e.g. FIN7, APT29, or a ransomware-affiliate group — as documented in MITRE ATT&CK. We use this format when a client wants to test a specific threat hypothesis ("Are we prepared against the modus operandi of ransomware group X?").
What does red team as a service mean?→
Instead of a one-off exercise, we contract a continuous mandate: multiple smaller goal scenarios per year combined with detection-engineering cycles. Only useful past a certain SOC maturity — otherwise the same attack path just keeps succeeding.
Do we need a red team assessment or a pentest?→
If you first want to know where your weaknesses are or need to assess a specific application: pentest. If you want to know whether a real attack would be noticed and whether your detection response works: red team assessment. If regulation requires it (DORA TLPT, TIBER-EU): a red team run under the TIBER framework.
Ready for an honest red team?
We help you decide which format — red team, adversary simulation or TIBER — actually answers your question.