Red Team Exercises

Full-scope adversary emulation against your people, processes and technology. We replicate the tactics, techniques and procedures of the threat actors that actually target your industry, then test whether your detection and response capabilities can stop them.

Red Team vs Penetration Test: What's the Difference?

A penetration test is a scoped technical assessment of a defined target — a web application, an external perimeter, a corporate network — that produces a list of findings, ranked by severity, with reproduction steps. It answers the question: are these systems vulnerable?

A red team exercise is an objective-driven adversarial engagement against your organisation as a whole. There is no narrow technical scope — only an objective and a set of rules of engagement. We choose how to achieve the objective: phishing, social engineering, physical entry, network exploitation, supply chain compromise, or any combination. The engagement answers a different question: can your blue team see and stop a determined attacker?

Most organisations need both. A red team without prior pen testing usually finds the same easy wins an attacker would — and burns budget on already-known weaknesses. We routinely sequence the work: harden the perimeter via targeted pen tests, then prove the broader security posture under realistic adversarial pressure.

Methodology: MITRE ATT&CK End-to-End

Every CDSEC red team engagement is mapped to the MITRE ATT&CK Enterprise framework. Each action our operators take is tagged with its corresponding Technique ID, which lets your detection team replay the engagement against their SIEM, EDR and SOC playbooks in concrete terms. The final deliverable includes an ATT&CK heatmap showing which techniques succeeded, which were detected, which were blocked, and which fired alerts that nobody actioned.

Reconnaissance & Initial Access

OSINT against your staff and infrastructure, weaponised payload development tailored to your stack, spear-phishing campaigns against named targets, password spraying against exposed authentication portals, and exploitation of edge devices.

Execution & Persistence

Living-off-the-land binaries (LOLBins), C2 over commodity channels (HTTPS, DNS, Slack/Teams APIs), scheduled task and service persistence, AMSI bypass, and EDR evasion using current public and private techniques.

Privilege Escalation & Lateral Movement

Active Directory abuse (Kerberoasting, AS-REP roasting, DCSync, constrained delegation), credential harvesting from memory, Pass-the-Hash and Pass-the-Ticket, RBCD takeovers, and certificate-based persistence via AD CS.

Actions on Objective & Exfiltration

Reaching agreed objectives — domain admin, PII database access, payment system compromise, source code repository control — and demonstrating data exfiltration to operator-controlled infrastructure with realistic volumes and protocols.

Engagement Phases

  1. Threat intelligence & scenario design. We profile the threat actors most likely to target your sector and select the TTPs to emulate. For regulated engagements we align with TIBER-EU, CBEST or iCAST scenario requirements.
  2. Rules of engagement & legal framework. Signed authorisation, white-cell contacts, prohibited targets, escalation procedures, and out-of-hours coverage. We never operate without explicit written authority.
  3. Execution. Typically four to twelve weeks of operator time, paced to mimic a real adversary rather than a sprint. Periodic touch-points with the white cell keep the engagement on track without leaking to the blue team.
  4. Replay & purple team. Once the engagement concludes we walk your defenders through every action chronologically, with logs, screenshots and ATT&CK tags, so they can validate detections and rebuild missed ones.
  5. Reporting. Executive narrative for the board, technical timeline for SOC and IR teams, ATT&CK heatmap, prioritised remediation plan, and a re-test offer at no additional cost within 90 days.

Who Commissions Red Team Exercises

Most red team engagements we run fall into three categories. Regulated financial services firms run them to satisfy CBEST, TIBER-EU or DORA threat-led testing obligations. Critical national infrastructure operators run them to validate the detection and response capabilities they've invested in over the previous three to five years. And mature security organisations — typically those who've already extracted the value from regular pen testing — run them annually as a board-level KPI for the CISO function.

If you've never had a pen test or your last external perimeter assessment was more than a year ago, a red team is almost always premature. Talk to us about structured penetration testing or threat-led penetration testing first.

Related Services

Commission a Red Team Exercise

Engagements typically run four to twelve weeks of operator time. We'll scope objectives, agree rules of engagement, and provide a fixed-price proposal within 48 hours of an initial call.

Speak to an Operator

Get In Touch

Ready to secure your business? Contact our team of certified experts today for a consultation.

Contact Us

Get in touch for questions about our services

Phone

+44131 460 4180

Speak directly with our security experts

9:00 AM - 5:00 PM GMT

Email

[email protected]

Get detailed responses within 24 hours

Business Hours

Schedule Meeting

Book a consultation

30-minute strategy session with our team

Flexible Scheduling

Our Global Offices

Local expertise with global reach across three continents

🇬🇧

United Kingdom

Outer Hebrides, Scotland

+44131 460 4180
9:00 AM - 5:00 PM GMT
GMT
🇺🇸

United States

Des Moines, IA

+1 (515) 123-4567
9:00 AM - 5:00 PM CST
CST
🇦🇪

United Arab Emirates

Dubai, UAE

+971 4 123 4567
9:00 AM - 5:00 PM GST
GST