Getting in is routine. We test clients in finance, insurance and telecommunications regularly, and given time and a real objective, someone gets through. What changed is the price of an attempt. Controls that held because chaining four steps was not worth an attacker’s afternoon are the ones we go at first, along with obscurity and anything whose safety rests on the pace a person types at. What still bounds an attacker is what they can reach and what they are allowed to be. A credential sitting in an internal repository is a finding. Privilege segregation, a secrets vault and automated commit scanning is the improvement. The useful questions are how far someone gets before anyone notices, what your detection team does when it does, and which structural problem let it happen in the first place. We test the thresholds as well as the rules, because a threshold set for a person working and a threshold set for machine pace are different numbers. We record when detection fired as carefully as when it did not, and we stay in the room afterwards to work through what your team saw and what it missed.
We keep that record stage by stage. The row underneath is what the client's own detection caught at each one, which is the number that changes between the first exercise and the second.
One exercise, stage by stage
InThroughOut
Attack
1Phishing link, or a vulnerable web application
2Command and control channel opens
3Privilege escalation in Active Directory
4Administrative account, widespread compromise
5Target systems reached
Detection
missed
late
seen
seen
missed
Illustrative
The tactics, techniques and procedures are the ones real attackers use, run against your real business processes. Where it helps, the exercise runs openly with your defenders instead of against them. These are sensitive projects: someone's work is being tested. The findings are written for the defence team to work from.
What we found
Endpoint detection and response software holds the highest privilege on every machine it runs on, so it is worth attacking directly. In one red team exercise we found three then-unknown vulnerabilities in a deployed EDR’s management portal, plus a default credential documented in the vendor’s own public user guide. The credential was the shortest way in. We disclosed all four. The vendor patched the three vulnerabilities. Changing the default was left to the customer.
How
Adversary emulation against a production deployment, treating the security product itself as the target rather than as part of the defence. Disclosed to the vendor and fixed.
Often enough, a decent ADCS honeypot would have stopped us, so we built one and gave it away. Certiception stands up a certificate authority in your environment, plants an ESC1 honeypot behind it, and ships SIGMA rules so the alert reaches your SIEM. The deception strategy guide our red team works from is public alongside it.
Three shapes these engagements take, depending on whether you are testing your defences, your detection, or a regulator’s requirement. Most are a combination.
Classic red team
We simulate an attacker going after your business processes, from first access through to the objective.
—Get into the network
—Move through the network towards a defined objective
—Complete the mission, or show exactly where it stopped
—What each identity we take over is allowed to be, and what that permission reaches
—Your detection capability tested throughout, without warning, against pace as well as technique: whether a burst of low-confidence attempts inside one hour reaches a human
TIBER and DORA threat-led testing
An EU-regulated attack simulation against critical business functions and the systems behind them.
—Threat intelligence-led scenario design
—Testing against critical functions in scope of the regulation
—Close coordination with you and with the regulator
—Documentation in the form the framework requires
Purple team engagement
Attackers and defenders work side by side, so detection improves during the exercise rather than after it.
—Attack and defence in the same room
—Detection tuned and retested as we go
—Thresholds retuned for machine pace, not only rules written for new techniques
—Coverage gaps identified against the techniques we actually used
—Suggestions for which detections to build next
Also available: Active Directory and identity review. Identity systems are the usual route to infrastructure takeover, so we map your attack paths and close the common ones. Non-human identities are part of that review: service accounts, CI runners, and the agents your teams have connected to them.
What a finding turns into
A finding is the start of the work, not the deliverable. The useful question is what
the finding is evidence of, because that is the thing that recurs and the thing worth
spending a quarter on.
What we foundWhat it was evidence ofWhat changed
Found:Accounts and credentials sitting in internal repositoriesEvidence of:Secrets live wherever a developer can reach them, and repository access is broader than anyone intendsChanged: Stronger privilege segregation, a vault, and automated commit scanning that fails a build
Found:A certificate template any domain user could abuse to reach domain adminEvidence of:Certificate services are a standing route to domain admin, and almost nobody watches themChanged: A decoy certificate authority with an ESC1 template behind it and detection rules, so the attempt reaches the SIEM. Certiception, open source
Found:A default credential in an EDR management portal, printed in the vendor’s own public user guideEvidence of:The security stack holds the highest privilege on every machine and is itself neither hardened nor monitoredChanged: The tools that watch the estate get hardened and watched like the estate. The three vulnerabilities we disclosed with it
The first row is the shape of what we find. The second and third are published, and
the tool in the second one is ours and free.
How we work
We agree the objective and the rules of engagement first, including what we are not allowed to touch, and the exercise runs against production unless you say otherwise. The route is whatever is shortest on the day. On one exercise that was a default credential printed in the vendor’s own public user guide for the EDR, which was faster than the three unknown vulnerabilities we had found in the same product. The exercise is run by people. What is cheap now is the attempt and not the fix, so each finding leaves with the structural change that removes the path rather than the single instance we used. At the end we walk your defence team through the whole path, step by step, including the stages nothing fired on.
Tell us what you are building and what you need looked at. You will get an answer
from the people who would run the engagement, and if another firm is the better
fit for what you are asking, we will name one.