Deutsch

Offensive Services

Red Team Operations

A penetration test asks: which vulnerabilities exist? A red team operation asks something different: can we reach the design data? The payroll? The plant controls? And above all — does anybody notice while it happens?

01

The distinction

Not more vulnerabilities, but a different question

The penetration test delivers a list. The red team operation delivers an answer to one single, previously agreed question — and evidence of how your defence performed while it was happening. This is not a larger pen test but a different discipline.

  • Objective — one agreed crown jewel instead of the most complete list of weaknesses possible. “We had access to the design data” carries more weight than forty medium findings.
  • Duration — several weeks rather than a few days. A real attacker has time, and time is their greatest advantage.
  • Scope — technology, people and buildings together. Testing only the technology misses the route an attacker actually takes.
  • Knowledge — only a small circle is informed. The defence does not know an exercise is running; otherwise you are testing preparation, not reaction.
  • Measure — what is assessed is not our access but your detection. An operation exposed after four hours is a better result than one that stays unnoticed for three weeks.
A long aisle between unlit server racks. A single glowing trail winds along the floor in wide curves between the rows, up to the one rack at the end of the aisle that is lit.

The process

Six weeks, six phases

We work along established frameworks — MITRE ATT&CK to classify the techniques, TIBER-EU as the process framework where it is required. A typical operation runs over six to eight weeks.

6–8 weeks
duration of a full operation
3–5
people in the informed circle
1 objective
agreed and recorded in writing beforehand
2 days
joint debrief afterwards
  1. 01

    Objective setting — which crown jewel counts as reached, and which limits are absolute. This is also where we record what must not happen under any circumstances: no production stoppage, no contact with medical systems, no real customer data.

  2. 02

    Reconnaissance — the attack surface from publicly available sources, without touching your systems. Employee profiles, job adverts naming technologies, data breaches, photographs from inside the building.

  3. 03

    Initial access — through technology, people or the building, whichever holds. In most operations it is not the technology.

  4. 04

    Establishing a foothold — access is stabilised without triggering your monitoring. This phase is the real test of your detection.

  5. 05

    Movement — lateral movement and privilege escalation up to the agreed objective. Every step is logged, with timestamp and technique used.

  6. 06

    Debrief — the joint reconstruction with your defence team. More on that below, because this is where the real value lies.

An attack nobody notices is a wasted test.

02

The debrief

Purple teaming: where the attack becomes defence

The most valuable phase comes last. In a joint session our team and your defence walk through the attack step by step — we with our log, your team with theirs. At every step the same question: did this show up on your side? If not, why not?

From that comparison come concrete detection rules, not recommendations. For every gap in detection we write, together, the rule that would have closed it, and test it during the session against our recorded data.

If you run Strider, we place the rules there directly. Talion takes over the automated first response to exactly the patterns we used in the operation — the next repetition of the same attack then ends in seconds rather than weeks.

03

The outcome

What you hold at the end

01

Not a report, but four things — and none of them is a list of vulnerabilities.

02

The attack path

The complete chain from the first step to the objective, with timestamps and the technique used at each point, classified to MITRE ATT&CK. Followable by someone who was not there.

03

The detection gaps

Where your monitoring should have fired and did not — with the reason: missing data source, rule too coarse, alert raised but lost in the noise.

04

The new rules

Finished detection rules, tested in your environment. Not as a suggestion in an appendix, but deployed and, if you wish, armed straight away.

05

The board version

Two pages for management and supervisory bodies: what the objective was, whether it was reached, how long it took, what has changed since. No jargon, no glossing over.

04

Regulation

When an operation is mandatory

For financial services, DORA makes threat-led penetration testing binding; TIBER-EU describes the framework under which it is to be carried out. This affects not only banks but insurers, payment providers and their critical IT suppliers.

Outside the financial sector an operation is not mandatory but increasingly expected — by cyber insurers at higher coverage levels and by corporate customers during supplier assessments. Where NIS2 applies, the result can serve as evidence of the effectiveness of technical measures.

05

The prerequisite

When you are not ready yet

A red team operation presupposes a working baseline. If a simple vulnerability scan already finds open management interfaces, you do not need a weeks-long operation to confirm that — you need two weeks of clearing up and then a penetration test.

An operation becomes worthwhile once there is a security operation that could notice something: central logging, somebody watching, defined escalation paths. Otherwise you are not testing your defence but merely establishing that there is none — which can be done more cheaply.

We will say so openly in the initial conversation. Selling an operation that comes too early gets us an order and gets you an expensive report.

06

In closing

The most honest answer you will get about your security

At the end of an operation you know two things for certain that no other method answers this way: whether somebody can reach your most valuable asset — and whether it is noticed. Both are yes-or-no questions, and both answers are evidenced rather than estimated.

Talk to us about objective and scope. The initial conversation is without obligation and not rarely ends with the recommendation to do something else first.

FAQ

Frequently asked questions

Who in the organisation may know about it?

As few as possible, but at least two: someone with authority to decide and someone who can confirm, if needed, that the incident is a test. Three to five is usual. The security team is expressly not among them — otherwise you are testing their preparation rather than their reaction.

What happens if your team is detected?

That is a good result, not a cancellation. We record where and how quickly, and agree with the informed circle: either we continue with a changed approach, or the operation ends there with a clear finding.

Do you also target our staff directly?

Yes, that is part of it — but within the agreed limits and without exposing anyone. Nobody who falls for a message is named in any report. Evaluation is by area and type of attack, not by person.

Can you guarantee nothing will go down?

Nobody using real techniques can guarantee that. We contain it: methods carrying an availability risk are excluded in advance, critical systems are either off limits or touched only at agreed times, and there is a number throughout on which we stop immediately.

What does an operation cost?

Considerably more than a penetration test, because it runs over weeks and involves several disciplines. The figure only becomes reliable after the initial conversation, once objective, scope and limits are settled. We name it beforehand, not afterwards.

Offensive Services

More in this area

Penetration Testing

Authorised attacks on your systems — black, white or grey box, external and internal. With findings ranked by severity …

View

Vulnerability Scanning

Outer skin, internal network, web applications and cloud checked continuously against CVE — rated against your situatio…

View

Social Engineering

How resilient is the human factor? We test it with phishing, phone calls and access attempts — documented, and without …

View

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.