Adversary simulation · Red · Purple · Social

Objective-based campaigns under signed Rules of Engagement and agreed stop conditions.

Red team and adversary simulation.

Campaigns test whether people, process, and tooling detect, escalate, contain, and recover when controls fail. Execution stays inside approved objectives and safety boundaries.

  • Red teamFull-scope, objective-led campaigns from initial access through identity, lateral movement, persistence, and a defined business impact target.
  • Purple teamCo-designed with defenders, with live feedback loops, replayable artefacts, detection engineering, telemetry review, and playbook validation.
  • Adversary emulationA named or curated threat profile, realistic access vectors, ATT&CK-mapped progression, and measured defensive outcomes across a defined window.
  • Ransomware simulationSafe-mode rehearsal of access, privilege escalation, lateral movement, backup and recovery paths, containment, and executive decision points without actual destruction.
  • Social engineeringAuthorised pretexts, helpdesk and workflow testing, business-process manipulation, and optional physical scenarios with HR-aligned guardrails.
  • Phishing simulationRole-targeted email or SMS campaigns across baseline, uplift, and validation waves, measured through reporting, escalation, and control effectiveness.
Controlled execution

Realism is bounded by written authority, named owners, and clear stop conditions.

Nothing happens outside what is signed.

  • AuthorisationRules of Engagement cover objectives, scope, test windows, escalation paths, approved AI use, model and data boundaries, synthetic voice or imagery, and stop conditions.
  • PeoplePeople-layer work is HR-aligned and respect-first. Results are aggregated and are not used for individual blame, humiliation, or performance management.
  • AI-assisted tradecraftOperator-reviewed tooling can support pretext drafts, recon synthesis, or detection queries when relevant. Messages, payloads, and targeting remain human-authorised.
  • Evidence handlingOnly the material needed to prove risk and guide uplift is retained. Artefacts, scripts, recordings, and staff interactions are confidential and follow agreed retention controls.
  • OutputsA chronological campaign narrative, detection and response gaps, ATT&CK mapping, replay notes, prioritised defender actions, and a working debrief.
01Discover & RoEObjectives, boundaries, windows, test cohorts, escalation paths, and signed controls.
02Threat-led designScenarios shaped by risk profile, likely threats, and critical business processes.
03Controlled executionRealistic activity inside agreed safety controls, monitoring, and stop conditions.
04Debrief & upliftValidated paths, defensive gaps, read-outs for executives, and working sessions for defenders.
05Retest & verifyUsually within 60–90 days. Rerun agreed scenarios and measure risk reduction.
Relevant standards MITRE ATT&CK/ MITRE D3FEND/ ACSC guidance/ NIST CSF/ OSSTMM
Scope first

Red team and ransomware campaigns typically need four to six weeks of lead time.

Send the objective and constraints.

Include the question the campaign must answer, the environment and people in scope, relevant threats, required stakeholders, and any safety boundaries.