Red team and adversary simulation.
Campaigns test whether people, process, and tooling detect, escalate, contain, and recover when controls fail. Execution stays inside approved objectives and safety boundaries.
// What we run
- Red teamFull-scope, objective-led campaigns from initial access through identity, lateral movement, persistence, and a defined business impact target.
- Purple teamCo-designed with defenders, with live feedback loops, replayable artefacts, detection engineering, telemetry review, and playbook validation.
- Adversary emulationA named or curated threat profile, realistic access vectors, ATT&CK-mapped progression, and measured defensive outcomes across a defined window.
- Ransomware simulationSafe-mode rehearsal of access, privilege escalation, lateral movement, backup and recovery paths, containment, and executive decision points without actual destruction.
- Social engineeringAuthorised pretexts, helpdesk and workflow testing, business-process manipulation, and optional physical scenarios with HR-aligned guardrails.
- Phishing simulationRole-targeted email or SMS campaigns across baseline, uplift, and validation waves, measured through reporting, escalation, and control effectiveness.
// Governance and evidence
Nothing happens outside what is signed.
- AuthorisationRules of Engagement cover objectives, scope, test windows, escalation paths, approved AI use, model and data boundaries, synthetic voice or imagery, and stop conditions.
- PeoplePeople-layer work is HR-aligned and respect-first. Results are aggregated and are not used for individual blame, humiliation, or performance management.
- AI-assisted tradecraftOperator-reviewed tooling can support pretext drafts, recon synthesis, or detection queries when relevant. Messages, payloads, and targeting remain human-authorised.
- Evidence handlingOnly the material needed to prove risk and guide uplift is retained. Artefacts, scripts, recordings, and staff interactions are confidential and follow agreed retention controls.
- OutputsA chronological campaign narrative, detection and response gaps, ATT&CK mapping, replay notes, prioritised defender actions, and a working debrief.
// Delivery
01Discover & RoEObjectives, boundaries, windows, test cohorts, escalation paths, and signed controls.
02Threat-led designScenarios shaped by risk profile, likely threats, and critical business processes.
03Controlled executionRealistic activity inside agreed safety controls, monitoring, and stop conditions.
04Debrief & upliftValidated paths, defensive gaps, read-outs for executives, and working sessions for defenders.
05Retest & verifyUsually within 60–90 days. Rerun agreed scenarios and measure risk reduction.
Relevant standards
MITRE ATT&CK/
MITRE D3FEND/
ACSC guidance/
NIST CSF/
OSSTMM
// Next step
Send the objective and constraints.
Include the question the campaign must answer, the environment and people in scope, relevant threats, required stakeholders, and any safety boundaries.