Black GhostBlack Ghost
Red Team · Offensive

Red Team.
A real adversary, against the whole company.

An objective-based, multi-vector attack simulation run without warning to the defensive team. We test technology, people, process and your detection and response capability, the way a determined attacker would.

Operational capability available today. Part of building a national cyber defense.

Objective-basedMulti-vectorRealistic scenarioMITRE ATT&CK

[ 01 / WHAT IT IS ]

Different from a pentest. The target is a concrete objective.

Where a pentest covers a defined surface, a Red Team engagement pursues a concrete objective, such as reaching a critical system, exfiltrating a dataset or compromising a high-privilege account, using any available path: application, network, cloud, social engineering or physical access. The defensive team is not warned. What we measure is how well your environment resists a patient, creative adversary, and how long it takes to notice one.

[ 02 / ATTACK VECTORS ]

Every path on the table. Combined the way a real adversary would.

Digital surface

Exploitation of applications, APIs, external network and exposed services as an initial entry point.

Social engineering

Targeted phishing, pretexting and vishing to gain the first foothold through people.

Movement & persistence

Privilege escalation, lateral movement and persistence toward the objective, evading detection.

Physical access (optional)

Physical access attempts against facilities and devices, when within the agreed scope.

[ 03 / HOW WE RUN IT ]

From objective to debrief.

  1. 01

    Objectives & rules

    We define the crown jewels, the Rules of Engagement and what is off-limits. Signed before we begin.

  2. 02

    Recon & weaponization

    Intelligence on the organization, its people and its surface. Preparing infrastructure and pretexts.

  3. 03

    Initial compromise

    Gaining first access through the most effective vector, whether technical or human.

  4. 04

    Actions on objective

    Movement, escalation and persistence toward the objective, testing detection at every step.

  5. 05

    Debrief & purple team

    Rebuilding the kill chain with your team, identifying where detection failed and how to close the gaps.

[ 04 / WHAT YOU GET ]

Deliverables. The real story of the operation.

Full operation narrative: every step, every decision and every detection point, or the absence of one.

Mapping of the TTPs used to MITRE ATT&CK.

An honest assessment of your team’s detection and response capability.

A remediation plan prioritized by risk and by ease of fixing.

A joint debrief session that transitions naturally into a purple team exercise.

Want to know if your defense holds against a real adversary?

Talk to our specialists. We design a realistic scenario, with clear objectives and tailored rules of engagement.