Red Team Operations

A Red Team does not look for vulnerabilities: it goes after an objective. Reaching the ERP, exfiltrating a specific file, getting into the industrial network. And while it does so, it measures something no penetration test tells you: whether your team notices, how long it takes and what it does when it does.

Penetration testing and Red Teaming are not the same

Pentest
Coverage
How many vulnerabilities exist within a defined perimeter, over a short period and with the defence team informed.
Red Team
Objective
A specific goal, by any route, over weeks and with the defence team blind. Detection is measured, not just exposure.
Purple Team
Learning
Attack and defence working together and in the open, running techniques one by one to tune detections. It is what improves a SOC fastest.

What we measure

Time to detection for each phase of the operation, and which specific technique triggered the alert.
Time to response and the quality of that response: what was contained, what was escalated and what was closed as a ticket.
Detection coverage mapped to MITRE ATT&CK: which techniques you see, which you do not, and which you believe you see but do not.
Attack paths that worked and why, so the fix addresses the cause rather than the symptom.

Formats

Full Red Team: from external reconnaissance through to the objective, with social engineering if agreed.
Assumed breach: we start from an already compromised workstation. It saves the weeks spent on initial access and concentrates on what hurts most: lateral movement, escalation and persistence.
Purple Team: joint sessions with your defence team to build and validate detections technique by technique.
Threat-led testing for entities subject to resilience requirements such as those in DORA.

How we work

1
Objectives and rules
What counts as success, what is out of bounds, who inside your organisation is aware and how the exercise is aborted if needed.
2
Prior intelligence
Exposed surface, people, technologies and suppliers. The same thing an adversary would do before launching anything.
3
Initial access
By whatever route works: technical exposure, leaked credentials or social engineering, if it is within the agreed scope.
4
Operation
Lateral movement, escalation, persistence and progress towards the objective, with every step timestamped so it can be cross-referenced against your logs.
5
Comparison with your defence
We lay the two timelines side by side: what we did and what your SOC saw. That is where the real value of the exercise sits.
6
Report and detection plan
Not only what to fix, but which detection rules to add so it triggers sooner next time.

What you get

A full operation timeline, cross-referenced against your detections.
MITRE ATT&CK coverage map showing what was detected, what was not and what was detected late.
Attack paths with the full chain and the exact point where breaking it costs least.
Detection recommendations: what to log, what to correlate and which rules to write.
Executive report with the reading for management and the board.
Debrief session with your defence team.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.

Questions we get asked

Are we ready for a Red Team?
If you have never run a penetration test and have no detection capability in place, probably not. A Red Team against an organisation with no telemetry only proves what you already suspect. We will tell you that before selling you the project.
How many people should know?
As few as possible: normally a sponsor and an emergency contact. If the whole SOC knows, you are not measuring detection, you are running a demonstration.
Does it include social engineering?
If you want it and within limits agreed in writing. It is the most realistic entry route, but it involves people and that is handled carefully: no individual employee is ever named in the report.
How long does it take?
Weeks, not days. A real adversary is not in a hurry, and compressing the exercise into a week turns it into something else. The calendar is set when objectives are defined.
Would they detect you?
Half an hour with an auditor to decide whether a Red Team, an assumed breach or starting with a Purple Team alongside your defence team is the right move.

Book 30 min with an auditor

Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET)  ·  Email: info@jaymonsecurity.com
We reply within 2 working hours.
ENES