Home / Red Team Exercises / How It Works
Mission Briefing
How a Red Team Exercise Unfolds
Every engagement is constructed from real threat intelligence specific to your sector. The attack progresses through seven phases — patient, persistent, and precisely targeted at your most critical assets.
Full-Spectrum Simulation
Seven Phases, One Continuous Attack
Each phase below tests a different layer of your defenses, and each one is run the way a real adversary would run it — using the tactics, techniques, and procedures of the groups actually targeting your sector.
PHASE 01 — RECONNAISSANCE
Intelligence Gathering & Target Profiling
Before a single packet is sent, our red team builds a comprehensive intelligence profile of your organization using the same techniques your adversaries use. Open-source intelligence, dark web monitoring, supplier chain mapping, employee exposure analysis, and technology footprint enumeration. We know your attack surface before we engage it.
- OSINT
- SOCMINT
- DNS enumeration
- Certificate transparency
- Dark web credential scanning
- Technology fingerprinting
↳ MITRE ATT&CK: TA0043 Reconnaissance · TA0042 Resource Development
PHASE 02 — INITIAL ACCESS
Establishing a Foothold
Using the intelligence gathered, we attempt initial access through the vectors your specific threat actors prefer: spear-phishing targeting key personnel, exploitation of internet-facing applications, supply chain pathways, or physical access to facilities. We use the same social engineering lures, the same CVEs, the same entry points as the groups actually targeting your sector.
- Spear-phishing
- Credential stuffing
- VPN exploitation
- Web app vulnerabilities
- Supply chain access
- Physical access (if in scope)
↳ MITRE ATT&CK: TA0001 Initial Access · T1566 Phishing · T1190 Exploit
Public-Facing Application
PHASE 03 — PERSISTENCE & DEFENSE EVASION
Staying Hidden, Staying Inside
Once inside, a sophisticated attacker doesn’t immediately act — they establish persistence and begin adapting to your specific defensive environment. Our red team deploys the same counter-detection techniques used by nation-state actors: living-off-the-land binaries, log manipulation, process injection, and traffic masquerading. This phase reveals whether your monitoring detects attacker presence or whether they can operate indefinitely undetected.
- LOLBin techniques
- Scheduled task persistence
- Log clearing
- Process masquerading
- C2 traffic obfuscation
- Timestomping
↳ MITRE ATT&CK: TA0003 Persistence · TA0005 Defense Evasion · T1070
Indicator Removal
PHASE 04 — PRIVILEGE ESCALATION & CREDENTIAL ACCESS
Gaining the Keys to the Kingdom
With an established foothold, the red team escalates privileges and harvests credentials to expand access. LSASS memory dumping, Kerberoasting, Pass-the-Hash, and PAM bypass techniques are used to acquire domain-level authority. This phase tests your privileged access management controls, your UEBA baselines, and whether anomalous credential behavior generates meaningful alerts within actionable timeframes.
- Kerberoasting
- LSASS credential dump
- Pass-the-Hash
- Token impersonation
- PAM bypass techniques
- DCSync
↳ MITRE ATT&CK: TA0004 Privilege Escalation · TA0006 Credential
Access · T1003 OS Credential Dumping
PHASE 05 — LATERAL MOVEMENT
Spreading Across the Environment
Using harvested credentials and trust relationships, the red team moves laterally toward the target — mapping your internal network, identifying crown-jewel systems, and testing east-west traffic monitoring. This is where most SOC detection programs have their largest gaps: attackers using legitimate credentials and standard administrative protocols look identical to authorized users.
- SMB lateral movement
- RDP pivoting
- WMI remote execution
- PsExec
- SSH tunneling
- AD trust exploitation
↳ MITRE ATT&CK: TA0008 Lateral Movement · T1021 Remote Services · T1550
Pass-the-Hash
PHASE 06 — COMMAND & CONTROL
Maintaining Operational Control
The red team establishes and maintains a resilient command-and-control infrastructure, testing whether your network monitoring detects outbound communication to adversary infrastructure. DNS tunneling, HTTPS C2 over legitimate-looking domains, and beacon traffic analysis reveal whether your perimeter controls provide genuine visibility or a false sense of outbound security.
- DNS tunneling
- HTTPS C2 beaconing
- Domain fronting
- Protocol masquerading
- Encrypted C2 channels
↳ MITRE ATT&CK: TA0011 Command and Control · T1071 Application Layer
Protocol · T1572 Protocol Tunneling
PHASE 07 — OBJECTIVE ACHIEVEMENT
Data Exfiltration, System Compromise & Impact
The final phase tests whether you can prevent an attacker from achieving their objective once they have reached it — data repositories, OT systems, financial controls, customer records. We simulate exfiltration, privilege abuse, destructive attack patterns, or ransomware precursor behavior depending on the engagement scope. This is the moment where your detection, response, and containment capabilities are measured against a real attack timeline.
- Data staging & exfiltration
- DLP evasion testing
- Ransomware precursor simulation
- OT / ICS interaction (if in scope)
- Backup access & enumeration
- Financial system access
↳ MITRE ATT&CK: TA0009 Collection · TA0010 Exfiltration · TA0040 Impact · T1486
Data Encrypted for Impact
Engagement Objectives
People, Process, and Technology — Tested Together
A red team exercise is the only form of security testing that evaluates all three dimensions of your security program simultaneously, under adversarial conditions.
// Dimension 01
People
- Security awareness and phishing susceptibility across all staff levels
- C-suite and executive targeting — whaling, BEC, voice phishing
- Physical security behaviors: tailgating, social engineering, badge cloning
- SOC analyst detection response and escalation speed
- Incident response team activation and decision-making under pressure
- Executive communication and crisis management during a live incident
// Dimension 02
Process
- Incident response plan effectiveness against a real attack timeline
- Alert triage and escalation workflows — are the right people notified?
- Change management and access provisioning controls under attack conditions
- Vendor and third-party access governance during an active incident
- Communication protocols between security, IT, legal, and executive teams
- Regulatory notification obligations — do you know when and who to call?
// Dimension 03
Technology
- SIEM detection rule coverage across tested MITRE ATT&CK techniques
- EDR effectiveness against living-off-the-land and fileless attack techniques
- Network segmentation integrity — east-west traffic and VLAN isolation
- PAM controls on privileged accounts and administrative access pathways
- DLP effectiveness for data staging and exfiltration via multiple channels
- Email gateway and web filtering evasion capability
The detection gap that defines your real risk exposure
The average attacker dwells inside a compromised network for 241 days before detection (IBM 2025). In those 241 days, they map your environment, harvest credentials, identify your most valuable assets, and position for maximum impact before executing. A red team exercise measures whether your program can close that gap — and by how much.
REGULATORY ALIGNMENT
Red team exercises are an explicit requirement under frameworks in every region we operate — from NY DFS Part 500 and CMMC 2.0 in North America, to DORA Article 26 TLPT in Europe, MAS TRM across Asia-Pacific, and GLI-33 for gaming and lottery operators.
Frequently Asked Questions
Will our SOC team know the exercise is happening?
Typically no. In a standard red team engagement, awareness is limited to a small ”white cell” — typically the CISO and one or two senior stakeholders — who manage the engagement without disclosing it to the operational security team. This is essential for authentic measurement of your SOC’s real detection capability. Partial-knowledge (purple team) and full-knowledge (assumed breach) variants are also available for specific training and improvement objectives.
Explore Red Team Exercises
Go Deeper
Engagement Process & What You Receive
How an engagement runs from first briefing to boardroom, and the eight deliverables it produces.
- Learn More
01
Red Team Exercises
The overview — what a red team exercise is, how it differs from penetration testing, and the full regulatory alignment.
- Learn More
02
Book a 30-minute red team briefing. We’ll walk through your specific threat profile, the objectives most relevant to your organization, and exactly how we’d structure an engagement — before you commit to anything.