02Objective-based · Full-scope
One question,
answered.
A penetration test asks how much is wrong. A red team asks something harder: can a capable, patient adversary reach the thing that would genuinely hurt you — and would anyone notice on the way?
- A money-movement objective, not a coverage checklist
- Technology, people and process in one engagement
- Detection and response measured as you go
- Full attack narrative, first contact to objective
//Which one you need
This is not a bigger penetration test.
They answer different questions, and buying the wrong one is a common and expensive mistake.
Penetration test
Coverage. How many exploitable weaknesses exist across a defined scope, how severe is each, and in what order should they be fixed?
Buy this when you need to find and fix things.
Red team
Consequence. Given a real objective and a motivated adversary, does your organisation stop them — and if not, at which point should it have?
Buy this when you need to know whether it all holds together.
If you have never had a penetration test, start there. A red team against an untested estate usually just proves what a cheaper engagement would have told you.
01Everything is in scope
Three vectors.
A real adversary does not restrict themselves to the surface you happened to buy testing for. Neither do we, within whatever bounds you set in writing.
Technical
External perimeter, cloud identity, internal lateral movement and privilege escalation — whatever the objective actually requires.
- Perimeter and cloud initial access
- Active Directory and identity attack paths
- Lateral movement and persistence
Human
Targeted social engineering built from real reconnaissance, aimed at the handful of people who can get us where we need to be.
- Spear phishing and pretext calls
- Supplier and executive impersonation
- Physical access and tailgating where in scope
Process
The gaps between systems and teams — where a request that should be verified is approved because it arrived through the usual channel.
- Onboarding, offboarding and access requests
- Change and exception handling
- Helpdesk identity verification
02How it runs
Objective first. Everything else serves it.
- 01
Set the objective
We agree the crown jewel and what "reached" means — a specific record, a specific transaction, a specific system. Everything else follows from that.
- 02
Rules of engagement
Written scope, out-of-bounds systems, escalation contacts, and who inside your organisation is aware. Usually very few people.
- 03
Operate
We work toward the objective the way an adversary would — quietly, opportunistically, and across whichever vectors get us closer.
- 04
Debrief together
The full narrative, with your defenders in the room, mapped against what they saw and when. This is where the value lands.
03The other deliverable
What your defenders saw, and when.
Reaching the objective is only half of it. The more useful half is the timeline: every action we took, set against what your tooling recorded and what your team acted on.
- Detection timeline
- Each step we took, whether it generated telemetry, whether that telemetry reached anyone, and how long before someone acted on it.
- The missed opportunities
- The points where a small change in alerting or process would have ended the engagement. These are usually cheaper to fix than the vulnerabilities.
- Purple team option
- We can run the last phase openly alongside your defenders, replaying attacks so they can tune detection with the attacker in the room.
- Evidence for the board
- A narrative that a non-technical director can follow from first contact to objective — the single most effective security budget document you will own.
A red team tests people who are not told it is a test. That has to be handled carefully. Results are never attributed to individuals, findings about staff are reported in aggregate, and we agree in advance how anyone who gets caught out will be spoken to afterwards.
→Next step
What would you least like us to reach?
That answer is usually the objective. A short conversation is enough to work out whether a red team is the right instrument, or whether something more targeted would serve you better.
daniel@theosec.com · +27 63 484 1051