Skip to content
8bytes

Test detection,
not just prevention.

End-to-end adversary simulation modelled on real-world TTPs. We don't just look for vulnerabilities — we behave like the attackers your blue team will eventually face.

Engagement types

How we engage.

Four engagement shapes, from full-scope multi-month campaigns to focused TTP-emulation exercises. Picked based on the gap you want to close.

Full-scope red team

Multi-month engagement covering initial access through to objective execution. Covert by default; tests prevention, detection, and response across the full kill chain.

Assumed breach

We start from an endpoint or a low-privilege user account. Skips initial-access for organisations that want to test internal response without the recon overhead.

Adversary emulation

Run the TTPs of a specific real-world actor (APT29, FIN7, LockBit) against your environment. Built around MITRE ATT&CK techniques relevant to your sector.

Social engineering

Phishing, vishing, and (where in scope) physical pretexting. Targets the human layer that automated controls do not protect.

Methodology

How we work.

01

Threat modelling & objectives

Define the crown-jewel assets and what 'success' looks like for the engagement. Align scope and rules of engagement with your stakeholders.

02

Reconnaissance

Passive and active discovery of attack surface, employees, technologies, and third-party trust relationships. OSINT-heavy.

03

Initial access

Phishing, exposed services, supply-chain footholds. We use the access vectors that real adversaries actually use against organisations like yours.

04

Persistence & lateral movement

Establish C2, harvest credentials, move laterally, escalate privileges, evade detection. MITRE ATT&CK tactics mapped throughout.

05

Objective execution & debrief

Achieve the agreed objective (exfiltration, ransomware simulation, IP theft). Then full purple-team debrief with your blue team and a detection roadmap.

Deliverables

What you receive.

Everything you need to fix what we found — and prove it to your auditors.

  • Executive narrative tied to your business risk
  • TTP-by-TTP timeline mapped to MITRE ATT&CK
  • C2 infrastructure, tooling, and artefacts handed over
  • Detection gap analysis — what your tools missed and why
  • Live purple-team debrief with your blue team
  • Remediation and detection-engineering playbook

FAQs

Common questions.

01

How is this different from a pentest?

A pentest finds vulnerabilities; a red team tests your detection and response. We assume vulnerabilities exist — what we want to know is whether your blue team notices when they are exploited, and how fast they react. The deliverable is a story about your detection capability, not a list of CVEs.

02

How long do red team engagements take?

Full-scope engagements typically run 6–10 weeks of active testing. Adversary emulation can be shorter (3–4 weeks). Assumed-breach scenarios sit in between. Discovery, debrief, and reporting add another 2–3 weeks on each side.

03

What does "assumed breach" actually mean?

You provide us with an endpoint or low-privilege account as the starting point — simulating an attacker who has already obtained initial access (a phished credential, a compromised contractor). We then test how far we can get from there. Useful when you want to focus the engagement on detection and lateral movement rather than initial access.

04

Will you actually phish our employees?

Only if it is in scope and a small group of stakeholders (typically the CISO and HR partner) has approved the campaign. We do not phish without explicit sign-off, and we never use phishing pretexts that could cause lasting reputational harm to the targeted individual.

05

Will you debrief our blue team afterwards?

Yes — a live purple-team session is part of every engagement. We walk through the timeline together, replay key TTPs, and identify where your detection capability needs investment. This is often the most valuable part of the engagement.

Get in touch

Ready to test your defences?

Book a call

Free 30-min scoping call. No commitment.