B BROCENT

Security · Red Team Engagement

Can your team detect a real intrusion — not just find the hole that let it in?

An undisclosed adversary, a real objective, and a small senior team pursuing it exactly like an attacker would. Your defenders respond without knowing it's a drill — because that's the only way to actually test whether they'd catch one.

Objective-based, not asset-list scopedMITRE ATT&CK-mapped findings4–8 weeks, senior 2–4 person team

Simulated attack path — illustrative

RECON ACCESS PERSIST LATERAL MOVE OBJECTIVE

Detected by SOC? Not until the debrief.

What's included

A scoped engagement, not a scan

Every Red Team Engagement is built around one real objective — reaching a specific system, account, or dataset — and run by a small senior team, not an automated sweep.

01

Objective & Rules of Engagement

A written scoping document: the target objective, your white-cell contact, off-limits systems, and stop conditions — agreed before anything starts.

02

Full kill-chain execution

Reconnaissance through objective achievement, using the same techniques — phishing, exposed services, physical access, cloud misconfiguration — a real adversary would chain together.

03

ATT&CK-mapped findings

Every technique used is mapped to a MITRE ATT&CK ID, so "what should have triggered detection" becomes a concrete engineering backlog, not a narrative.

04

Executive summary

A board-readable overview of what was reached, how, and what it means for the organisation's risk posture.

05

Attack-path timeline

A reconstructed, step-by-step account of the engagement — every pivot, every credential, every decision point.

06

Live purple-team debrief

A session with your security/IT team where the red team walks through what happened — collaborative, not adversarial.

Methodology

Six stages, MITRE ATT&CK-aligned

Most of an engagement's duration lives in stage 4 — lateral movement is the long game, not the headline moment.

1

Scoping & Rules of Engagement

Often takes as long as a full pentest's scoping and execution combined — the objective, the white-cell contact, and every boundary get written down first.

2

Reconnaissance

OSINT, employee enumeration, and external footprint mapping — building the same picture a real attacker would build.

3

Initial access

Phishing, an exposed service, a physical attempt, or a purchased foothold — whichever path the scenario calls for.

4

Persistence & lateral movement

The long phase. Establishing footholds, escalating privilege, and moving toward the objective while staying under the radar.

5

Objective achievement

Demonstrated, never executed for real — proof that the goal was reachable, without touching production data.

6

Purple-team debrief

A live walkthrough, technique by technique, turning the engagement into an actionable detection-engineering backlog.

How this differs

Not a deeper penetration test

A penetration test and a red team engagement answer two different questions. Most organisations need both — just not at the same time.

Penetration Testing

  • What vulnerabilities exist in these systems?
  • Scope: a defined asset list
  • Usually disclosed and scheduled
  • Tests vulnerability existence
  • Days to weeks
  • Where most organisations start
See Penetration Testing →

Red Team Engagement

  • Can an attacker reach this goal — would we notice?
  • Scope: a single objective
  • Undisclosed except to one white-cell contact
  • Tests detection & response, end to end
  • Weeks to months
  • The next step once hygiene is in place

Is this for you

Who this is — and isn't — built for

Good fit

  • You already run vulnerability scanning or penetration testing
  • You have a SOC, MDR, or internal detection team you want to genuinely test
  • You need to demonstrate detection maturity for a board, insurer, or regulator
  • You want findings your engineering team can actually action, not a scare story

Start elsewhere first

  • You haven't run a penetration test yet — start there
  • You don't have anyone who'd respond to an incident today
  • You need a broad vulnerability inventory, not a single objective
  • You want employee-level phishing awareness metrics — see Phishing Test →

Before you talk to a consultant

View all FAQs →

How is this different from your Penetration Testing service?

A penetration test finds vulnerabilities across a defined set of systems, disclosed and scheduled with your IT team. A Red Team Engagement pursues one real objective, undisclosed to your defenders, and measures whether they'd detect and respond to a genuine intrusion — not just whether a hole exists.

Full answer →

Will our own IT/security team know this is happening?

No — by design. Only a small "white cell," usually the CISO or one executive, knows the engagement is underway. That's what makes the detection-and-response test meaningful.

Full answer →

What if the team finds something that looks like a real attack in progress?

The Rules of Engagement, agreed before the engagement starts, include a safe-word and stop conditions precisely for this. The white-cell contact can pause or end the engagement immediately if needed.

Full answer →

How long does an engagement take?

Typically several weeks to a couple of months, depending on the objective and environment — most of that time goes into the lateral-movement phase, not initial access.

Full answer →

Do we need a working penetration-testing programme first?

Yes, generally. Red teaming assumes foundational vulnerability hygiene already exists — the value is in testing detection of an attacker who's already gotten past the easy stuff.

Full answer →

What do we get at the end — just a report, or a live walkthrough?

Both: a written executive summary, attack-path timeline, and ATT&CK-mapped findings, plus a live purple-team debrief session with your team.

Full answer →

Why isn't there a price on this page?

Every engagement is scoped to a real objective and environment, so a published price list would be misleading rather than useful — the market for this service is quote-driven industry-wide. Tell us your goal and we'll return a scoping call.

Full answer →

Scope your engagement

Every Red Team Engagement is quoted individually — objective, environment, and duration all shape it. Tell us your goal and we'll return a scoping call.

Talk to a consultant